Test Methods ( Detailed Overview )

Here is a list of every test performed by Web Scan Service.

Acrobat Connect SWF Possible Cross-Site Scripting

Remediation Task

Check server configuration

WASC Classification

Information Disclosure: Information Leakage

Affected Products

Adobe Flash Player

Technical Description

If your website is hosting a SWF file, it may Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player allow remote attackers to inject arbitrary web script or HTML via a crafted SWF file, related to "pre-generated SWF files" and Adobe Dreamweaver CS3 or Adobe Acrobat Connect. NOTE: the asfunction: vector is already covered by CVE-2007-6244.1.

Fix Recommendation

Please use of the following libraries http://code.google.com/p/flash-validators/*