Security researcher, Jordan Jones claims and tweeted from his account that he already reported the critical flaw to eBay, along with a proof-of-concept screenshot which shows that he has successfully uploaded a 'shell.php' file (as shown), a PHP script that allows the attacker to control the server - essentially a backdoor program.