REPORTS
PROGRAMS
PUBLISHERS
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'concrete5'
disclosed a bug submitted by
b'r3naissance'
b"'cnvID' parameter vulnerable to Insecure Direct Object References"
15 Apr 2018
b'Automattic'
disclosed a bug submitted by
b'mattaustin'
b'Remote Code Execution in Wordpress Desktop'
14 Apr 2018
b'Zomato'
disclosed a bug submitted by
b'hacker_one_one'
b'URL is vulnerable to clickjacking'
14 Apr 2018
b'Imgur'
disclosed a bug submitted by
b'protector47'
b'Information disclosure (No rate limting in forgot password & other login)'
14 Apr 2018
b'LocalTapiola'
disclosed a bug submitted by
b'putsi'
b'Flash-based XSS on mediaelement-flash-audio-ogg.swf of www.lahitapiolarahoitus.fi'
13 Apr 2018
b'Upserve '
disclosed a bug submitted by
b'paresh_parmar'
b'Blind stored xss in demo form'
12 Apr 2018
b'Mail.Ru'
disclosed a bug submitted by
b'101usb'
b'[tanks.mail.ru] Open Redirect'
12 Apr 2018
b'Shopify'
disclosed a bug submitted by
b'newbie_101'
b'Order notifications being sent for a deactivated staff account'
12 Apr 2018
b'LocalTapiola'
disclosed a bug submitted by
b'tan_stream'
b'The parameter in the POST query allows to control size of returned page which in turn can lead to the potential DOS attack'
11 Apr 2018
b'LocalTapiola'
disclosed a bug submitted by
b'curiositysec'
b'Exposed authentication (/cs/Satellite)'
11 Apr 2018
b'LocalTapiola'
disclosed a bug submitted by
b'teemuk'
b'Reflected XSS Vulnerability in https://www.lahitapiola.fi/cs/Satellite'
11 Apr 2018
b'Rockstar Games'
disclosed a bug submitted by
b'tolo7010'
b'Your support community suffers from angularjs injection and must be fixed immediately [CRITICAL]'
10 Apr 2018
b'LocalTapiola'
disclosed a bug submitted by
b'bugdiscloseguys'
b'CSRF possible when SOP Bypass/UXSS is available'
10 Apr 2018
b'LocalTapiola'
disclosed a bug submitted by
b'muon4'
b'Malicious file upload (secure.lahitapiola.fi)'
10 Apr 2018
b'Unikrn'
disclosed a bug submitted by
b'tolo7010'
b'CSRF log victim into the attacker account'
10 Apr 2018
b'Unikrn'
disclosed a bug submitted by
b'tolo7010'
b'session_id is not being validated at email invitation endpoint'
10 Apr 2018
b'Unikrn'
disclosed a bug submitted by
b'tolo7010'
b'CSRF in Raffles Ticket Purchasing'
10 Apr 2018
b'LocalTapiola'
disclosed a bug submitted by
b'putsi'
b'Reflected XSS on bbe_open_htmleditor_popup.php of BBE Theme via "value"-GET-parameter'
09 Apr 2018
b'MyCrypto'
disclosed a bug submitted by
b't-pwn'
b'HTML Injection on https://www.mycrypto.com/'
09 Apr 2018
b'LocalTapiola'
disclosed a bug submitted by
b'jacksonkv67'
b'xmlrpc.php FILE IS enable it will used for bruteforce attack and denial of service'
09 Apr 2018
1
...
502
503
504
505
506
...
772
BY DENIS WERNER - @NOBBD -
IMPRESSUM