A critical security flaw in the eBay website for its employees could allow an attacker to upload a backdoor shell,
claimed a security researcher, Jordan Jones who have unearthed the vulnerability.
Security researcher,
Jordan Jones claims and tweeted from his account that he already reported the critical flaw to eBay,
along with a proof-of-concept screenshot which shows that he has successfully uploaded a 'shell.php' file (as shown),
a PHP script that allows the attacker to control the server - essentially a backdoor program.