Exploit - https://github.com/gursev/flash-xdomain-xploit
Exploit - https://sethsec.blogspot.com/2014/03/exploiting-misconfigured-crossdomainxml.html
Using Flash - https://gursevkalra.blogspot.com/2013/08/bypassing-same-origin-policy-with-flash.html