Open redirect in proxy.php in FlashCanvas before 1.6 allows remote attackers to redirect users to arbitrary web sites and conduct cross-site scripting (XSS) attacks via the HTTP Referer header.
- http://www.7elements.co.uk/resources/blog/cve-2013-6880-proof-concept
No PoCs found on GitHub currently.