Security researcher Stefan Schurtz has found an open redirect vulnerability on Yahoos ads.yahoo.com domain.
Schurtz said he notified Yahoo about the security hole in mid-December. However, Yahoo hasnt fixed the issue and hasnt provided any feedback, except to say that open redirects are no longer included in the bug bounty program.
The researcher says the piggyback parameter on the domain can be abused to redirect users to arbi…