REPORTS
PROGRAMS
PUBLISHERS
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Monero'
disclosed a bug submitted by
b'ovrflow'
b'Out-of-bounds read when importing corrupt blockchain with monero-blockchain-import'
25 Apr 2018
b'Monero'
disclosed a bug submitted by
b'yukichen'
b'Buffer out of bound read in miniupnpc xml parser '
25 Apr 2018
b'Node.js third-party modules'
disclosed a bug submitted by
b'bl4de'
b'[mcstatic] Path Traversal allows to read content of arbitrary files'
24 Apr 2018
b'Paragon Initiative Enterprises'
disclosed a bug submitted by
b'foobar7'
b'Airship: Persistent XSS via Comment'
24 Apr 2018
b'New Relic'
disclosed a bug submitted by
b'grampae'
b'Drupal admin takeover via install.php not being performed prior to install.'
23 Apr 2018
b'Rockstar Games'
disclosed a bug submitted by
b'netfuzzer'
b"SocialClub's Facebook OAuth Theft through Warehouse XSS."
23 Apr 2018
b'Rockstar Games'
disclosed a bug submitted by
b'exception'
b'Bypass CAPTCHA protection'
23 Apr 2018
b'Ed'
disclosed a bug submitted by
b'karel_origin'
b'DOM XSS in edoverflow.com/tools/respond due to unsafe usage of the innerHTML property.'
23 Apr 2018
b'Automattic'
disclosed a bug submitted by
b'edoverflow'
b'Stored XSS in learnboost.com via the lesson[goals] parameter.'
22 Apr 2018
b'Automattic'
disclosed a bug submitted by
b'edoverflow'
b'Stored XSS in www.learnboost.com via ZIP codes.'
22 Apr 2018
b'Paragon Initiative Enterprises'
disclosed a bug submitted by
b'cablej'
b'Incomplete fix for #181225 (target=_blank vulnerability)'
20 Apr 2018
b'ExpressionEngine'
disclosed a bug submitted by
b'khaledibnalwalid'
b'RCE By import channel field'
20 Apr 2018
b'ExpressionEngine'
disclosed a bug submitted by
b'flex0geek'
b'[EE] change the author of post using the author_id'
20 Apr 2018
b'ExpressionEngine'
disclosed a bug submitted by
b'flex0geek'
b'[EE] Spoof the redirect process'
20 Apr 2018
b'Khan Academy'
disclosed a bug submitted by
b'conan0x7'
b'CSRF token fixation and potential account takeover'
19 Apr 2018
b'Rockstar Games'
disclosed a bug submitted by
b'europa'
b'Stored XSS in Snapmatic + R?Editor comments'
19 Apr 2018
b'Unikrn'
disclosed a bug submitted by
b'albatraoz'
b"CSRF logs the victim into attacker's account"
19 Apr 2018
b'Node.js third-party modules'
disclosed a bug submitted by
b'caioluders'
b'[pdfinfojs] Command Injection on filename parameter'
19 Apr 2018
b'HackerOne'
disclosed a bug submitted by
b'd4rk_g1rl'
b'Email Forwarding invitations for Drafts are not marked as accepted, allowing multiple users to join a program after disabling Email Forwarding'
18 Apr 2018
b'Shopify'
disclosed a bug submitted by
b'bastianwelfrid'
b'Stored XSS in partners dashboard'
18 Apr 2018
1
...
500
501
502
503
504
...
772
BY DENIS WERNER - @NOBBD -
IMPRESSUM