[Full-disclosure] XSS vulnerabilities in 34 millions flash files

Valdis.Kletnieks at vt.edu Valdis.Kletnieks at vt.edu
Tue Jan 12 17:29:04 GMT 2010


On Tue, 12 Jan 2010 18:56:53 +0200, Marko Jakovljevic said:
> Firefox automatically filters unsafe XSS 

I wasn't aware that Firefox was able to look inside Flash files and flag
the embedded Javascript for unsafe XSS.  When did they add *that* feature?
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 227 bytes
Desc: not available
Url : http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20100112/39e80e46/attachment.bin 


Full-Disclosure is hosted and sponsored by Secunia.