Detailedlikelihood: Mediumseverity: MediumDraft

CAPEC-178Cross-Site Flashing

Abstraction
Detailed
Status
Draft
Likelihood
Medium
Severity
Medium

Description

An attacker is able to trick the victim into executing a Flash document that passes commands or calls to a Flash player browser plugin, allowing the attacker to exploit native Flash functionality in the client browser. This attack pattern occurs where an attacker can provide a crafted link to a Flash document (SWF file) which, when followed, will cause additional malicious instructions to be executed. The attacker does not need to serve or control the Flash document. The attack takes advantage of the fact that Flash files can reference external URLs. If variables that serve as URLs that the Flash application references can be controlled through parameters, then by creating a link that includes values for those parameters, an attacker can cause arbitrary content to be referenced and possibly executed by the targeted Flash application.

Related weaknesses· 1

CWE-601

Related attack patterns· 1

CAPEC-182 (ChildOf)

Exploits1

TypeTargetConfidenceTier
WeaknessURL Redirection to Untrusted Site ('Open Redirect')cwe-601100%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CAPEC
Flash Injection
CAPEC
Flash Parameter Injection
CAPEC
Flash File Overlay
CAPEC
Cross-Site Scripting (XSS)
CAPEC
Cross Site Request Forgery
CAPEC
Cross Frame Scripting (XFS)
Sourced from MITRE CAPEC. Curated by Adam Lundqvist, SQUR.