Cyber Attack | Data Breach

Published on April 14th, 2014 📆 | 6909 Views ⚑


Flickr vulnerable to SQL Injection and Remote Code Execution Flaws

Ibrahim Raafat, a security researcher from Egypt has found SQL injection vulnerabilities on Flickr Photo Books, new feature for printing custom photo books through Flickr that was launched 5 months ago.
He claimed to have found two parameters (page_id , items) vulnerable to Blind SQL injection and one  (i.e. order_id) Direct SQL Injection that allowed him to query the Flickr database for its content by the injection of a SQL SELECT statements.
[adsense size='1']
A Successful SQL exploitation could allow an attacker to steal the Database and MYSQL administrator password.
flickr sql injection
Furthermore, Flickr's SQL injection flaws also facilitate the attacker to exploit remote code execution on the server and using load_file(“/etc/passwd“) function he was successfully managed to read the content from the sensitive files on the Flickr server, as shown below:
flickr sql injection

In addition to this, Ibrahim was able to write new files on the server that let him upload a custom 'code execution shell'.

[adsense size='1']

Video Demonstration: 


He reported the vulnerability to Yahoo which have been patched.

Tagged with:

Comments are closed.