Another bug in Yahoo has been discovered, which ran on an old server kernel and allows root access to its system, according to security researcher Ebrahim Hegazy.
Hegazy found that by executing one of the URL parameters used in Yahoo Mail, he could cause the server to execute system commands remotely.
On Yahoo 's end , the parameter is used inside a PHP eval() function, which takes strings (the parameter Hegazy used) and executes as PHP code. The PHP function's documentation explicitly warns against using it where possible, and as a last resort. This validation process does not appear to have occurred; Hegazy was able to use a combination of print() and system() functions to execute the commands and return the results.

