Uber Rider RCE
In early 2016, a security bug was reported to Uber, allowing remote code execution on rider.uber.com. This bug allowed an adversary to execute arbitrary commands on the Uber server. The bug was due to the insecure usage of a template engine. Let's explore what this security bug is and how to prevent it.