# CVE-2011-2461_Magento_Patch
## By [Edmonds Commerce](https://www.edmondscommerce.co.uk)
This CVE relates to a CSRF vulnerability in the Adobe Flex .swf files used by Magento.
You can find more information regarding the CVE here:
* [Peter O'Callaghan - Magento CSRF vulnerability via Adobe Flex](https://peterocallaghan.co.uk/2016/07/magento-csrf-vulnerability-via-adobe-flex/)
* [Minded Security - The old is new, again. CVE-2011-2461 is back!](http://blog.mindedsecurity.com/2015/03/the-old-is-new-again-cve-2011-2461-is.html)
* [Adobe - Flex Security Issue APSB11-25](https://helpx.adobe.com/flash-builder/kb/flex-security-issue-apsb11-25.html)
# The Files
This repo contains patched versions of editor.swf, uploader.swf and uploaderSingle.swf.
# Install
Simply replace the files in skin/adminhtml/default/default/media/ with these.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view