Ibrahim Raafat, an Egyptian researcher , has uncovered a vulnerability in Yahoo! Suggestions that could be exploited by attackers to delete 365,000 posts and 1,155,000 comments posted by users on the site.
The expert identified an Insecure Direct Object Reference Vulnerability (IDORV) on Yahoo, Suggestions.yahoo.com. The flaw could allow an attacker to escalate user privileges and gain access to the page's threads database.
The researcher began by analyzing the requests sent when users post or delete a comment or topic. In the case of comments, the requests contained an ID parameter, the value of which was associated with each comment posted on the website.
By changing the parameter value, the researcher found that he could delete any comment. In the case of posts, the ID parameter did not exist, so the expert added it himself. Raafat then developed a script that allowed him to easily delete all topics by changing the IDs.
Raafat reported the vulnerability to Yahoo, which was patched within two days.
For more technical details, check out Ibrahim Raafat's blog and the following POC video posted on YouTube:

