Embedding a flash video object in Adobe Dreamweaver CS3 or Adobe Contribute CS3 using the Insert Flash Video command might create a cross-site scripting vulnerability.
A potential cross-site scripting vulnerability has been identified within the FLVPlayer_Progressive.swf file.
- To purchase an upgrade from Adobe, visit the Adobe Store, click Software, and then click the link for the product you want to purchase.
- To locate an authorized reseller, visit the Adobe website at www.adobe.com/store/customerregistration/other_places.jhtml.
- Browse to the player's folder location:
- Contribute
- Windows
\Program Files\Adobe\Adobe Contribute CS3\Configuration\Templates\Video_Player - Mac OS
/Applications/Adobe Contribute CS3/Configuration/Templates/Video_Player
- Windows
- Dreamweaver
- Windows
\Program Files\Adobe\Adobe Dreamweaver CS3\configuration\Templates\Video_Player - Mac OS
/Applications/Adobe Dreamweaver CS3/configuration/Templates/Video_Player
- Windows
- Contribute
To mitigate this vulnerability on websites, site administrators that use the FLVPlayback_Progressive.swf component are encouraged to update their site by following these instructions:
- Preview the site in Dreamweaver using the "Preview In Browser" or in Contribute.
Note: Flash security settings may prevent Flash content from previewing if the content is stored on a local file folder. Please refer to "How do I let local Flash content communicate with the Internet" (TechNote 4c093f20.) for additional information on changing the security settings.
- Browse to the player's folder location:
- Contribute
- Windows
\Program Files\Adobe\Adobe Contribute CS3\Configuration\Templates\Video_Player - Mac OS
/Applications/Adobe Contribute CS3/Configuration/Templates/Video_Player
- Windows
- Dreamweaver
- Windows
\Program Files\Adobe\Adobe Dreamweaver CS3\configuration\Templates\Video_Player - Mac OS
/Applications/Adobe Dreamweaver CS3/configuration/Templates/Video_Player
- Windows
- Contribute
Please refer to the Security Bulletin APSD08-01 for additional information about the vulnerability.
Keywords:
kb402925

