Is there any security issue if I allow end users to upload .SWF file (not FLV), and then play it with the SWFTOOLS?
I only want user to upload the safe .SWF animation file, but am afraid of some malicious intent to embed some SWF file with damaging programming code....please help and advise what is the safest way to achieve this. Thanks/

Comments

ron williams’s picture

Status: Active » Closed (works as designed)

The SWF Tools module is provided to display the appropriate swf player for various media types. It is not intended to 'check' swf's for malicious code, nor is it intended to allow upload and embed of SWF's. I'd recommend asking in the forums regarding this.