REPORTS
PROGRAMS
PUBLISHERS
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Twitter'
disclosed a bug submitted by
b'mohaab007'
b'password sent over HTTP'
05 Aug 2014
b'Mavenlink'
disclosed a bug submitted by
b'niks'
b'privilege escalation'
05 Aug 2014
b'Twitter'
disclosed a bug submitted by
b'simon90'
b'Cookie not marked as secure.'
04 Aug 2014
b'Twitter'
disclosed a bug submitted by
b'guido'
b'XSS vulnerability in video player page'
02 Aug 2014
b'DC Compendium'
disclosed a bug submitted by
b'rodgodalle'
b'Multiple Full Path Disclosure (FPD) Vulnerability on Dccompendium.com domain'
02 Aug 2014
b'DC Compendium'
disclosed a bug submitted by
b'huzaifa_82'
b'Clickjacking: X-Frame-Options header missing'
01 Aug 2014
b'DC Compendium'
disclosed a bug submitted by
b'atom'
b'Login CSRF'
01 Aug 2014
wont-fix
b'DC Compendium'
disclosed a bug submitted by
b'huzaifa_82'
b'Forward Secrecy is disable'
01 Aug 2014
wont-fix
b'DC Compendium'
disclosed a bug submitted by
b'shahmeer_amir'
b'Backend source code disclosure on 404 pages'
01 Aug 2014
b'Secret'
disclosed a bug submitted by
b'denull'
b'ClientId gives away platform (iOS/Android) from which a secret was posted.'
01 Aug 2014
b'Yahoo!'
disclosed a bug submitted by
b'redshark1802'
b'Cross-origin issue on rmaiauth.ads.vip.bf1.yahoo.com'
31 Jul 2014
b'Yahoo!'
disclosed a bug submitted by
b'redshark1802'
b'Header injection on rmaitrack.ads.vip.bf1.yahoo.com'
31 Jul 2014
b'Mavenlink'
disclosed a bug submitted by
b'mikkz'
b'Login CSRF'
31 Jul 2014
b'Uzbey LLC'
disclosed a bug submitted by
b'faisalahmed'
b'All Active user sessions should be destroyed when user change his password!'
30 Jul 2014
b'DC Compendium'
disclosed a bug submitted by
b'smiegles'
b'Error page Cross-site scripting'
30 Jul 2014
b'jsDelivr'
disclosed a bug submitted by
b'shubham'
b'XSS'
29 Jul 2014
b'jsDelivr'
disclosed a bug submitted by
b'shahmeer_amir'
b'HSTS Policy not enabled on cdn.jsdelivr.net'
29 Jul 2014
wont-fix
b'4chan'
disclosed a bug submitted by
b'reactors08'
b'XSS in settings'
28 Jul 2014
b'Slack'
disclosed a bug submitted by
b'sehacure'
b'CSRF vulnerability on https://sehacure.slack.com/account/settings'
26 Jul 2014
b'Coinbase'
disclosed a bug submitted by
b'anshuman_bh'
b'CSRF on "Set as primary" option on the accounts page'
26 Jul 2014
1
...
741
742
743
744
745
...
765
BY DENIS WERNER - @NOBBD -
IMPRESSUM