Jump to content

Flash header and Java script security issue


Guest redback

Recommended Posts

Guest redback

Hello,

I am using a javascript in my header to display a flash banner and a banner .jpg version for those who dont the flash version.

I am getting the following message-

"this page contains both secure and nonsecure items? do you want to display the nonsecure items"

Here is the Java Script;

<script LANGUAGE=JavaScript1.1>

<!--

var MM_contentVersion = 6;

var plugin = (navigator.mimeTypes && navigator.mimeTypes["application/x-shockwave-flash"]) ? navigator.mimeTypes["application/x-shockwave-flash"].enabledPlugin : 0;

if ( plugin ) {

var words = navigator.plugins["Shockwave Flash"].description.split(" ");

for (var i = 0; i < words.length; ++i)

{

if (isNaN(parseInt(words)))

continue;

var MM_PluginVersion = words;

}

var MM_FlashCanPlay = MM_PluginVersion >= MM_contentVersion;

}

else if (navigator.userAgent && navigator.userAgent.indexOf("MSIE")>=0

&& (navigator.appVersion.indexOf("Win") != -1)) {

document.write('<SCR' + 'IPT LANGUAGE=VBScript\> \n'); //FS hide this from IE4.5 Mac by splitting the tag

document.write('on error resume next \n');

document.write('MM_FlashCanPlay = ( IsObject(CreateObject("ShockwaveFlash.ShockwaveFlash." & MM_contentVersion)))\n');

document.write('</SCR' + 'IPT\> \n');

}

if ( MM_FlashCanPlay ) {

document.write('<OBJECT classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000"');

document.write(' codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,0,0" ');

document.write(' ID="script" WIDTH="770" HEIGHT="110" ALIGN="">');

document.write(' <PARAM NAME=movie VALUE="/store/images/motel3.swf"> <PARAM NAME=quality VALUE=high> <PARAM NAME=bgcolor VALUE=#FFFFFF> ');

document.write(' <EMBED src="/store/images/motel3.swf" quality=high bgcolor=#FFFFFF ');

document.write(' swLiveConnect=FALSE WIDTH="770" HEIGHT="110" NAME="script" ALIGN=""');

document.write(' TYPE="application/x-shockwave-flash" PLUGINSPAGE="http://www.macromedia.com/go/getflashplayer">');

document.write(' </EMBED>');

document.write(' </OBJECT>');

} else{

document.write('<IMG SRC="/store/images/banner.jpg" WIDTH="770" HEIGHT="110" usemap="#script" BORDER=0>');

}

//-->

</SCRIPT>

Any assistance in removing the security message would be greatly apprectiated.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...