In all libraries SWFUpload (2.2.0.1, probably earlier versions + version Beta), Plupload of the version is lower 1.5.4(?) is found by XSS (in SWFUpload) and CSRF (in Plupload) vulnerability!
Hash sum vulnerable file swfupload.swf
CRC32: 5d875b2f
MD5: 3a1c6cc728dddc258091a601f28a9c12
SHA-1: 17c372678aafb3bc1a7b37320b5cc1d8af433527
Hash sum file bugfixed swfupload.swf:
CRC32: 1a2edc65
MD5: c0e5c70af799aeb906b1bef3b11e9a8d
SHA-1: 7156a56ffa8a90589951637c8c2833e84f3e8d4b
https://nealpoole.com/blog/2012/05/x...load-plupload/