REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
57
b'ooooooo_q'
50
b'haxta4ok00'
49
b'jon_bottarini'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Nextcloud'
disclosed a bug submitted by
b'ja3far'
b'Denial of Service when entring an Array in email at seetings'
19 Aug 2020
b'Valve'
disclosed a bug submitted by
b'gamer7112'
b"[GoldSrc] RCE via 'spk' Console Command"
19 Aug 2020
b'Valve'
disclosed a bug submitted by
b'gamer7112'
b'[GoldSrc] RCE via malformed BSP file'
19 Aug 2020
b'Valve'
disclosed a bug submitted by
b'irukandjisecresearch'
b"Buffer overflow In hl.exe's launch -game argument allows an attacker to execute arbitrary code locally or from browser"
19 Aug 2020
b'Yelp'
disclosed a bug submitted by
b'hk755a'
b"CRITICAL Insecure Direct Object Reference (I.D.O.R) - Link Other User's Credit Card "
19 Aug 2020
b'Yelp'
disclosed a bug submitted by
b'hk755a'
b"I.D.O.R To Order,Book,Buy,reserve On YELP FOR FREE (UNAUTHORIZED USE OF OTHER USER'S CREDIT CARD)"
19 Aug 2020
b'Yelp'
disclosed a bug submitted by
b'hk755a'
b"I.D.O.R TO EDIT ALL USER'S CREDIT CARD INFORMATION+(Partial credit card info disclosure)"
19 Aug 2020
b'Shopify'
disclosed a bug submitted by
b'ayyoub'
b'Password reset link not expired at Stocky App'
18 Aug 2020
b'Starbucks'
disclosed a bug submitted by
b'rexvuz'
b'Korea - Reflected XSS on https://www.istarbucks.co.kr/app/getGiftStock.do via "skuNo" and "skuImgUrl" parameters'
18 Aug 2020
b'Shopify'
disclosed a bug submitted by
b'tolo7010'
b'Some store settings/data are accessible to "No Access" permission users on GraphQL LiveView operation'
18 Aug 2020
b'Shopify'
disclosed a bug submitted by
b'jmp_35p'
b'Get analytics token using only apps permission'
18 Aug 2020
b'Shopify'
disclosed a bug submitted by
b'sreeju_kc'
b'OrderListInitial leaks order details'
18 Aug 2020
b'Shopify'
disclosed a bug submitted by
b'jaka_tingkir'
b'access permission is not revoked even if the email has been deleted or changed on the partner account -partners.shopify-'
18 Aug 2020
b'Shopify'
disclosed a bug submitted by
b'rioncool22'
b'Blind Stored XSS Via Staff Name'
18 Aug 2020
b'WordPress'
disclosed a bug submitted by
b'simonscannell'
b'Stored XSS in Post Preview as Contributor'
18 Aug 2020
b'WordPress'
disclosed a bug submitted by
b'simonscannell'
b'pre-auth Stored XSS in comments via javascript: url when administrator edits user supplied comment'
18 Aug 2020
b'Mendix'
disclosed a bug submitted by
b'enixium'
b'Reflected XSS in "*.mendix.com/openid/*"'
18 Aug 2020
b'Dropcontact'
disclosed a bug submitted by
b'try___for_impossible'
b'IDOR at [https://dropcontact.firstpromote] which allows an UNAUTHORIZED user to ACCESS and EDIT Paypal GMAIL by Changing the ID.'
18 Aug 2020
b'Gener8'
disclosed a bug submitted by
b'5hu8h4m_n4g4'
b'Session not invalidated after password reset'
18 Aug 2020
b'Solana BBP'
disclosed a bug submitted by
b'anjpan'
b'Sensitive data leaks [username, password, keys]'
18 Aug 2020
1
...
254
255
256
257
258
...
719
BY DENIS WERNER - @NOBBD -
IMPRESSUM