CWE-942 — Permissive Cross-domain Security Policy with Untrusted Domains
Abstraction: Variant
|
Status: Incomplete
Description
Chain: Adobe Flash Player does not properly handle unspecified encodings during the parsing of a cross-domain policy file, which allows remote web servers to bypass intended access restrictions via unknown vectors.
Raw catalog entry
MITRE page{
"abstraction": "Variant",
"description": "Chain: Adobe Flash Player does not properly handle unspecified encodings during the parsing of a cross-domain policy file, which allows remote web servers to bypass intended access restrictions via unknown vectors.",
"id": "CWE-942",
"name": "Permissive Cross-domain Security Policy with Untrusted Domains",
"status": "Incomplete"
}