Access to information about any video and its owner via GraphQL endpoint [dictor.mail.ru]
๐ https://hackerone.com/reports/924914
๐น Severity: Medium | ๐ฐ 2,500 USD
๐น Reported To: Mail.ru
๐น Reported By: #organdonor
๐น State: ๐ข Resolved
๐น Disclosed: September 1, 2020, 9:14am (UTC)
๐ https://hackerone.com/reports/924914
๐น Severity: Medium | ๐ฐ 2,500 USD
๐น Reported To: Mail.ru
๐น Reported By: #organdonor
๐น State: ๐ข Resolved
๐น Disclosed: September 1, 2020, 9:14am (UTC)
IDOR ะฟะพะทะฒะพะปัะตั ะธะทะผะตะฝะธัั ะธะฝัะพัะผะฐัะธั ะพ ะฟะพะปัะทะพะฒะฐัะตะปะต.
๐ https://hackerone.com/reports/708182
๐น Severity: Medium
๐น Reported To: Mail.ru
๐น Reported By: #iframe
๐น State: ๐ข Resolved
๐น Disclosed: September 1, 2020, 9:21am (UTC)
๐ https://hackerone.com/reports/708182
๐น Severity: Medium
๐น Reported To: Mail.ru
๐น Reported By: #iframe
๐น State: ๐ข Resolved
๐น Disclosed: September 1, 2020, 9:21am (UTC)
warofdragons.my.games: configuration files with database account are accessible
๐ https://hackerone.com/reports/786609
๐น Severity: Medium | ๐ฐ 150 USD
๐น Reported To: Mail.ru
๐น Reported By: #iframe
๐น State: ๐ข Resolved
๐น Disclosed: September 1, 2020, 9:24am (UTC)
๐ https://hackerone.com/reports/786609
๐น Severity: Medium | ๐ฐ 150 USD
๐น Reported To: Mail.ru
๐น Reported By: #iframe
๐น State: ๐ข Resolved
๐น Disclosed: September 1, 2020, 9:24am (UTC)
[garnier-olia.lady.mail.ru] Reflected XSS /exp/ bypass "/"
๐ https://hackerone.com/reports/787815
๐น Severity: Low
๐น Reported To: Mail.ru
๐น Reported By: #iframe
๐น State: ๐ข Resolved
๐น Disclosed: September 1, 2020, 9:26am (UTC)
๐ https://hackerone.com/reports/787815
๐น Severity: Low
๐น Reported To: Mail.ru
๐น Reported By: #iframe
๐น State: ๐ข Resolved
๐น Disclosed: September 1, 2020, 9:26am (UTC)
Clickjacking lead to remove review
๐ https://hackerone.com/reports/965141
๐น Severity: Medium
๐น Reported To: Yelp
๐น Reported By: #alaayousef
๐น State: ๐ข Resolved
๐น Disclosed: September 1, 2020, 6:07pm (UTC)
๐ https://hackerone.com/reports/965141
๐น Severity: Medium
๐น Reported To: Yelp
๐น Reported By: #alaayousef
๐น State: ๐ข Resolved
๐น Disclosed: September 1, 2020, 6:07pm (UTC)
CRLF injection on www.starbucks.com
๐ https://hackerone.com/reports/858650
๐น Severity: Medium | ๐ฐ 250 USD
๐น Reported To: Starbucks
๐น Reported By: #x3n0nn3p
๐น State: ๐ข Resolved
๐น Disclosed: September 1, 2020, 9:59pm (UTC)
๐ https://hackerone.com/reports/858650
๐น Severity: Medium | ๐ฐ 250 USD
๐น Reported To: Starbucks
๐น Reported By: #x3n0nn3p
๐น State: ๐ข Resolved
๐น Disclosed: September 1, 2020, 9:59pm (UTC)
XSS by file (Active Storage `Proxying`)
๐ https://hackerone.com/reports/949513
๐น Severity: Medium | ๐ฐ 500 USD
๐น Reported To: Ruby on Rails
๐น Reported By: #ooooooo_q
๐น State: ๐ข Resolved
๐น Disclosed: September 1, 2020, 10:51pm (UTC)
๐ https://hackerone.com/reports/949513
๐น Severity: Medium | ๐ฐ 500 USD
๐น Reported To: Ruby on Rails
๐น Reported By: #ooooooo_q
๐น State: ๐ข Resolved
๐น Disclosed: September 1, 2020, 10:51pm (UTC)
Stored XSS in Post title (PoC)
๐ https://hackerone.com/reports/942859
๐น Severity: Medium | ๐ฐ 250 USD
๐น Reported To: Imgur
๐น Reported By: #zerox4
๐น State: ๐ข Resolved
๐น Disclosed: September 2, 2020, 6:06am (UTC)
๐ https://hackerone.com/reports/942859
๐น Severity: Medium | ๐ฐ 250 USD
๐น Reported To: Imgur
๐น Reported By: #zerox4
๐น State: ๐ข Resolved
๐น Disclosed: September 2, 2020, 6:06am (UTC)
Takeover an account that doesn't have a Shopify ID and more
๐ https://hackerone.com/reports/867513
๐น Severity: Critical | ๐ฐ 22,500 USD
๐น Reported To: Shopify
๐น Reported By: #francisbeaudoin
๐น State: ๐ข Resolved
๐น Disclosed: September 2, 2020, 2:47pm (UTC)
๐ https://hackerone.com/reports/867513
๐น Severity: Critical | ๐ฐ 22,500 USD
๐น Reported To: Shopify
๐น Reported By: #francisbeaudoin
๐น State: ๐ข Resolved
๐น Disclosed: September 2, 2020, 2:47pm (UTC)
Public access to Sidekiq dashboard at shopper.sbermarket.ru
๐ https://hackerone.com/reports/951190
๐น Severity: Medium | ๐ฐ 500 USD
๐น Reported To: Mail.ru
๐น Reported By: #avolume
๐น State: ๐ข Resolved
๐น Disclosed: September 2, 2020, 4:09pm (UTC)
๐ https://hackerone.com/reports/951190
๐น Severity: Medium | ๐ฐ 500 USD
๐น Reported To: Mail.ru
๐น Reported By: #avolume
๐น State: ๐ข Resolved
๐น Disclosed: September 2, 2020, 4:09pm (UTC)
looch.tv CORS crossite user information and stream_key access
๐ https://hackerone.com/reports/708886
๐น Severity: Medium
๐น Reported To: Mail.ru
๐น Reported By: #iframe
๐น State: ๐ข Resolved
๐น Disclosed: September 2, 2020, 5:43pm (UTC)
๐ https://hackerone.com/reports/708886
๐น Severity: Medium
๐น Reported To: Mail.ru
๐น Reported By: #iframe
๐น State: ๐ข Resolved
๐น Disclosed: September 2, 2020, 5:43pm (UTC)
[api.33slona.ru] ะะพัััะฟ ะบ API ะธะท ะทะฐ ะฝะตะฟัะฐะฒะธะปัะฝะพะน ะบะพะฝัะธะณััะฐัะธะธ ัะตัะฒะตัะฐ 302 ัะตะดะธัะตั.
๐ https://hackerone.com/reports/819714
๐น Severity: No Rating
๐น Reported To: Mail.ru
๐น Reported By: #iframe
๐น State: ๐ข Resolved
๐น Disclosed: September 2, 2020, 6:24pm (UTC)
๐ https://hackerone.com/reports/819714
๐น Severity: No Rating
๐น Reported To: Mail.ru
๐น Reported By: #iframe
๐น State: ๐ข Resolved
๐น Disclosed: September 2, 2020, 6:24pm (UTC)
Subdomain Takeover at analyticstest.geekbrains.ru
๐ https://hackerone.com/reports/942179
๐น Severity: Medium
๐น Reported To: Mail.ru
๐น Reported By: #steal_wart
๐น State: ๐ข Resolved
๐น Disclosed: September 2, 2020, 6:27pm (UTC)
๐ https://hackerone.com/reports/942179
๐น Severity: Medium
๐น Reported To: Mail.ru
๐น Reported By: #steal_wart
๐น State: ๐ข Resolved
๐น Disclosed: September 2, 2020, 6:27pm (UTC)
Denial of Service | twitter.com & mobile.twitter.com
๐ https://hackerone.com/reports/903740
๐น Severity: Medium | ๐ฐ 1,120 USD
๐น Reported To: Twitter
๐น Reported By: #cyanpiny
๐น State: ๐ข Resolved
๐น Disclosed: September 2, 2020, 7:18pm (UTC)
๐ https://hackerone.com/reports/903740
๐น Severity: Medium | ๐ฐ 1,120 USD
๐น Reported To: Twitter
๐น Reported By: #cyanpiny
๐น State: ๐ข Resolved
๐น Disclosed: September 2, 2020, 7:18pm (UTC)
IDOR in locid parameter allowing to view others accounts Profile Locations
๐ https://hackerone.com/reports/966949
๐น Severity: Low
๐น Reported To: Yelp
๐น Reported By: #cocoh__23
๐น State: โช๏ธ Informative
๐น Disclosed: September 2, 2020, 7:26pm (UTC)
๐ https://hackerone.com/reports/966949
๐น Severity: Low
๐น Reported To: Yelp
๐น Reported By: #cocoh__23
๐น State: โช๏ธ Informative
๐น Disclosed: September 2, 2020, 7:26pm (UTC)
[static-server-gx] Path Traversal allowing to read any files on the server
๐ https://hackerone.com/reports/581939
๐น Severity: High
๐น Reported To: Node.js third-party modules
๐น Reported By: #lightangel1412
๐น State: ๐ข Resolved
๐น Disclosed: September 3, 2020, 12:44am (UTC)
๐ https://hackerone.com/reports/581939
๐น Severity: High
๐น Reported To: Node.js third-party modules
๐น Reported By: #lightangel1412
๐น State: ๐ข Resolved
๐น Disclosed: September 3, 2020, 12:44am (UTC)
Open SonarQube instance leaking internal source code
๐ https://hackerone.com/reports/947946
๐น Severity: Critical
๐น Reported To: Equifax
๐น Reported By: #aksquare
๐น State: ๐ข Resolved
๐น Disclosed: September 3, 2020, 5:59am (UTC)
๐ https://hackerone.com/reports/947946
๐น Severity: Critical
๐น Reported To: Equifax
๐น Reported By: #aksquare
๐น State: ๐ข Resolved
๐น Disclosed: September 3, 2020, 5:59am (UTC)
SQL injection at fleet.city-mobil.ru
๐ https://hackerone.com/reports/881901
๐น Severity: High | ๐ฐ 10,000 USD
๐น Reported To: Mail.ru
๐น Reported By: #r0hack
๐น State: ๐ข Resolved
๐น Disclosed: September 3, 2020, 1:19pm (UTC)
๐ https://hackerone.com/reports/881901
๐น Severity: High | ๐ฐ 10,000 USD
๐น Reported To: Mail.ru
๐น Reported By: #r0hack
๐น State: ๐ข Resolved
๐น Disclosed: September 3, 2020, 1:19pm (UTC)
REFLECTED XSS On http://jsgames.mail.ru/bad_browser.php via back_url paramter
๐ https://hackerone.com/reports/948259
๐น Severity: Medium
๐น Reported To: Mail.ru
๐น Reported By: #yukusawa18
๐น State: ๐ข Resolved
๐น Disclosed: September 3, 2020, 1:23pm (UTC)
๐ https://hackerone.com/reports/948259
๐น Severity: Medium
๐น Reported To: Mail.ru
๐น Reported By: #yukusawa18
๐น State: ๐ข Resolved
๐น Disclosed: September 3, 2020, 1:23pm (UTC)
Reflected XSS on โโโโโโโ
๐ https://hackerone.com/reports/971360
๐น Severity: Medium
๐น Reported To: U.S. Dept Of Defense
๐น Reported By: #nagli
๐น State: ๐ข Resolved
๐น Disclosed: September 3, 2020, 5:20pm (UTC)
๐ https://hackerone.com/reports/971360
๐น Severity: Medium
๐น Reported To: U.S. Dept Of Defense
๐น Reported By: #nagli
๐น State: ๐ข Resolved
๐น Disclosed: September 3, 2020, 5:20pm (UTC)
Elmah.axd is publicly accessible and leaking Error Log for ROOT on โโโโโ_PRD_WEB1 โโโโโโโโโelmah.axd
๐ https://hackerone.com/reports/962753
๐น Severity: Medium
๐น Reported To: U.S. Dept Of Defense
๐น Reported By: #rudra_2000
๐น State: ๐ข Resolved
๐น Disclosed: September 3, 2020, 5:22pm (UTC)
๐ https://hackerone.com/reports/962753
๐น Severity: Medium
๐น Reported To: U.S. Dept Of Defense
๐น Reported By: #rudra_2000
๐น State: ๐ข Resolved
๐น Disclosed: September 3, 2020, 5:22pm (UTC)