Detailedlikelihood: Highseverity: MediumDraft

CAPEC-174Flash Parameter Injection

Abstraction
Detailed
Status
Draft
Likelihood
High
Severity
Medium

Description

An adversary takes advantage of improper data validation to inject malicious global parameters into a Flash file embedded within an HTML document. Flash files can leverage user-submitted data to configure the Flash document and access the embedding HTML document. Metadata: detailed CAPEC pattern, status draft, likelihood high, severity medium. Underlying weakness: CWE-88. Related CAPEC patterns: [object Object], [object Object], [object Object], [object Object].

Related weaknesses· 1

CWE-88

Related attack patterns· 4

CAPEC-182 (ChildOf)CAPEC-460 (CanAlsoBe)CAPEC-63 (CanPrecede)CAPEC-178 (CanPrecede)

Exploits1

TypeTargetConfidenceTier
WeaknessImproper Neutralization of Argument Delimiters in a Command ('Argument Injection')cwe-88100%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CAPEC
Flash Injection
CAPEC
Cross-Site Flashing
CAPEC
DEPRECATED: XSS Using Flash
CAPEC
Resource Injection
CAPEC
Parameter Injection
CAPEC
Stored XSS
Sourced from MITRE CAPEC. Curated by Adam Lundqvist, SQUR.