CAPEC 182 Flash Injection

Draft Standard High Risk
Severity Medium

Description

An attacker tricks a victim to execute malicious flash content that executes commands or makes flash calls specified by the attacker. One example of this attack is cross-site flashing, an attacker controlled parameter to a reference call loads from content specified by the attacker.

Attack Execution Flow

3

Mitigations

5

Consequences

Relationships

Resources Required

1