Month: October 2024

HackerOne Bug Bounty Disclosure: lack-of-rate-limiting-in-hxxps-pki-passreset-aspx-leads-to-pii-disclosure-and-potential-account-takeover-hypervis-r

Company Name: U.S. Dept Of Defense Company HackerOne URL: https://hackerone.com/deptofdefense Submitted By:hypervis0rLink to Submitters Profile:https://hackerone.com/hypervis0r Report Title:Lack of rate limiting...

HackerOne Bug Bounty Disclosure: unauthenticated-lfi-local-file-inclusion-using-the-symbol-at-the-target-hxxps–xym

Company Name: U.S. Dept Of Defense Company HackerOne URL: https://hackerone.com/deptofdefense Submitted By:0xymLink to Submitters Profile:https://hackerone.com/0xym Report Title:Unauthenticated LFI (Local File...