Flickr vulnerable to SQL Injection and Remote Code Execution Flaws
Now Security Researcher are on the fire mood, I think. Last week was one of the vulnerable week for the internet. As researcher have found Heartbleed vulnerability that puts almost three-fourth (3/4) of the worlds websites in a vulnerable side. After this Researcher form Detectify have found the critical vulnerability on the Google products that leads to read the 'etc/passwd' and 'etc/host' file of the Google Server.

Now once again another biggest photo sharing site Flickr  (owned by Yahoo.Inc) have suffered from sever vulnerability. A security researcher Ibrahim Raafat from Egypt have found the SQL injection vulnerability on the Flickr site.

Raafat claims that he has found two parameters ( page_id and items ) vulnerable to Blind SQL injection and one (Order_id) vulnerable to direct SQL injection. This vulnerable allow the attacker to read the Flickr database. Further more a successful SQL exploitation can allow attacker to gain database and MYSQL login credentials, by injecting the SQL query.

Flickr hacked, Flickr vulnerable to SQL Injection and Remote Code Execution Flaws, Flickr vulnerable, Flickr SQL injection, Flickr remote code execution, hackers area, security researcher, Flickr  rewards, Flickr  hacked, yahoo hacked, hacking yahoo products, security researcher, bug bounty products, Heat bleed vulnerability

Further more Researcher explains that, SQL injection vulnerability on Flickr allows the attacker to produce its attack to Remote Code Execution on the server and using load_file(“/etc/passwd“) function he was successfully managed to read the content from the sensitive files on the Flickr server, as shown below: 

Flickr hacked, Flickr vulnerable to SQL Injection and Remote Code Execution Flaws, Flickr vulnerable, Flickr SQL injection, Flickr remote code execution, hackers area, security researcher, Flickr  rewards, Flickr  hacked, yahoo hacked, hacking yahoo products, security researcher, bug bounty products, Heat bleed vulnerability

Raafat have also shows the Video demonstration that the vulnerability allows to write new files on the server that let him upload a custom 'code execution shell'.


Post a Comment

  1. Hello world
    I teach hacking andriod apk virus - windows Hacking - web server hacking -
    Reseller :- Hacking Tools & Hacking services, Also Teach Hacking Methods Via teem weaver or Anydesk,
    Each Method Take minimum 1 hour to learn with vedio Tutorial And Hacking Tools ,

    How to Make Money hacking tools,

    - Spamming & Tools ,
    - Carding & Tools ,
    - Virus with control panal and Spy bot files,
    - Virus With Builder And Crypter ,
    - Scanners with Bruters ,
    - Crypters with Doc Exploits ,pdf Exploits ,TExtfile Exploits ,
    - PHP Exploits with shell and mailer
    - OTP verications Bypass with Bulletproof Scam-page and Otp control
    - Company Ceo or cfo leads Any country
    - Rat virus with builder
    - Cookies Stealers and Builder
    - keyloger and builder
    - Credit card Scam-pages
    - Bank login Scam-pages
    - debit card topup scam page
    - donation scam-page
    - dhl login and tracking scam-page
    - fedax login and tracking scam-page
    - Shipping Tools

    Place & Ground
    learners you will pay cheap $ for demo Tools & Method

    Business grounds

    Credit card Low Interest Services,

    - Credit card with Fullz Information - Minimum Investment 150$ - With 50k Credit limit And balance
    - Debit Card Topup AS per Card limit - Minimum Investment 200$ - With 8000$ balance
    - Dating scam Fresh male female Logins - Minimum Investment 80$ - Dating Login upto 30

    -----------------
    ABOUT US :
    Icq :-675452902
    Skype: rushr00t000
    email me:- hackitbackd00r@gmail.com

    ReplyDelete
  2. Selling good and fresh cvv fullz

    track 1 and 2 with pin

    bank login

    bank transfer

    writing cheques

    transfer to cc ...

    Sell Fresh CVV - Western Union Transfer - Bank Login - Card Dumps - Paypal - Ship

    Fresh Cards, Selling Dumps, Cvvs, Fullz

    Tickets,Hotels,Credit card topup...Paypal transfer, Mailer,Smtp,western union login,

    Book Flight Online

    SELL CVV GOOD And HACK BIG CVV GOOD Credit Card

    Fresh Cards. Selling Dumps, Cvvs, Fullz.Tickets,Hotels,Credit cards


    Sell Cvv(cc) - Wu Transfer - Card Dumps - Bank login/paypal

    And many more other hacking services

    contact me : hackerw169@gmail.com
    ICQ: 699 396 818


    - I have account paypal with good balance

    - I hope u good customers and will be long-term cooperation


    Prices Western Union Online Transfer


    -Transfer(Eu,Uk,Asia,Canada,Us,France,Germany,Italy and very

    easy to do African)

    - 200$ = 1500$ (MTCN and sender name + country sender)

    - 350$ = 4000$ (MTCN and sender name + country sender)

    - 500$ = 6000$ (MTCN and sender name + country sender)

    - 600$ = 8000$ (MTCN and sender name + country sender)

    Then i will do transfer's for you, After about 30 mins you'll have

    MTCN and sender name + country sender


    - Dumps prices

    - Tracks 1&2 US = 85$ per 1

    - Tracks 1&2 UK = 100$ per 1

    - Tracks 1&2 CA / AU = 110$ per 1

    - Tracks 1&2 EU = 120$ per 1


    Bank Logins Prices US UK CA AU EU


    - Bank Us : ( HALIFAX,BOA,CHASE,Wells Fargo...)

    . Balance 5000$ = 250$

    . Balance 8000$ = 400$

    . Balance 12000$ = 600$

    . Balance 15000$ = 800$

    . Balance 20000$ = 1000$

    - Bank UK : ( LLOYDS TSB,BARCLAYS,Standard Chartered,HSBC...)

    . Balance 5000 GBP = 300 GBP

    . Balance 12000 GBP = 600 GBP

    . Balance 16000 GBP = 700 GBP

    . Balance 20000 GBP = 1000 GBP

    . Balance 30000 GBP = 1200 GBP


    contact me : hackerw169@gmail.com
    ICQ: 699 396 818

    ReplyDelete
  3. **FULLZ AVAILABLE WITH HIGH CREDIT SCORES**
    (Spammed From Credit Bureau of USA)

    **TOOLS & TUTORIALS AVAILABLE FOR HACKING SPAMMING CARDING**

    =>Contact 24/7<=

    Telegram> @killhacks
    ICQ> 752822040
    Skype> Peeterhacks

    FRESHLY SPAMMED
    VALID INFO WITH VALID DL EXPIRIES

    *All info included*
    NAME+SSN+DOB+DL+DL-STATE+ADDRESS
    Employee & Bank details included

    CC & CVV'S ONLY USA AVAILABLE

    $1 for SSN+DOB
    $2 for SSN+DOB+DL
    $5 for High credit fullz 700+
    (bulk order negotiable)
    *Payment in all crypto currencies will be accepted

    ->You can buy few for testing
    ->Serious buyers contact me for long term business
    ->Genuine & Verified stuff

    PLEASE DON'T ASK ANYTHING FOR FREE

    TOOLS & TUTORIALS AVAILABLE FOR
    (Carding, spamming, hacking, scam page, Cash outs, dumps cash outs)

    Ethical Hacking Tools & Tutorials
    Kali linux
    Facebook & Google hacking
    SQL Injector
    Bitcoin flasher
    Viruses
    Keylogger & Keystroke Logger
    Premium Accounts (Netflix, coinbase, FedEx, Pornhub, etc)
    Paypal Logins
    Bulk SMS Sender
    Bitcoin Cracker
    SMTP Linux Root
    DUMPS with pins track 1 and 2 with & without pin
    Smtp's, Safe Socks, rdp's, VPN, Viruses
    Cpanel
    Php mailer
    Server I.P's & Proxies
    HQ Emails Combo

    *If you need a valid vendor I'm here for you, you'll never be disappointed*

    CONTACT 24/7
    Telegram> @killhacks
    ICQ> 752822040
    Skype> Peeterhacks

    ReplyDelete

 
Top