REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
84
b'linkks'
75
b'jobert'
70
b'nyymi'
64
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Reverb.com'
disclosed a bug submitted by
b'bigshaq'
b'Persistent XSS in https://sandbox.reverb.com/item/'
06 May 2018
b'Node.js'
disclosed a bug submitted by
b'dade'
b'registry.nodejs.org Subdomain Takeover'
04 May 2018
b'HackerOne'
disclosed a bug submitted by
b'haxta4ok00'
b'Team object in GraphQL discloses team group names and permissions'
04 May 2018
b'Mavenlink'
disclosed a bug submitted by
b'tolo7010'
b'Account members can re-add themselve after has been deleted by administrator'
03 May 2018
b'Apache httpd (IBB)'
disclosed a bug submitted by
b'hanno'
b'Optionsbleed / CVE-2017-9798'
03 May 2018
b'Ed'
disclosed a bug submitted by
b'tangent90ninety'
b'Session cookie missing SecureFlag on git.edoverflow.com.'
03 May 2018
b'vulners.com'
disclosed a bug submitted by
b'bobrov'
b'[vulners.com] nginx alias_traversal'
03 May 2018
b'Coalition, Inc.'
disclosed a bug submitted by
b'startedfromthebottom'
b'No authentication on email address for password reset functionality/ https://platform.thecoalition.com/forgot-password'
03 May 2018
b'Unikrn'
disclosed a bug submitted by
b'tolo7010'
b'Rate-limit protection get executed in the last stage of the registration process, allowing enumeration of existing account.'
03 May 2018
b'New Relic'
disclosed a bug submitted by
b'jon_bottarini'
b'[NR Infrastructure] Bypass of #200576 through GraphQL query abuse - allows restricted user access to root account license key'
02 May 2018
b'New Relic'
disclosed a bug submitted by
b'jon_bottarini'
b'Manipulation of submit payment request allows me to obtain Infrastructure Pro/Other Services for free or at greatly reduced price'
02 May 2018
b'New Relic'
disclosed a bug submitted by
b'kunal_bahl'
b'Newrelic s3 bucket is writeable and deleteable by authorized AWS users'
02 May 2018
b'New Relic'
disclosed a bug submitted by
b'ho_nc'
b'Broken Authentication and session management OWASP A2'
02 May 2018
b'New Relic'
disclosed a bug submitted by
b'japz'
b'Hyperlink Injection on adding active users'
02 May 2018
b'New Relic'
disclosed a bug submitted by
b'mr_sharma_'
b'XSS (Reflected)'
02 May 2018
b'New Relic'
disclosed a bug submitted by
b'jon_bottarini'
b'NR Internal_API call allows me to read the events/violations/policies/messages of ANY New Relic account (AND pull data from infrastructure)'
02 May 2018
b'Greenhouse.io'
disclosed a bug submitted by
b'irvinlim'
b'DoS through cache poisoning using invalid HTTP parameters'
02 May 2018
b'Shopify'
disclosed a bug submitted by
b'richardf'
b'Potential to abuse pricing errors in saved carts'
02 May 2018
b'Vend'
disclosed a bug submitted by
b'al88nsk'
b'Improper access control on adding a Register to an Outlet'
02 May 2018
b'Shopify'
disclosed a bug submitted by
b'rijalrojan'
b'Replace other user files in Inbox messages '
01 May 2018
1
...
466
467
468
469
470
...
742
BY DENIS WERNER - @NOBBD -
IMPRESSUM