Home page logo

bugtraq logo Bugtraq mailing list archives

Flash player can read local files
From: jelmer <jkuperus () xs1 xs4all nl>
Date: Sun, 6 Oct 2002 14:24:00 +0200 (CEST)

The following message apperently bounced the first time i send it :s

Flash player can read local files


There is a flaw in the macromedia flash player wich allows reading and
sending of local files
The flaw lies in the fact that when a flash movie is loaded from a remote
smb share it is treated
as though it was loaded from the users harddisk.
Allowing the following action script code to work

urlXML = new XML();
urlXML.onLoad = readXML;
myField = "Loading data...";

function readXML() {
 myField = urlXML.toString();

It uses the flash's xml control to read and display the contents of
In order for it to work one has to get a user to view a specially crafted
webpage wich could look like this

<script language="javascript">

It points the browser to the swf on the smb share so that it displays it


Download the following file and extract the contained swf to a remote
start it from there (  for instance by dragging it from the share into
explorer or creating a html file as described above)


It will read and display the contents of c:\jelmer.txt

A live demonstration is not provided because it really isn't good practice
to open up smb shares to the
outside world and i am only able to host this sort of stuff at my home

vendor status

Macromedia was notified a long time ago  as far as I know they are still
looking in to it.

  By Date           By Thread  

Current thread:
  • Flash player can read local files jelmer (Oct 07)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]