VK.com - HackerOne Reports
View on HackerOne163
Total Reports
7
Critical
30
High
38
Medium
38
Low
Open redirect на мобильной версии в контакте (m.vk.com
Reported by:
executor
|
Disclosed:
Medium
Weakness: Open Redirect
Bounty: $300.00
Баг с оплатой подписки
Reported by:
azimoff
|
Disclosed:
Medium
Bounty: $300.00
Делаем плейлист от любого(почти) пользователя/группы/артиста.
Reported by:
executor
|
Disclosed:
Low
Bounty: $100.00
Clickjacking vkpay
Reported by:
0x3c3e
|
Disclosed:
Medium
Weakness: UI Redressing (Clickjacking)
XSS в личных сообщениях
Reported by:
vladvis
|
Disclosed:
High
Weakness: Cross-site Scripting (XSS) - Stored
HTML Injection possible due to bad filter
Reported by:
jackb898
|
Disclosed:
Low
Weakness: Cross-site Scripting (XSS) - Generic
Missing Server Side Rate Limiting can Lead to VK Account Take over
Reported by:
mkap
|
Disclosed:
Weakness: Violation of Secure Design Principles
Bounty: $400.00
Просмотр аттачей удаленного сообщения.....
Reported by:
executor
|
Disclosed:
Low
Weakness: Information Disclosure
Bounty: $200.00
Просмотр инфы на странице пользователя или группы который тебя добавил в ЧС
Reported by:
pisarenko
|
Disclosed:
Low
Weakness: Information Disclosure
Bounty: $200.00
Раскрытие названия частной группы через старый бокс просмотра фото.
Reported by:
executor
|
Disclosed:
Medium
Weakness: Information Disclosure
Bounty: $100.00
доступ к com.vk.usersstore.UsersContentProvider, возможна утечка exchange_token на android < 21
Reported by:
korniltsev
|
Disclosed:
Low
Weakness: Improper Access Control - Generic
CSRF отредактировать карточки в посте у группы
Reported by:
circuit
|
Disclosed:
Weakness: Cross-Site Request Forgery (CSRF)
Bounty: $100.00
Смотрим фотографии из частных/закрытых групп.
Reported by:
executor
|
Disclosed:
High
Weakness: Information Disclosure
Bounty: $500.00
Получение стикеров
Reported by:
sql
|
Disclosed:
Low
Weakness: Business Logic Errors
Bounty: $200.00
Reflected Xss On https://vk.com/search
Reported by:
b4walid
|
Disclosed:
Medium
Weakness: Cross-site Scripting (XSS) - Reflected
Bounty: $500.00
Способ узнать имя человека и ВУЗ удаленной страницы
Reported by:
grande
|
Disclosed:
Weakness: Privilege Escalation
Нет маркера на добавление песни в плейлист пользователя
Reported by:
pisarenko
|
Disclosed:
Low
Weakness: CRLF Injection
Bounty: $100.00
Stored XSS при удалении группы из беседы (m.vk.com)
Reported by:
aboba
|
Disclosed:
Low
Weakness: Cross-site Scripting (XSS) - Stored
Bounty: $500.00
Возможность провести DoS атаку от имени vk.com сервера
Reported by:
denispugachev
|
Disclosed:
Мини-уязвимость в обработке ссылок
Reported by:
qwe
|
Disclosed:
Low
Page 1 of 9
Next