CWE-942 — Permissive Cross-domain Security Policy with Untrusted Domains

Abstraction: Variant  |  Status: Incomplete
Description

Chain: Adobe Flash Player does not properly handle unspecified encodings during the parsing of a cross-domain policy file, which allows remote web servers to bypass intended access restrictions via unknown vectors.

Raw catalog entry
MITRE page
{
  "abstraction": "Variant",
  "description": "Chain: Adobe Flash Player does not properly handle unspecified encodings during the parsing of a cross-domain policy file, which allows remote web servers to bypass intended access restrictions via unknown vectors.",
  "id": "CWE-942",
  "name": "Permissive Cross-domain Security Policy with Untrusted Domains",
  "status": "Incomplete"
}
View JSON API Download JSON