REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
58
b'ooooooo_q'
52
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'HackerOne'
disclosed a bug submitted by
b'todayisnew'
b'Reflected XSS on www.hackerone.com and resources.hackerone.com'
05 May 2020
b'Clario'
disclosed a bug submitted by
b'rumiljonov'
b'Account verification bypass on translate.kromtech.com'
05 May 2020
b'HackerOne'
disclosed a bug submitted by
b'jobert'
b'Potential stored Cross-Site Scripting vulnerability in Support Backend'
04 May 2020
b'Vanilla'
disclosed a bug submitted by
b'haxta4ok00'
b'disclosure of email by sending a message.'
04 May 2020
b'MTN Group'
disclosed a bug submitted by
b'w31rd0'
b' SQL Injection on cookie parameter'
03 May 2020
b'Greenhouse.io'
disclosed a bug submitted by
b'kartarkat'
b'Open S3 Bucket Accessible by any Aws User'
01 May 2020
b'MTN Group'
disclosed a bug submitted by
b'newbipath12'
b'Unsafe cors sharing of admin users '
30 Apr 2020
b'Uber'
disclosed a bug submitted by
b'redshark1802'
b'duplicate hsts headers lead to firefox ignoring hsts on business.uber.com'
30 Apr 2020
b'Uber'
disclosed a bug submitted by
b'healdb'
b'Reflected XSS and sensitive data exposure, including payment details, on lioncityrentals.com.sg'
30 Apr 2020
b'SEMrush'
disclosed a bug submitted by
b'albatraoz'
b'IDOR in the https://market.semrush.com/'
30 Apr 2020
b'SEMrush'
disclosed a bug submitted by
b'a_d_a_m'
b'SSRF and LFI in site-audit tool'
30 Apr 2020
b'Mail.ru'
disclosed a bug submitted by
b'organdonor'
b'Ability to find out the name of the database table and its columns'
30 Apr 2020
b'Mail.ru'
disclosed a bug submitted by
b'root0x0'
b'Http Response Splitting on thumb.cloud.mail.ru'
30 Apr 2020
b'Mail.ru'
disclosed a bug submitted by
b'wize'
b'CRLF Injection in 301 Redirect allow to Set-Cookies for mail.ru '
30 Apr 2020
b'Mail.ru'
disclosed a bug submitted by
b'dedsec69'
b'Information Disclosure on {http://pro.tracker.my.com}'
30 Apr 2020
b'Razer'
disclosed a bug submitted by
b'zathu'
b'Insecure HostnameVerifier within WebView of Razer Pay Android (TLS Vulnerability)'
30 Apr 2020
b'Razer'
disclosed a bug submitted by
b'reemer'
b'SQL Injection in https://api-my.pay.razer.com/inviteFriend/getInviteHistoryLog'
30 Apr 2020
b'Razer'
disclosed a bug submitted by
b'sambal0x'
b'[Razer Pay Mobile App] IDOR within /v1_IM/friends/queryDrawRedLog allowed unauthorised access to read logs'
30 Apr 2020
b'Starbucks'
disclosed a bug submitted by
b'b4bilal'
b'Korea - LFI Server directory traversal at starbucks.co.kr'
30 Apr 2020
b'Razer'
disclosed a bug submitted by
b'sambal0x'
b"Improper Authorization at https://api-my.pay.razer.com/v1/trxDetail?trxId=[Id] allowing unauthorised access to other user's transaction details"
30 Apr 2020
1
...
301
302
303
304
305
...
730
BY DENIS WERNER - @NOBBD -
IMPRESSUM