HomeSecurityRemote code execution vulnerability in Yahoo servers leads to access

Remote code execution vulnerability in Yahoo servers leads to access

500px-Yahoo_Logo.svg__3

Another bug in Yahoo has been discovered, which ran on an old server kernel and allows root access to its system, according to security researcher Ebrahim Hegazy.

Hegazy found that by executing one of the URL parameters used in Yahoo Mail, he could cause the server to execute system commands remotely.

On Yahoo 's end , the parameter is used inside a PHP eval() function, which takes strings (the parameter Hegazy used) and executes as PHP code. The PHP function's documentation explicitly warns against using it where possible, and as a last resort. This validation process does not appear to have occurred; Hegazy was able to use a combination of print() and system() functions to execute the commands and return the results.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS