Security researcher Ibrahim Raafat was able to gain access to Flickr databases when he discovered an SQL Injection vulnerability in the Photo Books section. The expert also found a remote code execution vulnerability.
Raafat initially found two Blind SQL Injection vulnerabilities in the “Checkout” field of Flickr Photo Books, which the sharing site introduced in November 2013.
The researcher reported his findings, but received no response for eight days. After further searching the website, he was able to identify an SQL Injection flaw that he could exploit to gain access to Flickr databases, including the MySQL root password.
The expert then went even further and managed to write files and execute code on the server. After his second report, Yahoo, which owns Flickr, addressed the vulnerabilities within 6 hours.
Last week, Yahoo fixed some bugs in Flickr that had been around for two months before being taken seriously by the company.
Take a look at the video posted by the expert:

