REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
84
b'linkks'
75
b'jobert'
70
b'nyymi'
64
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Topcoder'
disclosed a bug submitted by
b'powerpuff'
b'CSRF on https://apps.topcoder.com/wiki/pages/doattachfile.action'
14 Dec 2020
b'Glassdoor'
disclosed a bug submitted by
b'l0cpd'
b"Reflected XSS at https://www.glassdoor.com/ via the 'numSuggestions' parameter"
14 Dec 2020
b'WordPress'
disclosed a bug submitted by
b'erwan_lr'
b"Arbitrary change of blog's background image via CSRF"
14 Dec 2020
b'Imgur'
disclosed a bug submitted by
b'1a2er3d'
b'Bypass subscription'
13 Dec 2020
b'Stripo Inc'
disclosed a bug submitted by
b'abhishek101'
b'No rate limiting for confirmation email lead to huge Mass mailings'
11 Dec 2020
b'Stripo Inc'
disclosed a bug submitted by
b'falcon_319'
b'SSRF external interaction'
11 Dec 2020
b'Yoti'
disclosed a bug submitted by
b'duckoverflow'
b'Multiple Vulnerabilities in (*www.yoti.com) - Leads to Leakage user admin Sensitive Exposure'
11 Dec 2020
b'Semrush'
disclosed a bug submitted by
b'a_d_a_m'
b'Broken validation of user Id for JWT Token'
11 Dec 2020
b'OPPO'
disclosed a bug submitted by
b'darkwatcher'
b'Information Disclosure at https://portal.finzfin.com/1.txt'
11 Dec 2020
b'Node.js third-party modules'
disclosed a bug submitted by
b'trygve_lie'
b'Default behavior of Fastifys versioned routes can be used for cache poisoning when Fastify is used in combination with a http cache / CDN'
10 Dec 2020
b'Glassdoor'
disclosed a bug submitted by
b'ta8ahi'
b'Site wide CSRF affecting both job seeker and Employer account on glassdoor.com'
10 Dec 2020
b'OPPO'
disclosed a bug submitted by
b'hetroublemakr'
b'No rate limit on Reporting a Threat on [https://community.coloros.com] lead to Increase in the User Group/Points'
10 Dec 2020
b'Starbucks'
disclosed a bug submitted by
b'ko2sec'
b'Unrestricted File Upload Leads to RCE on mobile.starbucks.com.sg'
09 Dec 2020
b'VK.com'
disclosed a bug submitted by
b'onlymalelove'
b'Reflected XSS /video'
09 Dec 2020
b'VK.com'
disclosed a bug submitted by
b'persewerance'
b'XSS in vk.link'
09 Dec 2020
b'VK.com'
disclosed a bug submitted by
b'darkprism'
b' auth.restore'
09 Dec 2020
b'Blueboard'
disclosed a bug submitted by
b'milap18'
b'path traversal vulnerability adding /success-form after www.blueboard.com and skip request-a-demo page.'
09 Dec 2020
b'curl'
disclosed a bug submitted by
b'ospoco'
b'CVE-2020-8286: Inferior OCSP verification'
09 Dec 2020
b'Mail.ru'
disclosed a bug submitted by
b'moonwalker'
b' '
09 Dec 2020
b'Slack'
disclosed a bug submitted by
b'demonia'
b'Slack-Corp Heroku application disclosing limited info about company members'
09 Dec 2020
1
...
244
245
246
247
248
...
741
BY DENIS WERNER - @NOBBD -
IMPRESSUM