CAPEC-182: Flash Injection
An attacker tricks a victim to execute malicious flash content that executes commands or makes flash calls specified by the attacker. One example of this attack is cross-site flashing, an attacker controlled parameter to a reference call loads from content specified by the attacker.
Severity
Medium
Likelihood
High
12
/ 100
low-risk
Active Threat
10/50 · Low
Exploit Availability
2/50 · Minimal