martedì, giugno 17, 2008

JavaScript and VBScript Injection in ActionScript 3

Heady stuff. The title says it all, doesn’t it? Of course, it would be easy to imagine how nefarious types might abuse this…

“In AS Script Injection, complete and unmodified JavaScript and/or VBScripts are stored inside AS3 files using XML, and are then parsed and sent to the browser, typically using the ExternalInterface class."