Informatica - HackerOne Reports
View on HackerOne68
Total Reports
11
Critical
34
High
14
Medium
7
Low
[informatica.com] Blind SQL Injection
Reported by:
konqi
|
Disclosed:
Critical
Weakness: SQL Injection
[marketplace.informatica.com]-Reflected XSS
Reported by:
0ways
|
Disclosed:
Medium
Weakness: Cross-site Scripting (XSS) - Reflected
EXIF metadata not stripped from profile image
Reported by:
growler09
|
Disclosed:
Medium
Weakness: Missing Encryption of Sensitive Data
[marketplace.informatica.com] - XXE
Reported by:
yarbabin
|
Disclosed:
High
Weakness: Command Injection - Generic
[marketplace.informatica.com] - XXE
Reported by:
yarbabin
|
Disclosed:
High
Weakness: Command Injection - Generic
[now.informatica.com] Reflective XSS
Reported by:
robd4k
|
Disclosed:
High
Weakness: Cross-site Scripting (XSS) - Generic
[http://www.informatica.com]- info disclosure
Reported by:
modam3r5
|
Disclosed:
Critical
Weakness: Information Disclosure
Blind SQL injection at tsftp.informatica.com
Reported by:
r1pley
|
Disclosed:
Critical
Weakness: SQL Injection
No rate limiting on form[register]
Reported by:
growler09
|
Disclosed:
Weakness: Improper Access Control - Generic
[afocusp.informatica.com] Sql injection afocusp.informatica.com:37777
Reported by:
e3xpl0it
|
Disclosed:
Critical
Weakness: SQL Injection
[parc.informatica.com] Reflected Cross Site Scripting and Open Redirect
Reported by:
bogdantcaciuc
|
Disclosed:
Medium
Weakness: Cross-site Scripting (XSS) - Generic
[ipm.informatica.com] Sql injection Oracle
Reported by:
e3xpl0it
|
Disclosed:
Critical
Weakness: SQL Injection
XXE in upload file feature
Reported by:
yarbabin
|
Disclosed:
High
Weakness: Uncontrolled Resource Consumption
[app.informaticaondemand.com] XXE
Reported by:
yarbabin
|
Disclosed:
High
Weakness: Uncontrolled Resource Consumption
[rev-app.informatica.com] - XXE
Reported by:
yarbabin
|
Disclosed:
High
Weakness: Uncontrolled Resource Consumption
loing in to marketplace panel on enablement.informatica.com
Reported by:
lu3ky-13
|
Disclosed:
Medium
Weakness: Improper Authentication - Generic
Unrestricted file upload - cloudacademy.informatica.com
Reported by:
0ways
|
Disclosed:
Medium
[marketplace.informatica.com] - Stored XSS
Reported by:
jubabaghdad
|
Disclosed:
High
Weakness: Cross-site Scripting (XSS) - Stored
[careers.informatica.com] XSS on "isJTN"
Reported by:
huntertxt
|
Disclosed:
High
Weakness: Cross-site Scripting (XSS) - Generic
[doc.rt.informaticacloud.com] Reflected XSS via Stack Strace
Reported by:
bigbear_
|
Disclosed:
High
Weakness: Cross-site Scripting (XSS) - Reflected