REPORTS
PROGRAMS
PUBLISHERS
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Razer'
disclosed a bug submitted by
b's3cr3tsdn'
b'Insecure Processing of XML leads to Denial of Service through Billion Laughs Attack'
11 Mar 2020
b'Razer'
disclosed a bug submitted by
b'l00ph0le'
b'Store Cross-Site Scripting - www.razer.ru'
11 Mar 2020
b'Razer'
disclosed a bug submitted by
b't3ngu'
b' Information disclosure at http://sea-s2s.molthailand.com/status.php'
11 Mar 2020
b'Razer'
disclosed a bug submitted by
b'nnez'
b'Leftover back-end system on www.zest.co.th allows an unauthorized attacker to generate Razer Gold Pin for free'
11 Mar 2020
b'Starbucks'
disclosed a bug submitted by
b'iampuky'
b'Korea - LFI via path traversal at https://msr.istarbucks.co.kr:6443/appif/'
10 Mar 2020
b'Shopify'
disclosed a bug submitted by
b'fisher'
b'H1514 Deanonymizing Exchange Marketplace private listings '
10 Mar 2020
b'Starbucks'
disclosed a bug submitted by
b'l00ph0le'
b'Hong Kong - Open Redirect on card.starbucks.com.hk'
10 Mar 2020
b'Mail.ru'
disclosed a bug submitted by
b'asdqwedev'
b'Blind SQL Injection on news.mail.ru'
10 Mar 2020
b'Mail.ru'
disclosed a bug submitted by
b'godofdarkness_msf'
b'Account takeover at geekbrains.ru'
10 Mar 2020
b'Mail.ru'
disclosed a bug submitted by
b'khalidhissen'
b'ssl cookkie without secure flag set'
10 Mar 2020
b'Mail.ru'
disclosed a bug submitted by
b'api_0'
b'[windows10.hi-tech.mail.ru] Blind SQL Injection '
10 Mar 2020
b'Mail.ru'
disclosed a bug submitted by
b'alexeysergeevich'
b'turboslim.lady.mail.ru - Blind sql-injection.'
10 Mar 2020
b'Mail.ru'
disclosed a bug submitted by
b'naategh'
b'vk.com profile page takeover on https://cabinet.am.ru/'
10 Mar 2020
b'Mail.ru'
disclosed a bug submitted by
b'linkks'
b' allods.mail.ru sql injection'
10 Mar 2020
b'Mail.ru'
disclosed a bug submitted by
b'asdqwedev'
b'Stored XSS at branded site in .mail.ru domain'
10 Mar 2020
b'Mail.ru'
disclosed a bug submitted by
b'r0hack'
b'Account TakeOver through password recovery at am.ru'
10 Mar 2020
b'Node.js third-party modules'
disclosed a bug submitted by
b'mik317'
b'[blamer] RCE via insecure command formatting'
10 Mar 2020
b'HackerOne H1P BBP1'
disclosed a bug submitted by
b'bencode'
b'Testing'
10 Mar 2020
b'Node.js third-party modules'
disclosed a bug submitted by
b'whoareme'
b'Server-Side Request Forgery (SSRF) in Ghost CMS '
09 Mar 2020
b'JamieWeb'
disclosed a bug submitted by
b'mahendra00'
b'HTTP Request Smuggling'
09 Mar 2020
1
...
352
353
354
355
356
...
768
BY DENIS WERNER - @NOBBD -
IMPRESSUM