REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
58
b'ooooooo_q'
52
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'PHP (IBB)'
disclosed a bug submitted by
b'vah13'
b'potential remote code execution with phar archive '
13 Oct 2019
b'PHP (IBB)'
disclosed a bug submitted by
b'aerodudrizzt'
b'Memory corruption when parsing a hostile PHAR archive'
13 Oct 2019
b'PHP (IBB)'
disclosed a bug submitted by
b'aerodudrizzt'
b'Crash (DoS) when parsing a hostile TIFF'
13 Oct 2019
b'Python (IBB)'
disclosed a bug submitted by
b'aerodudrizzt'
b'Information disclosure in mmap module - python 2.7.12'
13 Oct 2019
b'WordPress'
disclosed a bug submitted by
b'yzy9951'
b'[FG-VD-18-165] Wordpress Cross-Site Scripting Vulnerability Notification II'
11 Oct 2019
b'HackerOne'
disclosed a bug submitted by
b'kunal94'
b'Disclosure of Email title report in quick award paypout email (no content mode)'
11 Oct 2019
b'Shopify'
disclosed a bug submitted by
b'dostoevskylabs'
b'Reflective Cross-site Scripting via Newsletter Form'
11 Oct 2019
b'SEMrush'
disclosed a bug submitted by
b'r0hack'
b'Manipulation of exam results at Semrush.Academy'
11 Oct 2019
b'Mail.ru'
disclosed a bug submitted by
b'johndoe1492'
b'OOB XXE '
11 Oct 2019
b'Mail.ru'
disclosed a bug submitted by
b'johndoe1492'
b'OOB XXE '
11 Oct 2019
b'Mail.ru'
disclosed a bug submitted by
b'mase289'
b'XSS via Cookie in Mail.ru'
11 Oct 2019
b'Mail.ru'
disclosed a bug submitted by
b'kiriknik'
b'Blind SSRF on sentry.dev-my.com due to Sentry misconfiguration'
11 Oct 2019
b'Mail.ru'
disclosed a bug submitted by
b'iframe'
b'[agent.33slona.ru] Recovery code bruteforce'
11 Oct 2019
b'Mail.ru'
disclosed a bug submitted by
b'iframe'
b'[sso.33slona.ru] Application Messages Error stacktrace PHP.'
11 Oct 2019
b'QIWI'
disclosed a bug submitted by
b'circuit'
b'account takeover https://qiwi.me '
11 Oct 2019
b'Shopify'
disclosed a bug submitted by
b'mariogh'
b'Bypass report #416983 - Removed Staff members who had "Apps" permission can still modify flow app connections'
10 Oct 2019
b'Shopify'
disclosed a bug submitted by
b'mariogh'
b'Unauthenticated read and write access to ALL endpoints of a store is possible for removed staff members who had "Apps" permission'
10 Oct 2019
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'alyssa_herrera'
b'PII leakage-Full SSN on ???'
10 Oct 2019
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'alyssa_herrera'
b'Partial SSN exposed through Presentation slides on ??????????'
10 Oct 2019
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'ragnar'
b'MSSQL injection via param Customwho in https://?????/News/Transcripts/Search/Sort/ and WAF bypass'
10 Oct 2019
1
...
359
360
361
362
363
...
730
BY DENIS WERNER - @NOBBD -
IMPRESSUM