HomeSecurityCritical vulnerability identified on Yahoo website

Critical vulnerability discovered on Yahoo website

yahoo-remote-code-execution-vulnerability-process-list

Researcher Ebrahim Hegazy discovered a critical PHP Code Injection vulnerability in a Yahoo, which could allow the insertion and remote execution of arbitrary PHP code on the company's server.

The vulnerability exists in the following Yahoo Taiwan sub-domain “https://tw.user.mall.yahoo.com/rating/list?sid = [ CODE_Injection ]” and the 'sid' parameter is what allows PHP code injection.

In the demo he posted, Ebrahim showed how he gained access to directories and process lists by inserting the following code:

https://tw.user.mall.yahoo.com/rating/list?sid=${@print(system(“dir”))}

https://tw.user.mall.yahoo.com/rating/list?sid=${@print(system(“ps”))}

The researcher also discovered that Yahoo's server uses an old kernel that is vulnerable to "local privilege escalation" vulnerabilities.

Yahoo immediately patched the vulnerabilities after being notified by the researcher, whose reward has not yet been announced.

Google rewards researchers with $20,000 for such vulnerabilities, while Yahoo has set a maximum reward of $15,000. Let's see how generous Yahoo will be this time.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS