Security researcher Behrouz Sadeghipour has uncovered several vulnerabilities in Yahoo Taiwans Fashion subdomain. The list of security holes includes authentication bypass, and full path and MySQL credentials disclosure.
First, the expert uncovered a login page for the Fashion section of the website. However, he managed to bypass the authentication, which enabled him to add new content, edit content and even upload files.
Sadeghipour has also found a full path disclosure flaw and has …