REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
84
b'linkks'
75
b'jobert'
70
b'nyymi'
64
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Mavenlink'
disclosed a bug submitted by
b'aroly'
b"Information disclosure when trying to delete an expense's attachment on m.mavenlink.com "
20 Jan 2018
b'QIWI'
disclosed a bug submitted by
b'tikoo_sahil'
b'Information disclosure on https://paycard.rapida.ru'
20 Jan 2018
b'concrete5'
disclosed a bug submitted by
b'sts'
b'Reflected XSS vulnerability in Database name field on installation screen'
20 Jan 2018
b'HackerOne'
disclosed a bug submitted by
b'666reda'
b'Submitted reports state logs leakage'
19 Jan 2018
b'Inflection'
disclosed a bug submitted by
b'hackedbrain'
b'Information Disclosure and Privilege Escalation in app.goodhire.com/member/developers/api-settings'
18 Jan 2018
b'SEMrush'
disclosed a bug submitted by
b'inferno-'
b'Reflected XSS using Header Injection'
18 Jan 2018
b'Blockstack'
disclosed a bug submitted by
b'firestone'
b'Weak crossdomain.xml'
18 Jan 2018
b'Pushwoosh'
disclosed a bug submitted by
b'protector47'
b'Development configuration file'
18 Jan 2018
b'shopify-scripts'
disclosed a bug submitted by
b'ahihi'
b'SEGV on ary_concat'
17 Jan 2018
b'shopify-scripts'
disclosed a bug submitted by
b'ahihi'
b'heap-buffer-overflow in OP_R_BREAK'
17 Jan 2018
b'shopify-scripts'
disclosed a bug submitted by
b'ahihi'
b'heap-use-after-free in OP_RESCUE'
17 Jan 2018
b'Showmax'
disclosed a bug submitted by
b'ven0ms'
b'Query string parameter modifications returned in page'
16 Jan 2018
b'AlienVault '
disclosed a bug submitted by
b'cujanovic'
b'DNS pinning SSRF'
16 Jan 2018
b'LocalTapiola'
disclosed a bug submitted by
b'muon4'
b'Cleartext protocol after bank authentication (yrityspalvelu.tapiola.fi)'
14 Jan 2018
b'ok.ru'
disclosed a bug submitted by
b'lincoln9932'
b'XSS ? ?????? ??????????'
13 Jan 2018
b'Cloudflare'
disclosed a bug submitted by
b'webster'
b'Cloudflare does not sufficiently truncate credit card numbers in invoices'
12 Jan 2018
b'Coursera'
disclosed a bug submitted by
b'ahsankhan'
b'XSS Stored'
12 Jan 2018
b'Rockstar Games'
disclosed a bug submitted by
b'alexbirsan'
b'SMB SSRF in emblem editor exposes taketwo domain credentials, may lead to RCE'
12 Jan 2018
b'concrete5'
disclosed a bug submitted by
b'gamliel'
b'Host Header Injection allow HiJack Password Reset Link'
12 Jan 2018
b'concrete5'
disclosed a bug submitted by
b'egix'
b'Unsafe usage of Host HTTP header in Concrete5 version 5.7.3.1'
11 Jan 2018
1
...
485
486
487
488
489
...
741
BY DENIS WERNER - @NOBBD -
IMPRESSUM