REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
58
b'ooooooo_q'
52
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'BTFS'
disclosed a bug submitted by
b'aslanemre'
b'XSS on remote.bittorrent.com'
11 May 2020
b'concrete5'
disclosed a bug submitted by
b'gamliel'
b'Administrators can add other administrators'
11 May 2020
b'HackerOne'
disclosed a bug submitted by
b'jobert'
b'GraphQL node interface for ActiveResource models lacks encoding for resource identifier, enabling parameter injection in Payments backend'
11 May 2020
b'Automattic'
disclosed a bug submitted by
b'keer0k'
b'Stored XSS in assets.txmblr.com'
11 May 2020
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'l00ph0le'
b'Remote Code Execution - Unauthenticated Remote Command Injection (via Microsoft SharePoint CVE-2019-0604)'
11 May 2020
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'cablej_dds'
b'???? - Complete account takeover'
11 May 2020
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'cablej_dds'
b'????????? - Insecure download cookie generation allows bypass of CAC authentication, access to deleted and locked files'
11 May 2020
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'cablej_dds'
b'????? - Pre-generation of VIEWSTATE allows CAC bypass'
11 May 2020
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'cablej_dds'
b'???? ????? exposes highly sensitive information to public'
11 May 2020
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'javilarx8'
b'Unrestricted File Upload'
11 May 2020
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'rootuser'
b'Sensitive Information Leaking Through DoD Owned Website. [??????????]'
11 May 2020
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b's3cr3tsdn'
b'Remote Code Execution in ??????'
11 May 2020
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'un4gi'
b'PII Leak via https://????????'
11 May 2020
b'Visma Public'
disclosed a bug submitted by
b'semsem123'
b'Unrestricted file upload leads to Stored XSS'
11 May 2020
b'MTN Group'
disclosed a bug submitted by
b'tp9222'
b'Week Passwords generated by password reset function'
09 May 2020
b'Node.js third-party modules'
disclosed a bug submitted by
b'mik317'
b'[logkitty] RCE via insecure command formatting'
09 May 2020
b'Vercel'
disclosed a bug submitted by
b'elmahdi'
b'through %09 Character the attacker is able to steal Github Token [ Account Takeover ]'
08 May 2020
b'Badoo'
disclosed a bug submitted by
b'0x3c3e'
b'Leak of authorization urls leads to account takeover'
08 May 2020
b'Visma Public'
disclosed a bug submitted by
b'hungry_boy'
b'Ability to delete projects from Archived companies (Read only version)'
08 May 2020
b'Mail.ru'
disclosed a bug submitted by
b'adiosmf'
b'XSS at go.mail.ru'
08 May 2020
1
...
299
300
301
302
303
...
730
BY DENIS WERNER - @NOBBD -
IMPRESSUM