HomeSecuritySQL Injection vulnerability in «Yahoo! Contributors Network»

SQL Injection vulnerability in "Yahoo! Contributors Network"

Yahoo!The Yahoo! Contributors Network (contributor.yahoo.com), the network of writers that provides content such as photos, videos, articles and knowledge to more than 600 million visitors each month, was vulnerable to a “Time based Blind SQL Injection” vulnerability.

Behrouz Sadeghipour, a security researcher, reported the Blind SQLI vulnerability on Yahoo's website, which could be exploited by hackers to steal users' database containing their personal information.

Behrouz reported this bug to Yahoo! a few months ago. The team responded positively and within a month successfully patched the vulnerability. Unfortunately, after that, Yahoo! announced that it would be shutting down the “Yahoo Contributors Network” due to its declining popularity and removed all content from the web, except for a few topics like “work for hire.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS