Contact About
  • Store
  • Products
  • Support
  • Community
  • Snagit
  • Product Info
  • Tutorials
  • Free Trial
  • Buy
  • Camtasia Relay
  • Product Info
  • Tutorials
  • Free Trial
  • Buy
  • Screencast.com
  • Product Info
  • Tutorials
  • Free Account
  • Buy
  • Camtasia Studio
  • Product Info
  • Tutorials
  • Free Trial
  • Buy
  • Morae
  • Product Info
  • Tutorials
  • Free Trial
  • Buy
  • Coach's Eye
  • Product Info
  • Download Now
  • Camtasia for Mac
  • Product Info
  • Tutorials
  • Free Trial
  • Buy
  • Jing
  • Product Info
  • Tutorials
  • Free Download
See All Downloads
TechSmith Labs

We're experimenting with new ideas and technologies to see what sticks. Check out what we've cooked up and let us know what you think!

Visit Labs
Training Resources

Stop by our library of training resources and learn something new! Inside you'll find videos, tutorials, guides, and more to help you improve your use of TechSmith tools. You'll be a pro in no time!

Start Learning
Skip Navigation
Log In | Sign Up
Forgot your username or password?
  • Answers
  • Ask a Question
  • My Stuff Support History Account Settings Notifications

Search

Advanced Search
Screen Reader users press enter to Limit by product.  Limit by product
Search Tips
Search filters applied

Cross-site Scripting in Flash SWF Files

Answer ID
3188
  |    Published 08/18/2011 01:03 PM   |    Updated 08/18/2011 01:03 PM  |   
Access Level
Everyone

Date Issued: April 15th, 2008

Affected Software and Components: Camtasia Studio v1, v2, v3, v4, and v5 Flash content, except ExpressShow SWF content, the default in v5, which does not accept external input variables. Camtasia Studio v5.1 resolves this issue and is not affected by the vulnerability.

Vulnerability Description: If Flash content (for example, SWF files) is created by the above affected software and is embedded in a website, then the website hosting the Flash content may be vulnerable to cross-site scripting attacks. An attacker can submit malicious data to the vulnerable Flash content in order to perform a cross-site scripting attack: when the vulenerable Flash content is viewed by a website visitor, the visitor's Flash player may take insecure, potentially harmful actions. These actions include modification of website content or sending website information such as cookies to the attacker.

Workarounds or Mitigations: Customers concerned about creating secure Flash content should upgrade to Camtasia Studio v5.1. Customers concerned about viewing Flash content can upgrade their Flash player. Adobe reports that they have addressed the vulnerability with an update to Flash Player (v9.0.115.0), as explained at the following link: Adobe Security Bulletin

Additional Information: No other TechSmith products or services are affected by this vulnerability. SWF files created by the TechSmith Jing application are not affected by this vulnerability, since there is no user-controlled input passed to the SWF file. All Camtasia Studio SWF files hosted by TechSmith's Screencast.com media hosting site, created using any version of Camtasia Studio with any production options, are not affected by this vulnerability. Input parameters passed to the SWF files hosted on Screencast.com are provided by the Screencast.com service, which mitigates this vulnerability. All other TechSmith products do not produce or use SWF files.

Acknowledgements: TechSmith would like to thank Rich Cannings of the Google Security Team for reporting this issue to us.

How well did this answer your question?
Rate answer 5 of 5 Rate answer 4 of 5 Rate answer 3 of 5 Rate answer 2 of 5 Rate answer 1 of 5   
Please tell us how we can make this answer more useful.

Users who viewed this answer have also viewed

  • Cross-site Scripting in ExpressShow SWF Files created by Camtasia Studio
  • Configuration Manipulation and Cross-site Scripting Vulnerabilities in Flash SWF Files
  • DLL Preloading Vulnerability in Camtasia Studio and Snagit
  • The "Manager Service" component of Camtasia Relay version 1.1 and 1.2 can be called without authentication or authorization
  • Cross-site Scripting (XSS) Vulnerability in Camtasia Relay Admin Help HTML Files.
Share
  • Delicious
  • Digg
  • Facebook
  • Reddit
  • StumbleUpon
  • Twitter
Print
Email this page
Notify Me
Forgot your username or password?

Find Answers

Contact Us

Ask a Question Submit a question to our support team.
Give Feedback
How can we make this site more useful for you?
Powered By RightNow Technologies
Store
  • Buy Now
  • Volume Pricing
  • Education Pricing
  • Gov't/Non-Profit Pricing
  • Contact Sales
  • Find a Reseller
Products
  • Snagit
  • Camtasia Studio
  • Camtasia for Mac
  • Camtasia Relay
  • Morae
  • Jing
  • Screencast.com
  • Coach's Eye
Support
  • Tutorials
  • Tech Support
  • Lost Software Key
Community
  • Newsletters
  • Education Community
  • Education Blog
  • TechSmith Blog
  • Questions & Feedback
  • Social Media
About
  • Company History
  • Management Team
  • Press Room
  • Calendar of Events
  • Careers
  • Partner Programs
  • Presentation Materials
  • Contact Us

© 1995 - 2012, Corporation, All Rights Reserved.

  • Privacy Policy
  • Accessibility
  • Contact
  • Sitemap