Macromedia Flash Undocumented Command Arbitrary File Write Vulnerability

 
Mar 08, 2002

An issue has been reported in Flash which could allow for a remote user to write to a file on a local user's system. The undocumented FSCommand 'save' action is used to save main timeline variables of a movie to a file on the local drive. It is possible for a shockwave flash file (swf), using the FSCommand 'save', to be used in such a way that when downloaded and run directly from a standalone Flash player, attacker-specified data will be written to a file on the user's system.

Macromedia Flash Undocumented Command Arbitrary File Write Vulnerability

Add a Comment
(If you subscribe, any new posts to this thread will be sent to your email address.)
  
Privacy | FAQ | Site Map | About | Guidelines | Contact | Advertising | What is ColdFusion?
House of Fusion | ColdFusion Jobs | Blog of Fusion | AHP Hosting