REPORTS
PROGRAMS
PUBLISHERS
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Lob'
disclosed a bug submitted by
b'common'
b'No Access Control'
12 Aug 2019
b'Brave Software'
disclosed a bug submitted by
b'padpao'
b'Link obfuscation bug'
12 Aug 2019
b'Nextcloud'
disclosed a bug submitted by
b'leonklingele'
b'Group admins can remove arbitrary data from "data" directory (including admin data)'
12 Aug 2019
b'Tron Foundation'
disclosed a bug submitted by
b'hayageek'
b'Private Key exposed in Travis Log can Compromise all the test servers.'
11 Aug 2019
b'Twitter'
disclosed a bug submitted by
b'orange'
b'Potential pre-auth RCE on Twitter VPN'
10 Aug 2019
b'TomTom'
disclosed a bug submitted by
b'zer0ttl'
b'Listing of Amazon S3 Bucket accessible to any amazon authenticated user (vector-maps-e457472599)'
09 Aug 2019
b'Maximum'
disclosed a bug submitted by
b'dawidczagan'
b'XSS risk reduction with X-XSS-Protection: 1; mode=block header'
09 Aug 2019
b'Dropbox'
disclosed a bug submitted by
b'davidrenardy'
b'Algorithmic complexity vulnerability in ZXCVBN leads to remote denial of service attack'
08 Aug 2019
b'Mail.ru'
disclosed a bug submitted by
b'mygf'
b'CSRF Vulnerability at https://aw.my.com/'
08 Aug 2019
b'HackerOne'
disclosed a bug submitted by
b'the_arch_angel'
b'Program Email Nofication settings ignored when being added as an external contributor'
07 Aug 2019
b'PayPal'
disclosed a bug submitted by
b'albinowax'
b'Bypass for #488147 enables stored XSS on https://paypal.com/signin again'
07 Aug 2019
b'PayPal'
disclosed a bug submitted by
b'albinowax'
b'Stored XSS on https://paypal.com/signin via cache poisoning'
07 Aug 2019
b'TTS Bug Bounty'
disclosed a bug submitted by
b'rioncool22'
b'Blind Stored XSS In "Report a Problem" on www.data.gov/issue/'
07 Aug 2019
b'Maximum'
disclosed a bug submitted by
b'protector47'
b'Version Disclosure (NginX)'
07 Aug 2019
b'Mail.ru'
disclosed a bug submitted by
b'elmahdi'
b'Unrestricted File Upload To Xss Stored [ https://ideas.browser.mail.ru/ ]'
07 Aug 2019
b'Mail.ru'
disclosed a bug submitted by
b'elmahdi'
b'SSRF On [ allods.mail.ru ]'
07 Aug 2019
b'Upserve '
disclosed a bug submitted by
b'stealthy'
b'Reflected XSS on https://inventory.upserve.com/ (affects IE users only)'
06 Aug 2019
b'TTS Bug Bounty'
disclosed a bug submitted by
b'ninja_cyber007'
b'Information disclosure (system username, server info) in the x-amz-meta-s3cmd-attrs response header on data.gov'
06 Aug 2019
b'Informatica'
disclosed a bug submitted by
b'vinothkumar'
b'Public Github Repo Leaking Internal Credentials Leading To DiscoveryIQ Docker Access'
06 Aug 2019
b'Starbucks'
disclosed a bug submitted by
b'spaceraccoon'
b'SQL Injection Extracts Starbucks Enterprise Accounting, Financial, Payroll Database'
06 Aug 2019
1
...
413
414
415
416
417
...
769
BY DENIS WERNER - @NOBBD -
IMPRESSUM