REPORTS
PROGRAMS
PUBLISHERS
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Infogram'
disclosed a bug submitted by
b'bluedangerforyou'
b'Login Cross Site Request Forgery '
27 Oct 2017
b'Infogram'
disclosed a bug submitted by
b'saikiran-10098'
b'User Enumeration'
27 Oct 2017
b'IRCCloud'
disclosed a bug submitted by
b'd0rkerdevil'
b'Missing robots exclusion header for user uploads'
27 Oct 2017
b'Infogram'
disclosed a bug submitted by
b'kiddie'
b'User enumeration via forgot password error message'
27 Oct 2017
b'Grabtaxi Holdings Pte Ltd'
disclosed a bug submitted by
b'poison'
b'CSV Injection https://hub.grab.com'
27 Oct 2017
b'Zomato'
disclosed a bug submitted by
b'prateek_0490'
b'[www.zomato.com/dubai/gold] CRITICAL - Allowing abitraty amount to become a GOLD MEMBER can lead to HUGE loss for ZOMATO'
27 Oct 2017
b'Zomato'
disclosed a bug submitted by
b'prateek_0490'
b'[www.zomato.com] Unauthenticated access to Internal Sales Data of Zomato through an unrestricted endpoint'
27 Oct 2017
b'Zomato'
disclosed a bug submitted by
b'prateek_0490'
b'[www.zomato.com] IDOR - Leaking all Personal Details of all Zomato Users through an endpoint'
27 Oct 2017
b'Inflection'
disclosed a bug submitted by
b'gopalsingh27'
b'Limited Account Takeover via Backup codes '
26 Oct 2017
b'MapsMarker.com e.U.'
disclosed a bug submitted by
b'nih95had'
b'facebook button URL should be HTTPS'
26 Oct 2017
b'Tor'
disclosed a bug submitted by
b'xiaoyinl'
b'Cross-domain linkability when system time changed in Tor Browser'
26 Oct 2017
b'HackerOne'
disclosed a bug submitted by
b'reydd'
b'Report Private Links Leaks to Google Analytics via Query String Param'
25 Oct 2017
b'Quora'
disclosed a bug submitted by
b'hk755a'
b'IDNs displayed in unicode'
25 Oct 2017
b'Tor'
disclosed a bug submitted by
b'julianjackson'
b'Linux TBB SFTP URI allows local IP disclosure'
25 Oct 2017
b'Tor'
disclosed a bug submitted by
b'geeknik'
b'Use of uninitialized value in memarea_strdup (src/common/memarea.c:369)'
25 Oct 2017
b'Inflection'
disclosed a bug submitted by
b'namansahore'
b'Fake mailing reports using mail service on [URL : mail-txn.identity.com]'
25 Oct 2017
b'VK.com'
disclosed a bug submitted by
b'lincoln9932'
b'CSRF ???????? ???????? ? ?????? ??? ?????? ????????????.'
25 Oct 2017
b'Ruby'
disclosed a bug submitted by
b'usa'
b'Ruby 2.3.x and 2.2.x still bundle DoS vulnerable verision of libYAML'
25 Oct 2017
b'Ruby'
disclosed a bug submitted by
b'dgollahon'
b'Parsing invalid unicode codepoints using json c extension (2.0.1+) triggers a segfault'
25 Oct 2017
b'VK.com'
disclosed a bug submitted by
b'alibaba_orange'
b'XSS ? ??????????? ? ??????'
25 Oct 2017
1
...
528
529
530
531
532
...
765
BY DENIS WERNER - @NOBBD -
IMPRESSUM