REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
83
b'linkks'
75
b'jobert'
70
b'nyymi'
62
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Nextcloud'
disclosed a bug submitted by
b'nihad4u'
b'DoS attack against the client when entering a long password'
14 Feb 2021
b'Nextcloud'
disclosed a bug submitted by
b'stefanniedermann'
b'New users can read all Nextcloud Deck data from previous user with same username'
14 Feb 2021
b'Nextcloud'
disclosed a bug submitted by
b'jackzhou'
b'xss on setup config page '
14 Feb 2021
b'Nextcloud'
disclosed a bug submitted by
b'mik317'
b'Content spoofing on https://surveyserver.nextcloud.com'
14 Feb 2021
b'WHO COVID-19 Mobile App'
disclosed a bug submitted by
b'y1ngxi0ng'
b'ArcGIS Rest Service linked to unsecured survey data'
13 Feb 2021
b'WHO COVID-19 Mobile App'
disclosed a bug submitted by
b'jaimaakali'
b'Error Page Text Injection (no compromise)'
13 Feb 2021
b'Mail.ru'
disclosed a bug submitted by
b'kaimi'
b'[files.ucs.ru] ProFTPd mod_copy Arbitrary Read/Write'
13 Feb 2021
b'Palo Alto Software'
disclosed a bug submitted by
b'silentkiller_'
b'[Bypass #870709] Unauthorised access to pagespeed global admin at https://webtools.paloalto.com/'
13 Feb 2021
b'Mail.ru'
disclosed a bug submitted by
b'jayesh25'
b'Improper Restriction of Excessive Authentication Attempts via https://certification.mail.ru/auth-form/?form=auth_certy (Rate limit Bypass)'
12 Feb 2021
b'Ubiquiti Inc.'
disclosed a bug submitted by
b'rchase'
b'Camera adoption DoS - UniFi Protect'
12 Feb 2021
b'Glassdoor'
disclosed a bug submitted by
b'prateek_0490'
b"Access to Glassdoor's Infra (AWS) and BitBucket account through leaked repo"
12 Feb 2021
b'8x8'
disclosed a bug submitted by
b'melbadry9'
b'DNS Miconfiguration (Subdomain Takeover) .8x8.com'
12 Feb 2021
b'Maker Ecosystem Growth Holdings, Inc'
disclosed a bug submitted by
b'harsithsivanandham'
b'xmlrpc.php FILE IS enabled it will used for Bruteforce attack and Denial of Service(DoS)'
12 Feb 2021
b'Informatica'
disclosed a bug submitted by
b'lu3ky-13'
b'Html injection on .informatica.com via search.html?q=1'
12 Feb 2021
b'Shopify'
disclosed a bug submitted by
b'corraldev'
b'Screenshot Service leaks X-ABS-App-Token'
12 Feb 2021
b'Mail.ru'
disclosed a bug submitted by
b'bobrov'
b'[supportlocal.delivery-club.ru] Subdomain Takeover'
12 Feb 2021
b'Mail.ru'
disclosed a bug submitted by
b'jayesh25'
b'Clickjacking Vulnerability via https://www.donationalerts.com/help/support leads to bypass for widget.support.my.games X-Frame Options'
12 Feb 2021
b'Twitter'
disclosed a bug submitted by
b'a13h1'
b'Bypass Password Authentication to Update the Password'
12 Feb 2021
b'Khan Academy'
disclosed a bug submitted by
b'sh3rl0ck_'
b'Password authentication when changing information bypass. Bypass of report #721341'
11 Feb 2021
b'TikTok'
disclosed a bug submitted by
b'iambouali'
b'Lack of rate limitation on careers site allows the attacker to brute force the verification code'
11 Feb 2021
1
...
222
223
224
225
226
...
738
BY DENIS WERNER - @NOBBD -
IMPRESSUM