yahoo-smallbusiness

1 article
sort: new top best
clear filter
0 5/10

A security researcher describes discovering 3 vulnerabilities in Yahoo's bug bounty program: two remote code executions via command injection in a Brightroll queue management service (with filter bypass techniques), and an SSRF leading to arbitrary file read via curl flag injection in the Yahoo Small Business image processing endpoint.

Kedrisec Yahoo Brightroll RabbitMQ Aquatone Google AWS
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 17 hours ago · details