Security researcher Ebrahim Hegazy has identified a remote code injection vulnerability affecting several domains from Yahoo, Orange, Microsoft, and possibly others. Fortunately, the vulnerability has been fixed.
The expert discovered the flaw while analyzing a Yahoo subdomain in Mexico, mx.horoscopo.yahoo.net. Here, he found an admin panel that could be accessed without login credentials. The researcher calls this an “unauthorized Administrator access” or “Indirect Object Reference” flaw.
From this table, Hegazy was able to upload his own aspx file to the server. The file could contain code that would allow an attacker to execute arbitrary code. However, the file uploaded for research purposes only contained a simple string of characters.
After recognizing the vulnerability, he tried to determine if other Yahoo domains were affected. To his surprise, he discovered that not only Yahoo subdomains were affected, but also MSN and Microsoft's French telecommunications company, Orange.
Watch the video below:

