REPORTS
PROGRAMS
PUBLISHERS
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'HackerOne'
disclosed a bug submitted by
b'c666a323be94d57'
b'RCE in profile picture upload'
08 Jun 2016
b'Coinbase'
disclosed a bug submitted by
b'anik'
b'Transaction Pending Via Ip Change '
07 Jun 2016
b'Uber'
disclosed a bug submitted by
b'err'
b'Password Reset Does Not Confirm the Existence of an Email Address'
07 Jun 2016
b'New Relic'
disclosed a bug submitted by
b'the_joker'
b'Session takeover'
06 Jun 2016
b'QIWI'
disclosed a bug submitted by
b'ngaurav'
b'SSL Certificate on qiwi.com will expire soon.'
06 Jun 2016
b'Uber'
disclosed a bug submitted by
b'jouko'
b'Compromising Atlassian Confluence (team.uberinternal.com) via WordPress (newsroom.uber.com)'
06 Jun 2016
b'Uber'
disclosed a bug submitted by
b'jouko'
b'OneLogin authentication bypass on WordPress sites'
06 Jun 2016
b'Automattic'
disclosed a bug submitted by
b'akshyy'
b"Remove anyone's pic gravtar"
05 Jun 2016
b'Badoo'
disclosed a bug submitted by
b'esevece'
b'Tokens from services like Facebook can be stolen'
03 Jun 2016
b'Badoo'
disclosed a bug submitted by
b'saeedhashem'
b"Ability to collect users' ids that have visited a specific web page with malicious code "
03 Jun 2016
b'Ubiquiti Networks'
disclosed a bug submitted by
b'ebrietas'
b'Auth bypass on directory.corp.ubnt.com'
02 Jun 2016
b'WePay'
disclosed a bug submitted by
b'krankopwnz'
b'Unauthenticated Stored XSS in API Panel'
02 Jun 2016
b'Shopify'
disclosed a bug submitted by
b'ogig'
b'SVG parser loads external resources on image upload'
02 Jun 2016
b'Mapbox'
disclosed a bug submitted by
b'dawgyg'
b'Reflected cross-site scripting (XSS) on api.tiles.mapbox.com'
01 Jun 2016
b'Zendesk'
disclosed a bug submitted by
b'eboda'
b'Stored XSS on [your_zendesk].zendesk.com in Facebook Channel'
01 Jun 2016
b'Zendesk'
disclosed a bug submitted by
b'albinowax'
b'Stored XSS via Angular Expression injection on developer.zendesk.com'
01 Jun 2016
b'LocalTapiola'
disclosed a bug submitted by
b'reactors08'
b'www.lahitapiola.fi DOM XSS by choosing regional company'
01 Jun 2016
b'Algolia'
disclosed a bug submitted by
b'bugs3ra'
b'No rate-limit in Two factor Authentication leads to bypass using bruteforce attack'
01 Jun 2016
b'Algolia'
disclosed a bug submitted by
b'bugs3ra'
b'API Key added for one Indices works for all other indices too.'
01 Jun 2016
b'Algolia'
disclosed a bug submitted by
b'bugs3ra'
b'PHP version disclosed on blog.algolia.com'
01 Jun 2016
1
...
679
680
681
682
683
...
776
BY DENIS WERNER - @NOBBD -
IMPRESSUM