REPORTS
PROGRAMS
PUBLISHERS
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Shopify'
disclosed a bug submitted by
b'mosuan'
b'Timeline Editor Self-XSS (Previous Fix #738072 Incomplete)'
16 Mar 2020
b'Node.js third-party modules'
disclosed a bug submitted by
b'visat'
b'[htmr] DOM-based XSS'
15 Mar 2020
b'Nextcloud'
disclosed a bug submitted by
b'foobar7'
b'SSRF protection bypass'
14 Mar 2020
b'Nextcloud'
disclosed a bug submitted by
b'teaport'
b'Only the file extensions are checked, not the MIME types as configured'
14 Mar 2020
b'Nextcloud'
disclosed a bug submitted by
b'beched'
b'Docker image with FPM is vulnerable to CVE-2019-11043'
14 Mar 2020
b'Khan Academy'
disclosed a bug submitted by
b'jamesconnor'
b'Information can be changed without a password'
14 Mar 2020
b'Twitter'
disclosed a bug submitted by
b'safehacker_27'
b'Accepting error message on twitter sends you to attacker site'
13 Mar 2020
b'Mail.ru'
disclosed a bug submitted by
b'hackervision'
b'Brute-force any email account through allods.mail.ru '
13 Mar 2020
b'Ping Identity'
disclosed a bug submitted by
b'jackb898'
b'Internal Hostname disclosure from multiple Apache servers via blank host header method'
12 Mar 2020
b'Twitter'
disclosed a bug submitted by
b'meepmerp'
b'lack of input validation that can lead Denial of Service (DOS)'
12 Mar 2020
b'TTS Bug Bounty'
disclosed a bug submitted by
b'nathand'
b'Cache poisoning DoS to various TTS assets'
12 Mar 2020
b'BCM Messenger'
disclosed a bug submitted by
b'namunah'
b'Account Takeover with old password and login QR'
12 Mar 2020
b'Revive Adserver'
disclosed a bug submitted by
b'hoangn144'
b'bypass old password with array in /admin/account-user-email.php'
12 Mar 2020
b'Revive Adserver'
disclosed a bug submitted by
b'hoangn144'
b'Open redirection bypass in /www/admin/campaign-modify.php'
12 Mar 2020
b'HackerOne'
disclosed a bug submitted by
b'tolo7010'
b'Disabled account can still use GraphQL endpoint'
12 Mar 2020
b'Slack'
disclosed a bug submitted by
b'defparam'
b'Mass account takeovers using HTTP Request Smuggling on https://slackb.com/ to steal session cookies'
12 Mar 2020
b'Slack'
disclosed a bug submitted by
b'sandrogauci'
b'Slack DTLS uses a private key that is in the public domain, which may lead to SRTP stream hijack'
12 Mar 2020
b'Slack'
disclosed a bug submitted by
b'sandrogauci'
b'TURN server allows TCP and UDP proxying to internal network, localhost and meta-data services'
12 Mar 2020
b'Monero'
disclosed a bug submitted by
b'consistent-dream'
b'Monero wallet password change is confirmed when not matching'
11 Mar 2020
b'Monero'
disclosed a bug submitted by
b'ahook'
b'Potential linkage of public/private (anonymous) node addresses'
11 Mar 2020
1
...
351
352
353
354
355
...
768
BY DENIS WERNER - @NOBBD -
IMPRESSUM