REPORTS
PROGRAMS
PUBLISHERS
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'arkadiyt-projects'
disclosed a bug submitted by
b'priyankvadaliya'
b'Feature-Policy Header is Missing and Pastebin files'
05 Aug 2019
b'Kartpay'
disclosed a bug submitted by
b'eissen5c'
b'Application Design issue for Phone Number field in Registration.'
05 Aug 2019
b'Kartpay'
disclosed a bug submitted by
b'iheb_hamad1'
b'Captcha protection Bypass on Forgot password page'
05 Aug 2019
b'Automattic'
disclosed a bug submitted by
b'albinowax'
b'Disclosure of 152 cookie names via crafted input'
04 Aug 2019
b'Ubiquiti Networks'
disclosed a bug submitted by
b'grampae'
b'Resource Consumption DOS on Edgemax v1.10.6'
04 Aug 2019
b'Mail.ru'
disclosed a bug submitted by
b'humanoidphantom'
b'Make user buy items via clickjacking possibility'
04 Aug 2019
b'Pornhub'
disclosed a bug submitted by
b'justas_b'
b'Single User DOS by Poisoning Cookie via Get Parameter'
03 Aug 2019
b'HackerOne'
disclosed a bug submitted by
b'asad0x01_'
b'Total bounties paid amount is disclosed because of redesign of the Program Profiles'
02 Aug 2019
b'Khan Academy'
disclosed a bug submitted by
b'red_assassin'
b'RTL override char allowed at https://www.khanacademy.org/computer-programming/link_redirector?url=*'
02 Aug 2019
b'Mail.ru'
disclosed a bug submitted by
b'theappsec'
b'[lootdog.io] User phone number disclosure'
02 Aug 2019
b'Mail.ru'
disclosed a bug submitted by
b'godexmachine'
b'[https://pandao.ru] - PUT method available'
02 Aug 2019
b'Mail.ru'
disclosed a bug submitted by
b'secator'
b'[XSS] iframe ? payments/phones'
02 Aug 2019
b'Mail.ru'
disclosed a bug submitted by
b'secator'
b'[XSS] data-url ? ???????'
02 Aug 2019
b'Mail.ru'
disclosed a bug submitted by
b'ilyailya'
b'??? ????????? lootdog ? ??????????? ?? ?????????.'
02 Aug 2019
b'Mail.ru'
disclosed a bug submitted by
b'bobrov'
b'[o2.mail.ru] nginx alias traversal'
02 Aug 2019
b'Nextcloud'
disclosed a bug submitted by
b'j4tayu'
b'SignUp using Fake Email'
02 Aug 2019
b'Grammarly'
disclosed a bug submitted by
b'metnew'
b"Handling of `tracking` command allows making arbitrary blind requests with user's cookies from Grammarly Extension's origin"
01 Aug 2019
b'Kartpay'
disclosed a bug submitted by
b'c00lbugs'
b'Error Page Content Spoofing or Text Injection [https://vpn.kartpay.com/]'
01 Aug 2019
b'OLX'
disclosed a bug submitted by
b'codeslayer137'
b'Cross-site Scripting (XSS) - Reflected'
31 Jul 2019
b'TTS Bug Bounty'
disclosed a bug submitted by
b'tikoo_sahil'
b'Improper Session management can cause account takeover[https://micropurchase.18f.gov]'
30 Jul 2019
1
...
414
415
416
417
418
...
769
BY DENIS WERNER - @NOBBD -
IMPRESSUM