REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
58
b'ooooooo_q'
52
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'ZEIT'
disclosed a bug submitted by
b'luied1920'
b'Open Redirect on Gitllab Oauth leading to Acount Takeover'
22 Dec 2019
b'Badoo'
disclosed a bug submitted by
b'matthijsmelissen'
b'SSO through odnoklassniki uses http rather than https'
21 Dec 2019
b'HackerOne'
disclosed a bug submitted by
b'the_arch_angel'
b'How the Bug stole hacking'
20 Dec 2019
b'GitLab'
disclosed a bug submitted by
b'ryhmnlfj'
b'Uncontrolled Resource Consumption in any Markdown field using Mermaid'
20 Dec 2019
b'YouPorn'
disclosed a bug submitted by
b'n00bsec'
b'XSS reflected on [https://www.youporn.com]'
19 Dec 2019
b'Automattic'
disclosed a bug submitted by
b'simonscannell'
b'Authenticated Code Execution through Phar deserialization in CSV Importer as Shop manager in WooCommerce'
19 Dec 2019
b'Automattic'
disclosed a bug submitted by
b'simonscannell'
b"WooCommerce Blacklist in 'map_meta_cap' leads to Privilege Escalation of Shopmanagers"
19 Dec 2019
b'Automattic'
disclosed a bug submitted by
b'simonscannell'
b"Stored XSS in Jetpack's Simple Payment Module by Contributors / Authors"
19 Dec 2019
b'Automattic'
disclosed a bug submitted by
b'simonscannell'
b'Arbitrary File Download as Shopmanager'
19 Dec 2019
b'Stripo Inc'
disclosed a bug submitted by
b'aishkendle'
b'Password token leak via Host header'
19 Dec 2019
b'Stripo Inc'
disclosed a bug submitted by
b'aishkendle'
b'OLD SESSION DOES NOT EXPIRE AFTER PASSWORD CHANGE'
19 Dec 2019
b'Stripo Inc'
disclosed a bug submitted by
b'aishkendle'
b'Bypass email verification and create email template with the editor'
19 Dec 2019
b'GitLab'
disclosed a bug submitted by
b'vakzz'
b'Git flag injection - local file overwrite to remote code execution'
19 Dec 2019
b'GitLab'
disclosed a bug submitted by
b'vakzz'
b'Git flag injection leading to file overwrite and potential remote code execution'
19 Dec 2019
b'Mail.ru'
disclosed a bug submitted by
b'krupnikas'
b'Public available Sensitive Information about drivers'
18 Dec 2019
b'Polymail, Inc.'
disclosed a bug submitted by
b'renekroka'
b'Reflected XSS by changing url parameters on the user invite onboarding links.'
18 Dec 2019
b'QIWI'
disclosed a bug submitted by
b'circuit'
b'hard-use account takeover qiwi.com'
18 Dec 2019
b'Stripo Inc'
disclosed a bug submitted by
b'pirate_'
b'Redirection through referer tag'
18 Dec 2019
b'Stripo Inc'
disclosed a bug submitted by
b'rutik346'
b'Able to change password by entering wrong old password'
18 Dec 2019
b'Stripo Inc'
disclosed a bug submitted by
b'eliel'
b'SSRF in /cabinet/stripeapi/v1/siteInfoLookup?url=XXX'
18 Dec 2019
1
...
333
334
335
336
337
...
730
BY DENIS WERNER - @NOBBD -
IMPRESSUM