bug bounty

HackerOne Bug Bounty Disclosure: multiple-permission-model-bypasses-due-to-improper-path-traversal-sequence-sanitization-xion

Company Name: Node.js Company HackerOne URL: https://hackerone.com/nodejs Submitted By:xionLink to Submitters Profile:https://hackerone.com/xion Report Title:Multiple permission model bypasses due to improper...

HackerOne Bug Bounty Disclosure: non-revoked-api-key-disclosure-in-a-disclosed-api-key-disclosure-report-on-stripo-sankalpa

Company Name: Stripo Inc Company HackerOne URL: https://hackerone.com/stripo Submitted By:sankalpa_1337Link to Submitters Profile:https://hackerone.com/sankalpa_1337 Report Title:Non-revoked API Key Disclosure in a...

HackerOne Bug Bounty Disclosure: hxxp-reading-unprocessed-http-request-with-unbounded-chunk-extension-allows-dos-attacks-bart

Company Name: Node.js Company HackerOne URL: https://hackerone.com/nodejs Submitted By:bartLink to Submitters Profile:https://hackerone.com/bart Report Title:hXXp: Reading unprocessed HTTP request with unbounded...

HackerOne Bug Bounty Disclosure: node-js-is-vulnerable-to-the-marvin-attack-timing-variant-of-the-bleichenbacher-attack-against-pkcs-v-padding-hkario

Company Name: Node.js Company HackerOne URL: https://hackerone.com/nodejs Submitted By:hkarioLink to Submitters Profile:https://hackerone.com/hkario Report Title:Nodejs is vulnerable to the Marvin Attack...

HackerOne Bug Bounty Disclosure: path-traversal-by-monkey-patching-buffer-internals-tniessen

Company Name: Node.js Company HackerOne URL: https://hackerone.com/nodejs Submitted By:tniessenLink to Submitters Profile:https://hackerone.com/tniessen Report Title:Path traversal by monkey-patching Buffer internalsReport Link:https://hackerone.com/reports/2218653Date...

HackerOne Bug Bounty Disclosure: host-header-injection-internal-qa-delivery-indrive-com-mega

Company Name: inDrive Company HackerOne URL: https://hackerone.com/indrive Submitted By:mega9Link to Submitters Profile:https://hackerone.com/mega9 Report Title:Host Header Injection - internalqadeliveryindrivecomReport Link:https://hackerone.com/reports/2076786Date Submitted:12...

HackerOne Bug Bounty Disclosure: xmlrpc-php-wp-cron-php-files-are-enabled-and-will-used-for-ddos-dos-and-broutforce-users-attack-cyber-tech

Company Name: Nextcloud Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:cyber-techLink to Submitters Profile:https://hackerone.com/cyber-tech Report Title:xmlrpcphp &wp-cronphp files are enabled, and will...

HackerOne Bug Bounty Disclosure: idor-on-graphql-queries-billingdocumentdownload-and-billdetails-blaklis

Company Name: Shopify Company HackerOne URL: https://hackerone.com/shopify Submitted By:blaklisLink to Submitters Profile:https://hackerone.com/blaklis Report Title:IDOR on GraphQL queries BillingDocumentDownload and BillDetailsReport...