Skip to content

Latest commit

 

History

History
36 lines (36 loc) · 3.6 KB

File metadata and controls

36 lines (36 loc) · 3.6 KB

Reports in ian dunn program:

S.No Title Bounty
1 Bypass fix in https://hackerone.com/reports/151516 report. $100.0
2 unchecked unserialize usages in audit-trail-extension/audit-trail-extension.php $50.0
3 Formula injection via CSV exports in WordCamp Talks plugin $50.0
4 XSSI: Quick Navigation Interface - leak of private page/post titles $50.0
5 unchecked unserialize usage in WordPress-Functionality-Plugin-Skeleton/functionality-plugin-skeleton.php $25.0
6 constant cache_page_secret in regolith $25.0
7 Timing Attack in Google Authenticator - Per User Prompt $25.0
8 Brute force on wp-login $0.0
9 SSL certificate public key less than 2048 bit $0.0
10 Path Disclosure Vulnerability $0.0
11 XSS in Tagregator plugin $0.0
12 CSV Injection at Camptix Event Ticketing $0.0
13 Multiple XSS in Camptix Event Ticketing Plugin $0.0
14 [Not just a server configuration issue] Full Path Disclosure $0.0
15 Send emails to all users using Camptix $0.0
16 bypass to csv injection $0.0
17 Potentially vulnerable version of Apache software in and default files on https://iandunn.name/ $0.0
18 stored SELF xss on Basic Google Maps Placemarks Settings plugin $0.0
19 All Plugins - Direct file access to plugin files Vulnerability $0.0
20 Google Authenticator0.6 - PHP Version Dosclosure $0.0
21 Google Authenticator - Cross Site Scripting $0.0
22 CSV Injection in Camptix $0.0
23 Bypassing CSV injection using new line charcter $0.0
24 No CAPTCHA ia exist in pages $0.0
25 HTML injection-WordCamp Talks plugin $0.0
26 Security issue: Github repo's wiki publicly editable $0.0
27 xmlrpc.php FILE IS enable on Main website $0.0
28 Potential Open-Redirection $0.0
29 xmlrpc.php FILE IS enable it can be used for conducting a Bruteforce attack and Denial of Service(DoS) $0.0
30 Dos https://iandunn.name/ via CVE-2018-6389 exploitation $0.0
31 SSRF Possible through /wordpress/xmlrpc.php $0.0
32 Multiple server ssh usernames leaked in your github repository $0.0
33 Double evaluation in .bash_prompt of dotfiles allows a malicious repository to execute arbitrary commands $0.0