REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
83
b'linkks'
75
b'jobert'
70
b'nyymi'
62
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Slack'
disclosed a bug submitted by
b'albatraoz'
b'Internal SSRF bypass using slash commands at api.slack.com'
12 Jul 2018
b'Passit'
disclosed a bug submitted by
b'retcyb'
b'Old sessions does not expire On changing password via https://app.passit.io/account/change-password '
12 Jul 2018
b'Nextcloud'
disclosed a bug submitted by
b'samix'
b'Accessing to download.nextcloud.com from original ip adreess | insecure Download'
12 Jul 2018
b'Node.js third-party modules'
disclosed a bug submitted by
b'bl4de'
b'[m-server] HTML Injection in filenames displayed as directory listing in the browser allows to embed iframe with malicious JavaScript code'
12 Jul 2018
b'Node.js third-party modules'
disclosed a bug submitted by
b'bl4de'
b'[m-server] Path Traversal allows to display content of arbitrary file(s) from the server'
12 Jul 2018
b'Node.js third-party modules'
disclosed a bug submitted by
b'patrickrbc'
b'Privilege escalation allows any user to add an administrator'
12 Jul 2018
b'Shopify'
disclosed a bug submitted by
b'bored-engineer'
b'[out-of-scope] toxiproxy: Lack of CSRF protection allows an attacker to gain access to internal Shopify network'
11 Jul 2018
b'OLX'
disclosed a bug submitted by
b'konduru-jashwanth'
b'Cross Site Scripting -> Reflected XSS'
11 Jul 2018
b'Brave Software'
disclosed a bug submitted by
b'skanthak'
b'Arbitrary local code execution via DLL hijacking from executable installer'
09 Jul 2018
b'Brave Software'
disclosed a bug submitted by
b'skanthak'
b'Download of (later executed) .NET installer over insecure channel'
09 Jul 2018
b'Brave Software'
disclosed a bug submitted by
b'testingforbugs'
b'Directory Listing on https://promo-services-staging.brave.com'
09 Jul 2018
b'Discourse'
disclosed a bug submitted by
b'luigigubello'
b'Stored XSS in "post last edited" option'
09 Jul 2018
b'Y Combinator'
disclosed a bug submitted by
b'nthack'
b'Stored Cross Site Scripting'
09 Jul 2018
b'Razer US'
disclosed a bug submitted by
b'alifathi'
b'Heart-bleed Vulnerability that leads to disclose sensitive information from the memory'
09 Jul 2018
b'AlienVault '
disclosed a bug submitted by
b'pabster'
b'DOM-Based XSS in www.alienvault.com'
07 Jul 2018
b'Node.js third-party modules'
disclosed a bug submitted by
b'ibrahimd'
b'XSS in express-useragent through HTTP User-Agent'
06 Jul 2018
b'ICQ'
disclosed a bug submitted by
b'iframe'
b'???????? ??? ?????? ? ????????? icq ? ??????? amazonaws.com [config,txt]'
06 Jul 2018
b'VK.com'
disclosed a bug submitted by
b'povargek'
b'????? CSRF ????? ??? ????????? ?????????, ??? ??? ?????????? ??????-?????????'
06 Jul 2018
b'VK.com'
disclosed a bug submitted by
b'pisarenko'
b'???????? ????????? ????? ??????? ? ?????????????'
06 Jul 2018
b'Augur'
disclosed a bug submitted by
b'edmundedgar'
b'A miner can manipulate the gas reporting bond'
05 Jul 2018
1
...
450
451
452
453
454
...
738
BY DENIS WERNER - @NOBBD -
IMPRESSUM