Skip to content

Latest commit

 

History

History
465 lines (341 loc) · 5.68 KB

File metadata and controls

465 lines (341 loc) · 5.68 KB

Title

CRLF Injection in 301 Redirect allow to Set-Cookies for mail.ru

URL

https://hackerone.com/reports/811366

Severity score

null

Reporter

wize

Bounty paid

null


Title

CRLF injection in info.hacker.one

URL

https://hackerone.com/reports/217058

Severity score

null

Reporter

thalaivarsubu

Bounty paid

null


Title

CRLF Injection [vpn.corp.cuvva.com]

URL

https://hackerone.com/reports/231508

Severity score

null

Reporter

cyriac

Bounty paid

null


Title

CRLF Injection - http://stage.mackeeper.com/

URL

https://hackerone.com/reports/730786

Severity score

3.5

Reporter

kphaks

Bounty paid

$50


Title

[downloads.mariadb.org] CRLF injection in case of encoded query mark

URL

https://hackerone.com/reports/490997

Severity score

null

Reporter

s_p_q_r

Bounty paid

null


Title

CRLF injection agentcrm.8x8.com

URL

https://hackerone.com/reports/413115

Severity score

null

Reporter

w2w

Bounty paid

null


Title

CRLF injection on https://buildbot.mariadb.org

URL

https://hackerone.com/reports/481512

Severity score

null

Reporter

mik317

Bounty paid

null


Title

CRLF injection on www.starbucks.com

URL

https://hackerone.com/reports/858650

Severity score

5

Reporter

x3n0nn3p

Bounty paid

$250


Title

CRLF injection at https://mariadb.org/.

URL

https://hackerone.com/reports/476257

Severity score

5.3

Reporter

sergeybelove

Bounty paid

null


Title

Creating malformed URLs via new line character in-between two URLs leads to misrepresented hyperlinks in Tweets/DMs

URL

https://hackerone.com/reports/712979

Severity score

null

Reporter

zlz

Bounty paid

$560


Title

SMTP Header Injection at http://abonement.ucs.ru

URL

https://hackerone.com/reports/901956

Severity score

null

Reporter

killinem_sec

Bounty paid

null


Title

Монипулирование на страницах пользоватлей значением "Подсказывать стикеры в полях ввода"

URL

https://hackerone.com/reports/300622

Severity score

null

Reporter

pisarenko

Bounty paid

$100


Title

Нет маркера на добавление песни в плейлист пользователя

URL

https://hackerone.com/reports/242408

Severity score

null

Reporter

pisarenko

Bounty paid

$100


Title

Non-admin users can trigger writes to memcached by entering a malicious server as a share URL

URL

https://hackerone.com/reports/592864

Severity score

4.3

Reporter

jmdx

Bounty paid

$100


Title

Add arbitrary value in reset password cookie

URL

https://hackerone.com/reports/266030

Severity score

null

Reporter

cuso4

Bounty paid

null


Title

CRLF Injection on openvpn.svc.ubnt.com

URL

https://hackerone.com/reports/232327

Severity score

null

Reporter

0x0luke

Bounty paid

null


Title

mod_userdir CRLF injection (CVE-2016-4975)

URL

https://hackerone.com/reports/409512

Severity score

null

Reporter

bobrov

Bounty paid

$500


Title

CRLF Injection - http://stage-static-cdn.mackeeper.com/

URL

https://hackerone.com/reports/730788

Severity score

null

Reporter

kphaks

Bounty paid

$50


Title

CRLF Injection

URL

https://hackerone.com/reports/13314

Severity score

null

Reporter

bigbear

Bounty paid

null


Title

CRLF Injection in legacy url API (url.parse().hostname)

URL

https://hackerone.com/reports/771596

Severity score

null

Reporter

vavkamil

Bounty paid

null


Title

[synthetics.newrelic.com] SMTP header injection leads to (mass) arbitrary email sending

URL

https://hackerone.com/reports/347439

Severity score

null

Reporter

ldionmarcil

Bounty paid

$500


Title

CRLF Injection at vpn.bitstrips.com

URL

https://hackerone.com/reports/237357

Severity score

null

Reporter

wplus

Bounty paid

$500


Title

x-request-id header reflected in server response without sanitization

URL

https://hackerone.com/reports/798686

Severity score

null

Reporter

zeop

Bounty paid

$50


Title

CRLF Injection on https://vpn.mixmax.com

URL

https://hackerone.com/reports/234758

Severity score

null

Reporter

sir_morty

Bounty paid

null


Title

Cross-site scripting (XSS) vulnerability on a DoD website

URL

https://hackerone.com/reports/225936

Severity score

null

Reporter

sp1d3rs

Bounty paid

null


Title

CRLF Injection in email address

URL

https://hackerone.com/reports/796013

Severity score

null

Reporter

ashmek

Bounty paid

null


Title

Legal Robot

URL

https://hackerone.com/reports/276427

Severity score

0

Reporter

miftahabdul2307

Bounty paid

null


Title

[screenshot.mail.ru] CRLF Injection

URL

https://hackerone.com/reports/426238

Severity score

null

Reporter

bobrov

Bounty paid

null


Title

CRLF injection mcs.mail.ru (leads to XSS)

URL

https://hackerone.com/reports/335599

Severity score

null

Reporter

w2w

Bounty paid

null


Title

CRLF Injection on ███████

URL

https://hackerone.com/reports/245485

Severity score

null

Reporter

twicedi

Bounty paid

null


Title

CRLF Injection in urllib

URL

https://hackerone.com/reports/590020

Severity score

6.1

Reporter

push0ebp

Bounty paid

$1,000