REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
58
b'ooooooo_q'
52
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Razer'
disclosed a bug submitted by
b'zelzal'
b'Misconfigured Bucket [razer-assets2] https://assets2.razerzone.com/'
18 Mar 2020
b'Razer'
disclosed a bug submitted by
b'nnez'
b'Reflected XSS on https://www.easytopup.in.th/store/product/return on parameter mref_id'
18 Mar 2020
b'Razer'
disclosed a bug submitted by
b'marzuki1337'
b'AWS subdomain Takeover at estore.razersynapse.com'
18 Mar 2020
b'Starbucks'
disclosed a bug submitted by
b'bytebunny'
b'Singapore - IDOR in campaign.starbucks.com.sg'
17 Mar 2020
b'Starbucks'
disclosed a bug submitted by
b'k3mlol'
b'China - president-starbucks.com.cn DNS configuration reported as takeover'
17 Mar 2020
b'Starbucks'
disclosed a bug submitted by
b'e4366eolywrgpidfbio'
b'Minimal information disclosure of internal asset names and links which were not publicly accessible.'
17 Mar 2020
b'Starbucks'
disclosed a bug submitted by
b'jackb898'
b'athome.starbucks.com - URL parameter tampering of review forms permitted possible content injection'
17 Mar 2020
b'Starbucks'
disclosed a bug submitted by
b'gamer7112'
b'DOM XSS on app.starbucks.com via ReturnUrl'
17 Mar 2020
b'Mail.ru'
disclosed a bug submitted by
b'circuit'
b'[https://seosan.io] Account owner disclosure'
16 Mar 2020
b'Shopify'
disclosed a bug submitted by
b'mosuan'
b'Timeline Editor Self-XSS (Previous Fix #738072 Incomplete)'
16 Mar 2020
b'Node.js third-party modules'
disclosed a bug submitted by
b'visat'
b'[htmr] DOM-based XSS'
15 Mar 2020
b'Nextcloud'
disclosed a bug submitted by
b'foobar7'
b'SSRF protection bypass'
14 Mar 2020
b'Nextcloud'
disclosed a bug submitted by
b'teaport'
b'Only the file extensions are checked, not the MIME types as configured'
14 Mar 2020
b'Nextcloud'
disclosed a bug submitted by
b'beched'
b'Docker image with FPM is vulnerable to CVE-2019-11043'
14 Mar 2020
b'Khan Academy'
disclosed a bug submitted by
b'jamesconnor'
b'Information can be changed without a password'
14 Mar 2020
b'Twitter'
disclosed a bug submitted by
b'safehacker_27'
b'Accepting error message on twitter sends you to attacker site'
13 Mar 2020
b'Mail.ru'
disclosed a bug submitted by
b'hackervision'
b'Brute-force any email account through allods.mail.ru '
13 Mar 2020
b'Ping Identity'
disclosed a bug submitted by
b'jackb898'
b'Internal Hostname disclosure from multiple Apache servers via blank host header method'
12 Mar 2020
b'Twitter'
disclosed a bug submitted by
b'meepmerp'
b'lack of input validation that can lead Denial of Service (DOS)'
12 Mar 2020
b'TTS Bug Bounty'
disclosed a bug submitted by
b'nathand'
b'Cache poisoning DoS to various TTS assets'
12 Mar 2020
1
...
312
313
314
315
316
...
730
BY DENIS WERNER - @NOBBD -
IMPRESSUM