17-year-old security researcher Abdullah Hussam discovered an XSS vulnerability in the sIFR (Scalable Inman Flash Replacement) technology – which is used by several high-profile websites and allows text to be replaced with Flash, using JavaScript.
According to the researcher, the cross-site scripting vulnerability is located in a .SWF (Flash) file of the sIFR tool, while the list of vulnerable websites includes MasterCard, Visa, American Express, Amazon, BlackBerry, Adobe and a number of US universities.
Hussam points out that although several companies have patched the bug, there are still many websites that are still running a vulnerable version of sIFR.
Adobe fixed the issue about four months after receiving the report and added Abdullah Hussam's name to the acknowledgements for experts who have discovered vulnerabilities on the website or in Adobe products.
The researcher recently published a video, presenting his findings:
https://youtu.be/7WeIeJ_YYOQ

