Your bank (http://victim.com) is running its external-facing web application on Ruby on Rails. If you send a POST request to http://victim.com/transfer, you can transfer money to another person (the recipient is specified in the POST body).
The attacker sets up the following things on attacker.com:
1. A page that replies with 307 redirects to a specified destination
2. A Flash applet that makes POST requests
3. A page embedding that applet
The attacker sets the applet as if it were making a POST request to http://victim.com/transfer, setting the X-Requested-With header to bypass CSRF protection. But instead of POSTing directly to victim.com, the attacker POSTs to the redirect script.
So the end result looks something like this:
1. Flash checks to make sure that it can make requests to attacker.com (via crossdomain.xml, or by the same origin policy). It can.
2. POST request to attacker.com/redirect is made
3. attacker.com/redirect says "307, the request should go to http://victim.com/transfer
4. Flash says "OK" and makes the same request but now directed at victim.com
5. After the request has been made, Flash checks the crossdomain.xml file and says "whoops, shouldn't have made that request: you can't see the response."