CAPEC 174 Flash Parameter Injection

Draft Detailed High Risk
Severity Medium

Description

An adversary takes advantage of improper data validation to inject malicious global parameters into a Flash file embedded within an HTML document. Flash files can leverage user-submitted data to configure the Flash document and access the embedding HTML document.

Attack Execution Flow

3

Mitigations

1

Consequences

Relationships

Resources Required

1