A pair of eBay vulnerabilities could have left users of the online auction site open to malware and drive-by download attacks. Security researcher Aditya Sood said one of the eBay vulnerabilities involved a failure to ensure malware wasnt camouflaged within the image extensions of a file. Sood also said that eBay was returning messages with an identical file path. Earlier research uncovered a way to use specially designed links to potentially take over any eBay account. A spokesperson told Ecommercebytes the current eBay vulnerabilities have already been fixed.”]
Source: https://securityintelligence.com/news/security-researcher-ebay-vulnerabilities-led-drive-attacks/

