Clario - HackerOne Reports
View on HackerOne37
Total Reports
0
Critical
1
High
10
Medium
26
Low
Reflected XSS on stage.mackeeper.com
Reported by:
karna__
|
Disclosed:
Low
Weakness: Cross-site Scripting (XSS) - Reflected
Bounty: $60.00
RXSS on unsubscribe feature (affiliates.kromtech.com)
Reported by:
sec0ndw0lf
|
Disclosed:
Low
Weakness: Cross-site Scripting (XSS) - Reflected
Bounty: $75.00
Multiple Links Vulnerable to Reflected xss
Reported by:
dilawer
|
Disclosed:
Low
Weakness: Cross-site Scripting (XSS) - Reflected
Bounty: $50.00
RXSS on landings/land/3/ron_clean_17_app3_alerts/index.php (mackeeperapp3.mackeeper.com)
Reported by:
sec0ndw0lf
|
Disclosed:
Low
Weakness: Cross-site Scripting (XSS) - Reflected
Bounty: $75.00
CRLF Injection - http://stage.mackeeper.com/
Reported by:
kphaks
|
Disclosed:
Low
Weakness: CRLF Injection
Bounty: $50.00
RXSS on /landings/123.1/index.php (mackeeperapp.mackeeper.com)
Reported by:
sec0ndw0lf
|
Disclosed:
Medium
Weakness: Cross-site Scripting (XSS) - Reflected
Bounty: $300.00
Account Takeover because of the mis-configuration on the Password Reset Page
Reported by:
karna__
|
Disclosed:
Medium
Weakness: Business Logic Errors
Bounty: $300.00
XSS in https://affiliates.kromtech.com
Reported by:
kphaks
|
Disclosed:
Medium
Weakness: Cross-site Scripting (XSS) - Reflected
Bounty: $300.00
Open Redirect at https://store.mackeeper.com/767/cookie via redirectto parameter
Reported by:
sec0ndw0lf
|
Disclosed:
Low
Weakness: Open Redirect
Bounty: $50.00
rXSS on https://mackeeperapp.mackeeper.com/landings/download-blue/
Reported by:
trungnd95
|
Disclosed:
Low
Weakness: Cross-site Scripting (XSS) - Reflected
Open redirect on https://account.mackeeper.com
Reported by:
jin0ne
|
Disclosed:
Low
Weakness: Open Redirect
MK Site Cross-Site Scripting (XSS) in script context
Reported by:
adelin30
|
Disclosed:
Low
Weakness: Cross-site Scripting (XSS) - Reflected
rxss at https://mackeeper.com page not found via rid parameter
Reported by:
g0dzira
|
Disclosed:
Low
Weakness: Cross-site Scripting (XSS) - Reflected
Unauthenticated Reflected Cross-Site Scripting on https://account.mackeeper.com/signin page
Reported by:
patient_zero
|
Disclosed:
Low
Weakness: Cross-site Scripting (XSS) - Reflected
CRLF Injection - http://stage-static-cdn.mackeeper.com/
Reported by:
kphaks
|
Disclosed:
Low
Weakness: CRLF Injection
Bounty: $50.00
Information disclosure of Internal php files on [mackeeper.com/blog/api/send-event]
Reported by:
darkerhack
|
Disclosed:
Low
Weakness: Information Exposure Through an Error Message
Social media link hijack of team member [Linkedin] at https://mackeeper.com/team/
Reported by:
beerboy_ankit
|
Disclosed:
Low
Weakness: Misconfiguration
Previous
Page 2 of 2