eBay , and then attack users through the downloads.
The first bug resulted from an eBay to check the file headers of an image uploaded by users. An attacker could take advantage of this to upload a malicious file disguised as an image, which the server would then accept and decrypt.
"The site server fails to implement secure header checking of image file uploads to the server. It essentially validates the image extensions. Therefore, it is possible to upload a disguised malicious file (EXE, PDF, etc.) with an image file extension," said Aditya Sood, one of the researchers who discovered the vulnerabilities in a post.
If an attacker were able to upload a file of their choosing, they could embed malware of their choosing into that file. But the second vulnerability could make a potential attack even more serious. This bug arose from the fact that when a user successfully uploads a file, the website server returns a message with the exact path to the file.
"The attacker can upload a malicious .exe filedisguised as an image file and then use the URL for download attacks," Sood said.
"Or the attacker could also hide a malicious executable in the image file that runs on the end user's system when the image file is opened.".

