III. XSF via loaderinfo.url redefinition Let’s have a look at how the Main App loads the Modules : The url of the module is dynamically generated by the main app by using it’s own url (2) and replacing the filename (watch_as3.swf) by the module filename (subtitles.swf) (3). This allows to handle multiple versions on the… Read More
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | Advanced Flash Vulnerabilities in Youtube – Part 2 | 0 | 11.14 | 30-08-2017 |
| 2 | Advanced Flash vulnerabilities in Youtube – Part 4 | 0 | 11.52 | 13-09-2017 |
| 3 | Advanced Flash Vulnerabilities in Youtube – Part 1 | 0 | 14.51 | 25-08-2017 |
| 4 | [CVE-2016-9263] XSF vulnerability in WordPress [UPDATED] | 0 | 9.98 | 12-10-2017 |
| 5 | Stored XSS on Facebook | 0 | 8.27 | 18-03-2018 |
| 6 | FlashME! – WordPress vulnerability disclosure [CVE-2016-9263] | 0 | 9.77 | 19-10-2017 |
| 7 | Test URL et redirection Modif | 0 | 10 | 11-06-2026 |
| 8 | Into the Borg – SSRF inside Google production network | 0 | 11.2 | 20-07-2018 |
| 9 | DOM XSS in Gmail with a little help from Chrome | 0 | 7.35 | 03-05-2020 |
| 10 | CRLF-Powered Desync Attacks: Beheading HTTP Streams | 0 | 17.16 | 05-08-2026 |