Skip to content

Latest commit

 

History

History
165 lines (121 loc) · 2.22 KB

File metadata and controls

165 lines (121 loc) · 2.22 KB

Title

Bypass front server restrictions and access to forbidden files and directories through X-Rewrite-Url/X-original-url header on account.mackeeper.com

URL

https://hackerone.com/reports/737323

Severity score

6.1

Reporter

rumiljonov

Bounty paid

$300


Title

Django DEBUG mode enabled and leaked system information.

URL

https://hackerone.com/reports/963542

Severity score

null

Reporter

aungkyawphyo

Bounty paid

null


Title

Mirror of https://city-mobil.ru admin interface

URL

https://hackerone.com/reports/749677

Severity score

null

Reporter

merron

Bounty paid

$150


Title

misconfigured CORS let to HPP and SOP bypass

URL

https://hackerone.com/reports/867436

Severity score

null

Reporter

dagamosst90

Bounty paid

null


Title

Helpdesk takeover (subdomain takeover) in razerzone.com domain via unclaimed Zendesk instance

URL

https://hackerone.com/reports/810807

Severity score

null

Reporter

mshassy

Bounty paid

$250


Title

Spring Actuator endpoints publicly available, leading to account takeover

URL

https://hackerone.com/reports/862589

Severity score

null

Reporter

kazan71p

Bounty paid

$5,000


Title

mailgun subdomain takeover on "email.mail.geekbrains.ru"

URL

https://hackerone.com/reports/819309

Severity score

3.8

Reporter

risinghunter

Bounty paid

null


Title

Spring Actuator endpoints publicly available and broken authentication

URL

https://hackerone.com/reports/838635

Severity score

null

Reporter

kazan71p

Bounty paid

$12,500


Title

Cross-origin resource sharing misconfig | steal user information

URL

https://hackerone.com/reports/235200

Severity score

5.7

Reporter

bughunterboy

Bounty paid

$1,000


Title

[staging.tarantool.org] Github Pages Subdomain-take-over

URL

https://hackerone.com/reports/813377

Severity score

3.1

Reporter

iframe

Bounty paid

null


Title

vk.com profile page takeover on https://cabinet.am.ru/

URL

https://hackerone.com/reports/799593

Severity score

null

Reporter

naategh

Bounty paid

null