Bug Bounty Channel

@bug_bounty_channel


All bug bounties here.

Bug Bounty Channel

03 Sep, 18:36


Hacktivity from cybxis
 
Login email verification bypass via \`/oauth/token\`\.

https://hackerone.com/reports/2676025
Disclosed at: 2024-09-03 17:51:10 UTC+0
Created at: 2024-08-22 14:00:30 UTC+0

Bug Bounty Channel

30 Aug, 23:31


Hacktivity from 0xmekky
 
PHP info page disclosure in https://41\.242\.90\.8/

https://hackerone.com/reports/1848780
Disclosed at: 2024-08-30 23:12:32 UTC+0
Created at: 2023-01-27 14:42:49 UTC+0

Bug Bounty Channel

30 Aug, 23:31


Hacktivity from 0xmekky
 
Reflected cross site scripting \(XSS\) attacks Reflected XSS attacks,

https://hackerone.com/reports/1799197
Disclosed at: 2024-08-30 23:13:54 UTC+0
Created at: 2022-12-10 15:23:07 UTC+0

Bug Bounty Channel

30 Aug, 16:36


Hacktivity from deb0con
 
CVE\-2010\-1429 JBoss Insecure Storage of Sensitive Information on ips\.mtn\.co\.ug

https://hackerone.com/reports/2375659
Disclosed at: 2024-08-30 16:28:31 UTC+0
Created at: 2024-02-15 20:52:36 UTC+0

Bug Bounty Channel

30 Aug, 16:36


Hacktivity from deb0con
 
CVE\-2018\-0296 Cisco ASA Denial of Service & Path Traversal vulnerable on \[mtn\.co\.ug\]

https://hackerone.com/reports/2375666
Disclosed at: 2024-08-30 16:28:37 UTC+0
Created at: 2024-02-15 21:01:53 UTC+0

Bug Bounty Channel

30 Aug, 04:35


Hacktivity from saurabhb
 
Private data related to program exposed via /reports/<id>\.json endpoint to external user participant

https://hackerone.com/reports/2580982
Disclosed at: 2024-08-30 03:53:25 UTC+0
Created at: 2024-06-28 12:22:19 UTC+0

Bug Bounty Channel

29 Aug, 18:35


Hacktivity from 0xelkot
 
XSS on ███████

https://hackerone.com/reports/2615670
Disclosed at: 2024-08-29 17:45:46 UTC+0
Created at: 2024-07-22 07:44:56 UTC+0

Bug Bounty Channel

29 Aug, 18:35


Hacktivity from thpless
 
XSS found for https://█████████

https://hackerone.com/reports/2670521
Disclosed at: 2024-08-29 17:46:25 UTC+0
Created at: 2024-08-20 06:26:14 UTC+0

Bug Bounty Channel

29 Aug, 18:35


Hacktivity from iamunixtz
 
Blind Sql Injection in https://████

https://hackerone.com/reports/2597543
Disclosed at: 2024-08-29 17:47:35 UTC+0
Created at: 2024-07-11 16:44:20 UTC+0

Bug Bounty Channel

28 Aug, 09:31


Hacktivity from mmg
 
SQL injection in https://demor\.adr\.acronis\.com/ via the username parameter

https://hackerone.com/reports/1436751
Disclosed at: 2024-08-28 09:01:45 UTC+0
Created at: 2021-12-27 16:10:36 UTC+0

Bug Bounty Channel

28 Aug, 09:30


Hacktivity from mikkocarreon
 
\[CVE\-2021\-44228\] Arbitrary Code Execution on ng01\-cloud\.acronis\.com

https://hackerone.com/reports/1459714
Disclosed at: 2024-08-28 09:03:58 UTC+0
Created at: 2022-01-25 07:33:15 UTC+0

Bug Bounty Channel

28 Aug, 09:30


Hacktivity from godiego
 
\[forum\.acronis\.com\] JNDI Code Injection due an outdated log4j component

https://hackerone.com/reports/1430622
Disclosed at: 2024-08-28 09:04:18 UTC+0
Created at: 2021-12-19 06:07:01 UTC+0

Bug Bounty Channel

27 Aug, 15:32


Hacktivity from renniepak
 
MetaMask Browser \(on Android\) does not enforce Content\-Security\-Policy header

https://hackerone.com/reports/1941767
Disclosed at: 2024-08-27 15:02:23 UTC+0
Created at: 2023-04-11 09:52:42 UTC+0

Bug Bounty Channel

27 Aug, 15:31


Hacktivity from noentry
 
CVE\-2024\-7347: Buffer overread in the ngx\_http\_mp4\_module

https://hackerone.com/reports/2658447
Disclosed at: 2024-08-27 15:11:43 UTC+0
Created at: 2024-08-14 18:06:38 UTC+0

Bug Bounty Channel

27 Aug, 14:36


Hacktivity from mmg
 
Local Privilege Escalation via EXE hijacking with Acronis True Image 2021 installer

https://hackerone.com/reports/970739
Disclosed at: 2024-08-27 13:39:03 UTC+0
Created at: 2020-08-30 14:33:07 UTC+0

Bug Bounty Channel

27 Aug, 14:36


Hacktivity from mmg
 
Local Privilege Escalation via EXE hijacking with Acronis True Image 2021 \- Acronis Scheduler2 Service

https://hackerone.com/reports/971610
Disclosed at: 2024-08-27 13:46:27 UTC+0
Created at: 2020-08-31 21:20:38 UTC+0

Bug Bounty Channel

27 Aug, 14:36


Hacktivity from z3ron3
 
DLL Hijacking when sending feedback and crash report leading to Privilege Escalation

https://hackerone.com/reports/1008427
Disclosed at: 2024-08-27 13:46:49 UTC+0
Created at: 2020-10-14 13:17:52 UTC+0

Bug Bounty Channel

27 Aug, 14:36


Hacktivity from z3ron3
 
DLL Hijacking when creating Rescue Media Builder leading to Privilege Escalation

https://hackerone.com/reports/1010552
Disclosed at: 2024-08-27 13:48:12 UTC+0
Created at: 2020-10-17 09:59:28 UTC+0

Bug Bounty Channel

27 Aug, 14:36


Hacktivity from sanderz31
 
Acronis True Image 2020 Build 22510 Nonstop Backup Service Unquoted service path \(privilege escalation\)

https://hackerone.com/reports/1083532
Disclosed at: 2024-08-27 13:49:17 UTC+0
Created at: 2021-01-21 20:01:36 UTC+0

Bug Bounty Channel

27 Aug, 14:36


Hacktivity from vanitas
 
TrueImage for Acronis True Image 2020 \- Untrusted DLL Search\-Ordering lead to Privilege Escalation as Administrative account

https://hackerone.com/reports/959017
Disclosed at: 2024-08-27 13:49:50 UTC+0
Created at: 2020-08-14 18:18:16 UTC+0