Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

How I could've taken over the production server of a Yahoo acquisition through command injection

Summary

Following a banned researcher's trail, Sam Curry found a getImg.php endpoint on a Yahoo acquisition where command injection in image handling could have taken over the production server.
Published
Collected

original ↗

Related coverage

back