More CSRF issues with Flash crossdomain policy files

More and more, web app security looks like a house of cards.

forging arbitrary HTTP request headers with Flash


That's a pretty nasty vulnerability.

