Ebrahim had now discovered a flaw in the Yahoo service which allows SQL Injection.

states Hibrahim in the blog post.

Inspecting theuploading request, the expert discovered the cause of the problem in the Content-throw in Header!

Yahoo service SQL Injection vulnerability allows Remote Code Execution

Renamingthe Content-jot down Header to be app/php the problems was solved.

Ebrahimsubmitted the Proof of Concept to Yahoo and Yahoo patched the vulnerability.

SQL Injection Yahoo 1

SQL Injection Yahoo 2

SQL Injection Yahoo 3

SQL Injection Yahoo 4

spot_img

source: www.techworm.net