Flash Player 9 April 2008 Security Update affects me too
So here I was, thinking that the Flash Player 9 security update (version 9.0.124) wasn’t going to affect me. A silly assumption, of course—I should have tested with the beta, regardless—but since I didn’t do anything fancy with sockets or web services, I thought I would be fine.
Ha!
I missed this section: “You have SWFs that are exported for Flash Player 7 (SWF7) or earlier that communicate with the hosting HTML by any means”.
And when they say “any means,” that includes LoadVars.send(), which I am using, in a SWF that is hosted on a different subdomain than the page which contains it (petswf.bunnyherolabs.com vs bunnyherolabs.com).
Luckily, the fix was simple: I just had to add the parameter allowScriptAccess = "always" to the embed tag. Phew!
Next time I see one of these announcements, I promise I will test it, even if I don’t think it applies to me



I tried your suggestion but couldn’t get it working. In my SWF I’m calling loadvars but sending the request to another IP address (ie, not were the original SWF came from)
What was your situation exactly?
Thanks!!