REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
58
b'ooooooo_q'
52
b'haxta4ok00'
49
b'jon_bottarini'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'HackerOne'
disclosed a bug submitted by
b'japz'
b'Names not completely redacted despite "Redact the names of the involved users" is selected'
29 Aug 2023
b'Internet Bug Bounty'
disclosed a bug submitted by
b'shin24'
b'unsanitized input goes to regex function leads to ReDos that make request hangs'
28 Aug 2023
b'Internet Bug Bounty'
disclosed a bug submitted by
b'yadhukrishnam'
b'HTTP Request Smuggling via Empty headers separated by CR'
28 Aug 2023
b'inDrive'
disclosed a bug submitted by
b'kristoferent'
b'Stored XSS on promo.indrive.com'
28 Aug 2023
b'HackerOne'
disclosed a bug submitted by
b'zerotea'
b'Staff and Triage can modify the initial post of a report, including of already disclosed reports'
28 Aug 2023
b'Automattic'
disclosed a bug submitted by
b'riadalrashed'
b'Entering passwords on the Share Login Page can lead to a brute-force attack'
27 Aug 2023
b'Internet Bug Bounty'
disclosed a bug submitted by
b'kmhlyxj0'
b'jdbc apache airflow provider code execution vulnerability'
26 Aug 2023
b'Internet Bug Bounty'
disclosed a bug submitted by
b'kmhlyxj0'
b'odbc apache airflow provider code execution vulnerability'
26 Aug 2023
b'Glassdoor'
disclosed a bug submitted by
b'youstin'
b'Cache Poisoning allows redirection on JS files'
24 Aug 2023
b'LinkedIn'
disclosed a bug submitted by
b'tushar6378'
b'An Attacker Can Flag Draft Job Posts And Can Disclose The Draft Job Posts Details [ Similar to #1581528 Resolved Report]'
24 Aug 2023
b'LinkedIn'
disclosed a bug submitted by
b'find_me_here'
b'Attackers can use TRIAL Premium only by paying **IDR 10,000.00** from the original price of `IDR462,400.00` per month'
24 Aug 2023
b'LinkedIn'
disclosed a bug submitted by
b'tushar6378'
b'A Unverified User Can Post Newsletter (Which Is Not Allowed Through Application UI)'
24 Aug 2023
b'LinkedIn'
disclosed a bug submitted by
b'adilnbabras'
b"IDOR allows an attacker to delete anyone's featured photo."
24 Aug 2023
b'LinkedIn'
disclosed a bug submitted by
b'cybergoddess'
b'Improper access control on Linkedin Page'
24 Aug 2023
b'Uber'
disclosed a bug submitted by
b'lalit2020'
b"Complete Admin account takeover due to PhpDebugBar turned on in Uber's production server"
23 Aug 2023
b'Nextcloud'
disclosed a bug submitted by
b'rullzer'
b'Issuer not verified from obtained token in user_oidc '
23 Aug 2023
b'Nextcloud'
disclosed a bug submitted by
b'rullzer'
b'App stores client secret unencrypted in database'
23 Aug 2023
b'Nextcloud'
disclosed a bug submitted by
b'rullzer'
b"Text does not respect 'Allow download' permissions"
23 Aug 2023
b'Node.js'
disclosed a bug submitted by
b'leodog896'
b'Dependency Policy Bypass via process.binding'
23 Aug 2023
b'HackerOne'
disclosed a bug submitted by
b'sudi'
b'Bypass of #2035332 RXSS at image.hackerone.live via the `url` parameter'
22 Aug 2023
1
...
54
55
56
57
58
...
724
BY DENIS WERNER - @NOBBD -
IMPRESSUM