REPORTS
PROGRAMS
PUBLISHERS
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Mail.ru'
disclosed a bug submitted by
b'weev3kyaw'
b'Account takeover in cups.mail.ru using punycode characters'
23 Dec 2020
b'Mail.ru'
disclosed a bug submitted by
b'chaosbolt'
b'SDC bypass on calendar.mail.ru'
23 Dec 2020
b'Mail.ru'
disclosed a bug submitted by
b'act1on3'
b'[api-site.city-mobil.ru] Improper access control leads to information disclosure'
23 Dec 2020
b'Mail.ru'
disclosed a bug submitted by
b'kwel'
b' , domain_id [biz.mail.ru]'
23 Dec 2020
b'Mail.ru'
disclosed a bug submitted by
b'el_mehdi_abdi'
b'CSRF Delete chat invitation link.'
23 Dec 2020
b'Mail.ru'
disclosed a bug submitted by
b'act1on3'
b'[delivery.city-mobil.ru] Stored XSS into support request comment'
23 Dec 2020
b'Mail.ru'
disclosed a bug submitted by
b'gevakun'
b'This Github Repository Seems Leaking Samokat Django Project'
23 Dec 2020
b'NordVPN'
disclosed a bug submitted by
b'devashishsoni'
b'Reflected XSS via IE'
23 Dec 2020
b'Liberapay'
disclosed a bug submitted by
b'viber'
b'Reauthentication for changing password bypass'
23 Dec 2020
b'TikTok'
disclosed a bug submitted by
b'luizviana'
b'Bypass SMS verification to delete TikTok account'
23 Dec 2020
b'Ruby on Rails'
disclosed a bug submitted by
b'ooooooo_q'
b'Open Redirect (6.0.0 < rails < 6.0.3.2)'
22 Dec 2020
b'WHO COVID-19 Mobile App'
disclosed a bug submitted by
b'hackbhavin'
b'DMARC and SPF records'
22 Dec 2020
b'WHO COVID-19 Mobile App'
disclosed a bug submitted by
b'spaceraccoon'
b"Improper Input Validation on User's Location on PUT /WhoService/putLocation Could Affect Availability/Falsify Users"
22 Dec 2020
b'pixiv'
disclosed a bug submitted by
b'zimmer75'
b'Open Redirect at https://oauth.secure.pixiv.net'
22 Dec 2020
b'Mail.ru'
disclosed a bug submitted by
b'daniyal_nasir'
b'Data URI Stored XSS on Donations Page'
22 Dec 2020
b'TikTok'
disclosed a bug submitted by
b'luizviana'
b'Multiple Cross-Site Scripting vulnerability via the language parameter'
21 Dec 2020
b'WHO COVID-19 Mobile App'
disclosed a bug submitted by
b'd0nut'
b'Probably unexploitable XSS via Header Injection'
21 Dec 2020
b'Stripo Inc'
disclosed a bug submitted by
b'exploit_db'
b'Permanent DOS for new users!'
21 Dec 2020
b'phpBB'
disclosed a bug submitted by
b'they'
b"Server Side Request Forgery in 'Jabber settings' in Admin Control Panel"
20 Dec 2020
b'CS Money'
disclosed a bug submitted by
b'libneko'
b' / , steamid'
20 Dec 2020
1
...
271
272
273
274
275
...
771
BY DENIS WERNER - @NOBBD -
IMPRESSUM