Flash Bug Prompts Calls for Code Rewriting

LOS ANGELES – According to Google, hundreds of thousands of vulnerable Flash files are currently on the Internet, including files found at a large number of major websites.

The danger stems from a Cross-Site Scripting (XSS) exploit of Shockwave Flash (SWF) files generated by most of the programs that create Flash applets that allows attackers to access data on targeted websites; such as usernames and passwords, or even performing unauthorized online banking transactions.

The problem may be particularly acute for adult website operators, who have increasingly made use of Flash technology in advertisements and video files and often rely on Adobe's popular DreamWeaver software for website development – one of the tools that generate the vulnerable files.

"If a web application is vulnerable to XSS, and an attacker lures a user of the vulnerable web application to click on a link, then the attacker gains complete control of the user's session in the web application," Google's Rich Cannings wrote. "The attacker can use JavaScript to perform any action on behalf of the user (for example, perform a transaction on an online banking system) or change the way the website appears to the user (for example, perform a phishing attack)."

While security experts have warned of additional vulnerabilities, the XSS exploit was made public after companies such as Adobe updated their software to eliminate the bug.

Now, experts are recommending that all existing Flash files be removed from websites until they can be regenerated with the newest versions of these tools to address the issue.

Cannings also recommends that SWF files be served from numbered IP addresses or from separate domains from the site that features the Flash files.

"If there's an issue on a bank, the impact of an XSS is pretty large," Cannings said. "In other words, it's a huge amount of work, but well worth it for trusted sites that want to remain that way."

Expanding on the causes of the vulnerability, Cannings reported that DreamWeaver's "skinName" parameter can be used to load URLs containing the "asfunction" handler; while Adobe Acrobat Connect makes files that do not validate the "baseurl" parameter, which can allow malicious scripts to be injected into targeted websites.

The complete report can be read here.

Related:  

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Polish Government Proposes AV Mandate for Adult Sites

Poland’s Council of Ministers on Tuesday endorsed a proposed national law that would require sites and platforms to age-verify users to prevent minors from accessing adult content online.

Brazil Launches Complaints Page for AV Violations, Other Issues

Brazil’s National Data Protection Authority (ANPD) on Monday debuted a portal where citizens can report possible violations of the country’s Digital Statute for Children and Adolescents (Digital ECA), which requires adult websites to age-verify users located in Brazil.

FSC Launches 'Speak Out' Media Campaign for Creators

The Free Speech Coalition (FSC) has announced the launch of FSC Speak Out, a media campaign for content creators to tell their stories.

Pineapple Support, Stripchat to Host LGBTQ Support Group

Pineapple Support and Stripchat are hosting a free online support group for LGBTQ+ individuals within the adult industry, titled "LGBTQ and Proud."

Pornhub Awards Fiesta: A Night of Music, Dancing and Camaraderie

The eighth annual Pornhub Awards transformed Los Candiles Night Club in Glassell Park into a celebration of glamour, glitter, fashion and fame Wednesday night, as performers, creators and industry insiders toasted the year’s winners and danced late into the night while Diplo and Midnight Mary kept the party pulsing from behind the decks.

Ukrainian Parliament Rejects Porn Decriminalization Bill

The Verkhovna Rada, Ukraine’s parliament, on Thursday voted against passage of a bill that would have decriminalized the creation and distribution of pornography in that country — an activity that currently carries a prison sentence of three to five years.

FSC Launches Pride Fundraising Drive

The Free Speech Coalition (FSC) has launched its Pride Fundraising Drive to support its efforts on behalf of the LGBTQ+ community.

Cultpix Debuts AI-Generated Vintage Adult Films at Cannes

At this year’s Cannes Film Festival, B-movie streaming service Cultpix debuted a collection of AI-generated short films drawn from erotic magazine photo spreads published 50 years ago.

Ofcom Fines Youngtek Solutions $800K for AV Noncompliance

U.K. media regulator Ofcom on Wednesday imposed fines totaling 600,000 pounds (more than $800,000) against adult site operator Youngtek Solutions for failing to implement age checks and respond to information requests as required for compliance with the Online Safety Act.

Pornhub Launches Lesbian Site 'Pornhub Sapphic'

Pornhub has launched Pornhub Sapphic, a site dedicated to female and non-binary content and creators.

Show More