How I could've taken over the production server of a Yahoo acquisition through command injection
samcurry.net | blog | #bug-bounty | #rce | #reconnaissance | #web-security | #command-injection | #yahoo
Summary
Following a banned researcher's trail, Sam Curry found a getImg.php endpoint on a Yahoo acquisition where command injection in image handling could have taken over the production server.
- Published
- Collected
Skip to content