REPORTS
PROGRAMS
PUBLISHERS
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Snapchat'
disclosed a bug submitted by
b'malcolmx'
b'Domain Takeover in [obviousengine.com] a snapchat acquisitions'
07 Oct 2018
b'Chaturbate'
disclosed a bug submitted by
b'avinash_'
b'CSRF on change video thumbnail at https://chaturbate.com'
07 Oct 2018
b'Badoo'
disclosed a bug submitted by
b'jarvis7'
b'Compromising the user ID'
07 Oct 2018
b'ICQ'
disclosed a bug submitted by
b'ruvlol'
b'easyXDM allows cross domain postmessaging with any origin, leaking sensitive info'
05 Oct 2018
b'Django'
disclosed a bug submitted by
b'greenwolf'
b'Email Spoofing Possible on djangoproject.com Email Domain'
05 Oct 2018
b'Zomato'
disclosed a bug submitted by
b'areizen'
b'Reflected XSS on developers.zomato.com'
05 Oct 2018
b'Shopify'
disclosed a bug submitted by
b'zhurig'
b'Race condition at create new Location'
05 Oct 2018
b'Uber'
disclosed a bug submitted by
b'0x0luke'
b'XSS on partners.uber.com due to no user input sanitisation '
04 Oct 2018
b'Chaturbate'
disclosed a bug submitted by
b'mase289'
b'Cross-origin resource sharing: arbitrary origin trusted on chatws25.stream.highwebmedia.com'
04 Oct 2018
b'Brave Software'
disclosed a bug submitted by
b'metnew'
b'`settingcontent-ms` files lacks "mark of the web" => execute code by dbl click in Downloads toolbar'
04 Oct 2018
b'Brave Software'
disclosed a bug submitted by
b'metnew'
b'Cross-origin page stays focused before/after downloading + uninformative modal window for download'
04 Oct 2018
b'Brave Software'
disclosed a bug submitted by
b'metnew'
b'`alert()` dialogs on `chrome-extension://` origin (internal pages)'
04 Oct 2018
b'Brave Software'
disclosed a bug submitted by
b'metnew'
b'URL spoofing using protocol handlers'
04 Oct 2018
b'Brave Software'
disclosed a bug submitted by
b'metnew'
b'URL spoofing in Brave for macOS'
04 Oct 2018
b'Mail.Ru'
disclosed a bug submitted by
b'pisarenko'
b'?????????? ????? ??? ? ????????? ???????????? !'
03 Oct 2018
b'Mail.Ru'
disclosed a bug submitted by
b'saiyajin'
b'XSS in touch.mail.ru '
02 Oct 2018
b'PHP (IBB)'
disclosed a bug submitted by
b'cymtrick'
b'Improper handling of Chunked data request in sapi_apache2.c leads to Reflected XSS'
02 Oct 2018
b'Apache httpd (IBB)'
disclosed a bug submitted by
b'bobrov'
b'mod_userdir CRLF injection (CVE-2016-4975)'
02 Oct 2018
b'Chaturbate'
disclosed a bug submitted by
b'ninjan'
b'Internal loop going to infinite for cb.setTimeout(func, msecs) for broadcast app.'
01 Oct 2018
b'Chaturbate'
disclosed a bug submitted by
b'toth'
b'A 10GB file is reachable'
01 Oct 2018
1
...
462
463
464
465
466
...
766
BY DENIS WERNER - @NOBBD -
IMPRESSUM