REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
58
b'ooooooo_q'
52
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Ubiquiti Inc.'
disclosed a bug submitted by
b'ajxchapman'
b'UniFi Video web interface Configuration Restore user privilege escalation'
01 Apr 2020
b'Ubiquiti Inc.'
disclosed a bug submitted by
b'ajxchapman'
b'UniFi Video Server web interface admin user Firmware Update path traversal leading to local system compromise'
01 Apr 2020
b'Starbucks'
disclosed a bug submitted by
b'neweq'
b'China - Leaked credentials permitted a limited ability to create Starbucks coupons and cards'
01 Apr 2020
b'Ubiquiti Inc.'
disclosed a bug submitted by
b'b0yd'
b'UniFi Video v3.10.1 (Windows) Local Privileges Escalation to SYSTEM from arbitrary filedelete and DLL hijack vulnerabilities.'
01 Apr 2020
b'Starbucks'
disclosed a bug submitted by
b'0xpatrik'
b'China \xe2\x80\x93 Limited Partner PII Regarding Work Scheduling via Unauthenticated API Endpoint'
01 Apr 2020
b'Rocket.Chat'
disclosed a bug submitted by
b'codermak'
b'API Keys Hardcoded in Github repository'
01 Apr 2020
b'Open-Xchange'
disclosed a bug submitted by
b'catenacyber'
b'Buffer over-reads in i_stream_zlib_read'
01 Apr 2020
b'Open-Xchange'
disclosed a bug submitted by
b'catenacyber'
b' Null pointer dereference in SMTP server function smtp_command_parse_data_with_size'
01 Apr 2020
b'Endless Hosting'
disclosed a bug submitted by
b'pr3r00t'
b'Lets Encrypt Certificates affected by CAA Rechecking Incident'
01 Apr 2020
b'lemlist'
disclosed a bug submitted by
b'ctulhu'
b'Unrestricted File Upload on https://app.lemlist.com'
01 Apr 2020
b'Visma Bug Bounty Program'
disclosed a bug submitted by
b'hamzaavvvan'
b'Open Redirection In connect.identity.stagaws.visma.com'
01 Apr 2020
b'Nextcloud'
disclosed a bug submitted by
b'rcejules'
b'potential RCE and XSS via file upload requiring user account and default settings'
01 Apr 2020
b'Mail.ru'
disclosed a bug submitted by
b'chiraggupta8769-'
b'Self XSS via help.mail.ru interface'
01 Apr 2020
b'Mail.ru'
disclosed a bug submitted by
b'haxta4ok00'
b'[cfire.mail.ru] Time Based SQL Injection 2'
01 Apr 2020
b'Mail.ru'
disclosed a bug submitted by
b'haxta4ok00'
b'[parapa.mail.ru] SQL Injection reapet'
01 Apr 2020
b'Mail.ru'
disclosed a bug submitted by
b'haxta4ok00'
b'SSRF/XSPA [parapa.mail.ru]'
01 Apr 2020
b'Mail.ru'
disclosed a bug submitted by
b'haxta4ok00'
b'ssrf xspa [https://prt.mail.ru/]'
01 Apr 2020
b'Twitter'
disclosed a bug submitted by
b'mgf15'
b'Periscope iOS app CSRF in follow action due to deeplink'
31 Mar 2020
b'CS Money'
disclosed a bug submitted by
b'putsi'
b'SSRF via 3d.cs.money/pasteLinkToImage'
31 Mar 2020
b'DRIVE.NET, Inc.'
disclosed a bug submitted by
b'what_web'
b'[www.drive2.ru] CSRF through FCTX token bypass'
31 Mar 2020
1
...
308
309
310
311
312
...
730
BY DENIS WERNER - @NOBBD -
IMPRESSUM