German security researcher David Vieira-Kurz discovered a critical vulnerability in the official Ebay website in particular in its sub domain http://sea.ebay.com that allows an attacker a remote code execution. The flaw seems to affect the server side and the way it casts a static GET parameter that could be exploited to provide any array values. The vulnerability was fixed by the Ebay Security Team that fixed it this week. The researcher published a POC video to demonstrate how to exploit the vulnerability.”]
Source: https://securityaffairs.co/wordpress/20461/hacking/ebay-remote-code-execution.html

