REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
58
b'ooooooo_q'
52
b'haxta4ok00'
49
b'jon_bottarini'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Grabtaxi Holdings Pte Ltd'
disclosed a bug submitted by
b'bagipro'
b'[Grab Android/iOS] Insecure deeplink leads to sensitive information disclosure'
15 Mar 2019
b'GitLab'
disclosed a bug submitted by
b'jobert'
b'Unauthenticated blind SSRF in OAuth Jira authorization controller'
14 Mar 2019
b'Keybase'
disclosed a bug submitted by
b'jordanmilne'
b'Persistent XSS on keybase.io via "payload" field in `/user/sigchain_signature.toffee` template'
14 Mar 2019
b'Shopify'
disclosed a bug submitted by
b'ruvlol'
b'POST-based XSS on apps.shopify.com'
14 Mar 2019
b'Shopify'
disclosed a bug submitted by
b'ruvlol'
b'Reverse Proxy misroute leading to steal X-Shopify-Access-Token header'
14 Mar 2019
b'Unikrn'
disclosed a bug submitted by
b'v4lid0l'
b'????????? on CRM server without authorization'
14 Mar 2019
b'Ruby on Rails'
disclosed a bug submitted by
b'ooooooo_q'
b'RCE which may occur due to `ActiveSupport::MessageVerifier` or `ActiveSupport::MessageEncryptor` (especially Active storage)'
13 Mar 2019
b'Vanilla'
disclosed a bug submitted by
b'mr_me'
b'Vanilla Forums AddonManager getSingleIndex Directory Traversal File Inclusion Remote Code Execution Vulnerability'
13 Mar 2019
b'PortSwigger Web Security'
disclosed a bug submitted by
b'0x09al'
b'Privilege Escalation by abusing non-existent path. (Windows)'
13 Mar 2019
b'Shopify'
disclosed a bug submitted by
b'ishahriyar'
b'Reflected XSS in *.myshopify.com/account/register'
12 Mar 2019
b'Redtube'
disclosed a bug submitted by
b'jtjisgod'
b'Reflect XSS on Mobile Search page '
11 Mar 2019
b'Mail.ru'
disclosed a bug submitted by
b'eremeev'
b'[api.pandao.ru] IDOR ????????? ???????? ????? ?????? ????????????'
11 Mar 2019
b'Mail.ru'
disclosed a bug submitted by
b'xalerafera'
b'CSRF ?? ???? ? ?????? (Pandao)'
11 Mar 2019
b'Mail.ru'
disclosed a bug submitted by
b'xalerafera'
b'CSRF ??? ????? ????????? ?? Pandao'
11 Mar 2019
b'Mail.ru'
disclosed a bug submitted by
b'xalerafera'
b'CSRF ?? ???????? ?????? ?? ???????'
11 Mar 2019
b'Mail.ru'
disclosed a bug submitted by
b'iframe'
b'CSRF ?????????? ????????? ????? ????????????? ?????? ???????????? cfire.mail.ru'
11 Mar 2019
b'Mail.ru'
disclosed a bug submitted by
b'petser'
b'Cross application scripting via account.mail.ru'
11 Mar 2019
b'WordPress'
disclosed a bug submitted by
b'klmunday'
b'Stored XSS in Private Message component (BuddyPress)'
08 Mar 2019
b'WordPress'
disclosed a bug submitted by
b'klmunday'
b'Mssing Authorization on Private Message replies (BuddyPress)'
08 Mar 2019
b'Shopify'
disclosed a bug submitted by
b'commandersnuggle'
b'Access to Employee calendar disclosing internal presentation and meetings'
08 Mar 2019
1
...
401
402
403
404
405
...
729
BY DENIS WERNER - @NOBBD -
IMPRESSUM