In Flash, flash.display.LoaderInfo.parameters is used to get some initial data on flash load, for example, the name of JS callback function to interact with.
The two sources of parameters are: the query string in the URL of the main SWF file, and the value of the FlashVars HTML parameter (this affects only the main SWF file).
The problem is that a bad person can inject ome JavaScript code via swf url, for example:
Usage: link FilterFlashVarsLibrary.swc
library from bin
folder and use itsfilterFlashVars
See the demo