8x8 - HackerOne Reports
View on HackerOne70
Total Reports
6
Critical
20
High
27
Medium
17
Low
wavecell.com: Broken Link Hijacking / Instagram Takeover @██
Reported by:
xxxdopa
|
Disclosed:
Low
Weakness: Externally Controlled Reference to a Resource in Another Sphere
vidyard api auth_token exposed
Reported by:
stilou
|
Disclosed:
Medium
Weakness: Information Disclosure
Open Redirect ███.8x8.com
Reported by:
mr-k0anti
|
Disclosed:
Low
Weakness: Open Redirect
Subdomain takeover of ███.wavecell.com
Reported by:
ian
|
Disclosed:
High
Weakness: Privilege Escalation
Subdomain Takeover at http://██.get8x8.com/
Reported by:
testingforbugs
|
Disclosed:
Medium
Weakness: Leftover Debug Code (Backdoor)
Directory Listing vulnerability on █.packet8.net/php/include/
Reported by:
rajauzairabdullah
|
Disclosed:
Low
Weakness: Information Exposure Through Directory Listing
Default Creds Spring Boot Admin
Reported by:
testingforbugs
|
Disclosed:
High
Weakness: Information Disclosure
Remote Code Execution on ██.8x8.com via .NET VSTATE Deserialization
Reported by:
0daystolive
|
Disclosed:
Critical
Weakness: Code Injection
Open Redirect on [blog.wavecell.com]
Reported by:
melbadry9
|
Disclosed:
Low
Weakness: Open Redirect
Unprotected Atlantis Server at https://132.226.█.█
Reported by:
imranhudaa
|
Disclosed:
Medium
Weakness: Improper Authentication - Generic
LFI via Jolokia at https://█.█.█.█:1293
Reported by:
shuvam321
|
Disclosed:
Medium
Weakness: Information Disclosure
Disclosure of Users Information On Wordpress Api [https://jitsi.org/]
Reported by:
0xelkomy
|
Disclosed:
Low
Weakness: Improper Access Control - Generic
Access to ██████████████ due to weak credentials
Reported by:
kingragnar
|
Disclosed:
Medium
Weakness: Improper Authentication - Generic
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
Reported by:
n1had
|
Disclosed:
Low
Weakness: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
Stored Cross Site Scripting.
Reported by:
shakhawatpr99
|
Disclosed:
High
Weakness: Cross-site Scripting (XSS) - Stored
CRLF injection agentcrm.8x8.com
Reported by:
w2w
|
Disclosed:
Medium
Weakness: CRLF Injection
XSS (Cross site scripting) on https://apimgr.8x8.com
Reported by:
madrobot
|
Disclosed:
Medium
Weakness: Cross-site Scripting (XSS) - Reflected
CVE-2019-11248 on http://█.█.█.█:9100/debug/pprof/goroutine
Reported by:
mr-k0anti
|
Disclosed:
Low
Weakness: Information Disclosure
Credential leak on GitHub: https://github.com/█/█/ (Peoplesoft CRM)
Reported by:
pentestor
|
Disclosed:
Low
Weakness: Use of Hard-coded Credentials
Directory listing of https://get8x8.com/
Reported by:
whitehatmat
|
Disclosed:
Low