REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
58
b'ooooooo_q'
52
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Zomato'
disclosed a bug submitted by
b'bigbug'
b'Possible to enumerate Addresses of users using AddressId and guessing the delivery_subzone'
15 Jul 2020
b'Shopify'
disclosed a bug submitted by
b'francisbeaudoin'
b"Ability to link a Google account to another staff account/store owner that isn't linked yet"
14 Jul 2020
b'Shopify'
disclosed a bug submitted by
b'imranhudaa'
b"user with no draft order permission can still perform action on draft order's in stocky app (idor)"
14 Jul 2020
b'Shopify'
disclosed a bug submitted by
b'priyanshuxo'
b'Subdomain Takeover of multiple *.ttcdn.co domains'
14 Jul 2020
b'Razer'
disclosed a bug submitted by
b'pandaonair'
b'Race Condition in Oauth 2.0 flow can lead to malicious applications create multiple valid sessions'
14 Jul 2020
b'Razer'
disclosed a bug submitted by
b's3cr3tsdn'
b'[api.easy2pay.co] SQL Injection in cashcard via card_no parameter ??Bypassing IP whitelist??'
14 Jul 2020
b'Shopify'
disclosed a bug submitted by
b'sreeju_kc'
b'IDOR on stocky application-Low Stock-Varient-Settings-Columns'
14 Jul 2020
b'Shopify'
disclosed a bug submitted by
b'zonduu'
b'Open Redirect - www.shopify.com'
14 Jul 2020
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'natanalves01001'
b'(CORS) Cross-origin resource sharing misconfiguration'
14 Jul 2020
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'balisong'
b' SharePoint Web Services Exposed to Anonymous Access Users'
14 Jul 2020
b'Mail.ru'
disclosed a bug submitted by
b'woj_ciech'
b'Sensitive information exposure via git commit'
13 Jul 2020
b'Mail.ru'
disclosed a bug submitted by
b'hunter_py'
b'Reflected XSS on http://info.ucs.ru/settings/check/'
13 Jul 2020
b'Mail.ru'
disclosed a bug submitted by
b'weev3kyaw'
b'Stored XSS that allow an attacker to read victim mailboxes contacts in mail.ru and my.com application'
13 Jul 2020
b'Mail.ru'
disclosed a bug submitted by
b'm7mdharoun'
b'Subdomain Takeover at blog.instamart.ru'
13 Jul 2020
b'Mail.ru'
disclosed a bug submitted by
b'r0hack'
b'Cross-organization data access in city-mobil.ru'
13 Jul 2020
b'Mail.ru'
disclosed a bug submitted by
b'justchillin'
b'Reflected XSS in city-mobil.ru/'
13 Jul 2020
b'Mail.ru'
disclosed a bug submitted by
b'dedsec69'
b'Improper access control leading to deletion of Greeting videos on {https://smtp.8mar.mail.ru/}'
13 Jul 2020
b'Mail.ru'
disclosed a bug submitted by
b'ch0c0'
b'[icq.com/people/*uin*/edit] ??????????? ?????? ? ???????? ?? ????? ? ???? "???????"'
13 Jul 2020
b'Stripo Inc'
disclosed a bug submitted by
b'whitehatmat'
b'Integer Overflow (CVE_2017_7529)'
13 Jul 2020
b'Stripo Inc'
disclosed a bug submitted by
b'dotsecurity'
b'SSRF via Export Service in ActiveCampaign'
13 Jul 2020
1
...
277
278
279
280
281
...
730
BY DENIS WERNER - @NOBBD -
IMPRESSUM