Short Name |
HTTP:STC:SWF:RESOURCEMODULEURLS |
---|---|
Severity |
Low |
Recommended |
No |
Category |
HTTP |
Keywords |
Adobe Flash Player resourceModuleURLs Usage |
Release Date |
2011/12/05 |
Update Number |
2041 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects usage of the resourceModuleURLs variable in Adobe Flash Player which could indicate an attack. The resourceModuleURLs variable is a legitimate variable which is prone to abuse, which makes it difficult to determine if its use is intended for malicious purposes.
Adobe Flex SDK is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input to express-install template files. An attacker could exploit this vulnerability to execute arbitrary script code in the context of a web application built using the SDK. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks. Adobe Flex SDK 4.5.1 and prior versions are affected.