REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
83
b'linkks'
75
b'jobert'
70
b'nyymi'
62
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Nextcloud'
disclosed a bug submitted by
b'inhibitor181'
b'RTLO character allowed in shared files'
17 Aug 2020
b'Omise'
disclosed a bug submitted by
b'justlife_4x4'
b'Authenticity token doesnt expire after single use leading to CSRF'
17 Aug 2020
b'Nextcloud'
disclosed a bug submitted by
b'jplopezy'
b'XSS in desktop client via invalid server address on login form'
17 Aug 2020
b'OWOX, Inc.'
disclosed a bug submitted by
b'ant_pyne'
b'Unrestricted File Upload in Chat Window'
16 Aug 2020
b'BugPoC'
disclosed a bug submitted by
b'd1r3wolf'
b'Solution for XSS challenge calc.buggywebsite.com'
15 Aug 2020
b'Topcoder'
disclosed a bug submitted by
b'tushr'
b'SVG file upload leads to XML injection'
14 Aug 2020
b'Bitwala'
disclosed a bug submitted by
b'lamscun'
b'HTML injection in email content'
14 Aug 2020
b'Yoti'
disclosed a bug submitted by
b'lamscun'
b'[www.yoti.com] Wordpress user admin information discloure'
14 Aug 2020
b'Automattic'
disclosed a bug submitted by
b'hannanhaseeb'
b'Denial-of- service By Cache Poisoning The Cross-Origin Resource Sharing Misconfiguration Allow Origin Header'
14 Aug 2020
b'Node.js third-party modules'
disclosed a bug submitted by
b'chalker'
b'Arbitrary code execution via untrusted schemas in ajv'
14 Aug 2020
b'8x8'
disclosed a bug submitted by
b'testingforbugs'
b'Default Creds Spring Boot Admin'
14 Aug 2020
b'Nextcloud'
disclosed a bug submitted by
b'secconsult'
b'Missing memory corruption protection on Windows release built'
14 Aug 2020
b'New Relic'
disclosed a bug submitted by
b'jon_bottarini'
b'Stored XSS Via NRQL chartbuilder JSON view '
13 Aug 2020
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'un4gi'
b'Remote Code Execution via CVE-2019-18935'
13 Aug 2020
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'un4gi'
b'Path traversal on https://??? allows arbitrary file read (CVE-2020-3452)'
13 Aug 2020
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'they'
b'https://????? is vulnerable to CVE-2020-3452 Read-Only Path Traversal Vulnerability'
13 Aug 2020
b'New Relic'
disclosed a bug submitted by
b'jon_bottarini'
b'Bypass of #447975 - view mobile application token though "Application Information" sidebar on Installation page '
13 Aug 2020
b'New Relic'
disclosed a bug submitted by
b'jon_bottarini'
b'IDOR allows accounts to view full name of other accounts based on email through share notes feature'
13 Aug 2020
b'New Relic'
disclosed a bug submitted by
b'jon_bottarini'
b'Restricted user can add and delete tags of APM key transactions '
13 Aug 2020
b'New Relic'
disclosed a bug submitted by
b'skavans'
b'Restricted user can remove NerdStorage documents/collections scoped to ACCOUNT or ENTITY'
13 Aug 2020
1
...
274
275
276
277
278
...
738
BY DENIS WERNER - @NOBBD -
IMPRESSUM