REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
58
b'ooooooo_q'
52
b'haxta4ok00'
49
b'jon_bottarini'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'RubyGems'
disclosed a bug submitted by
b'mame'
b'Installing a crafted gem package may create or overwrite files'
31 Aug 2017
b'Brave Software'
disclosed a bug submitted by
b'mattaustin'
b'URL Spoof / Brave Shield Bypass'
31 Aug 2017
b'Bookfresh'
disclosed a bug submitted by
b'stefanofindsbugs'
b'Reflected XSS on www.bookfresh.com/index.html?view=upload_form'
31 Aug 2017
b'Vimeo'
disclosed a bug submitted by
b'stefanofindsbugs'
b'Reflected XSS on vimeo.com/musicstore'
31 Aug 2017
b'Vimeo'
disclosed a bug submitted by
b'stefanofindsbugs'
b'Stored XSS on player.vimeo.com'
31 Aug 2017
b'Vimeo'
disclosed a bug submitted by
b'stefanofindsbugs'
b'XSS when using captions/subtitles on video player based on Flash (requires user interaction)'
31 Aug 2017
b'Vimeo'
disclosed a bug submitted by
b'stefanofindsbugs'
b'XSS on vimeo.com | "Search within these results" feature (requires user interaction)'
31 Aug 2017
b'Vimeo'
disclosed a bug submitted by
b'stefanofindsbugs'
b'XSS on vimeo.com/home after other user follows you'
31 Aug 2017
b'Vimeo'
disclosed a bug submitted by
b'stefanofindsbugs'
b'XSS on player.vimeo.com without user interaction and vimeo.com with user interaction'
31 Aug 2017
b'Badoo'
disclosed a bug submitted by
b'stefanofindsbugs'
b'Open redirect helps to steal Facebook access_token'
31 Aug 2017
b'Badoo'
disclosed a bug submitted by
b'stefanofindsbugs'
b'crossdomain.xml too permissive on eu1.badoo.com, us1.badoo.com, etc.'
31 Aug 2017
b'Vimeo'
disclosed a bug submitted by
b'stefanofindsbugs'
b'XSS on mobile version of vimeo.com where the button "Follow" appears'
31 Aug 2017
b'Weblate'
disclosed a bug submitted by
b'punkit'
b'Improper Cookie expiration | Cookies Expiration Set to Future '
31 Aug 2017
b'Legal Robot'
disclosed a bug submitted by
b'gujjuboy10x00'
b'No length limit in invite_code can cause server degradation'
31 Aug 2017
b'RubyGems'
disclosed a bug submitted by
b'claudijd'
b'Request Hijacking Vulnerability in RubyGems 2.6.11 and earlier'
30 Aug 2017
b'RubyGems'
disclosed a bug submitted by
b'mame'
b'Escape sequence injection in "summary" field'
30 Aug 2017
b'Coinbase'
disclosed a bug submitted by
b'danilg'
b'Inaccurate Payment receipt '
30 Aug 2017
b'Coinbase'
disclosed a bug submitted by
b'7h3_3y3'
b' Information disclosure in coinbase android app'
30 Aug 2017
b'Coinbase'
disclosed a bug submitted by
b'dark_heaven'
b'Csrf bug on signup session'
30 Aug 2017
b'Coinbase'
disclosed a bug submitted by
b'mandy1394'
b'Information disclosue in Android Application'
30 Aug 2017
1
...
505
506
507
508
509
...
727
BY DENIS WERNER - @NOBBD -
IMPRESSUM