Skip to content

Latest commit

 

History

History
78 lines (77 loc) · 8.84 KB

TOPYAHOO!.md

File metadata and controls

78 lines (77 loc) · 8.84 KB

Top reports from Yahoo! program at HackerOne:

  1. Local File Include on marketing-dam.yahoo.com to Yahoo! - 19 upvotes, $2500
  2. Header injection on rmaitrack.ads.vip.bf1.yahoo.com to Yahoo! - 16 upvotes, $1000
  3. Cross-site scripting on the main page of flickr by tagging a user. to Yahoo! - 14 upvotes, $2173
  4. XSS Yahoo Messenger Via Calendar.Yahoo.Com to Yahoo! - 14 upvotes, $677
  5. Store XSS Flicker main page to Yahoo! - 12 upvotes, $1960
  6. REMOTE CODE EXECUTION/LOCAL FILE INCLUSION/XSPA/SSRF, view-source:http://sb*.geo.sp1.yahoo.com/, 4/6/14, #SpringClean to Yahoo! - 11 upvotes, $3000
  7. Loadbalancer + URI XSS #3 to Yahoo! - 10 upvotes, $0
  8. readble .htaccess + Source Code Disclosure (+ .SVN repository) to Yahoo! - 8 upvotes, $250
  9. HK.Yahoo.Net Remote Command Execution to Yahoo! - 7 upvotes, $1276
  10. Bypass of the Clickjacking protection on Flickr using data URL in iframes to Yahoo! - 7 upvotes, $250
  11. Information Disclosure to Yahoo! - 7 upvotes, $0
  12. From Unrestricted File Upload to Remote Command Execution to Yahoo! - 6 upvotes, $800
  13. HTML Injection on flickr screename using IOS App to Yahoo! - 6 upvotes, $800
  14. Directory Traversal to Yahoo! - 6 upvotes, $0
  15. SQLi on http://sports.yahoo.com/nfl/draft to Yahoo! - 5 upvotes, $3705
  16. Java Applet Execution On Y! Messenger to Yahoo! - 5 upvotes, $0
  17. Local file inclusion to Yahoo! - 4 upvotes, $1390
  18. Significant Information Disclosure/Load balancer access, http://extprodweb11.cc.gq1.yahoo.com/, 4/8/14, #SpringClean to Yahoo! - 4 upvotes, $500
  19. reflected XSS, http://extprodweb11.cc.gq1.yahoo.com/, 4/8/14, #SpringClean to Yahoo! - 4 upvotes, $300
  20. ads.yahoo.com Unvalidate open url redirection to Yahoo! - 4 upvotes, $0
  21. Security.allowDomain("*") in SWFs on img.autos.yahoo.com allows data theft from Yahoo Mail (and others) to Yahoo! - 3 upvotes, $2500
  22. SQL Injection ON HK.Promotion to Yahoo! - 3 upvotes, $1000
  23. Flickr: Invitations disclosure (resend feature) to Yahoo! - 3 upvotes, $750
  24. https://caldav.calendar.yahoo.com/ - XSS (STORED) to Yahoo! - 3 upvotes, $500
  25. invite1.us2.msg.vip.bf1.yahoo.com/ - CSRF/email disclosure to Yahoo! - 3 upvotes, $400
  26. XSS Vulnerability (my.yahoo.com) to Yahoo! - 3 upvotes, $250
  27. http://conf.member.yahoo.com configuration file disclosure to Yahoo! - 3 upvotes, $100
  28. Default /docs folder of PHPBB3 installation on gamesnet.yahoo.com to Yahoo! - 3 upvotes, $50
  29. ClickJacking on http://au.launch.yahoo.com to Yahoo! - 3 upvotes, $0
  30. Yahoo YQL Injection? to Yahoo! - 3 upvotes, $0
  31. In Fantasy Sports iOS app, signup page is requested over HTTP to Yahoo! - 3 upvotes, $0
  32. caesary.yahoo.net Blind Sql Injection to Yahoo! - 3 upvotes, $0
  33. Stored Cross Site Scripting Vulnerability in Yahoo Mail to Yahoo! - 3 upvotes, $0
  34. XSS in my yahoo to Yahoo! - 2 upvotes, $800
  35. information disclosure (LOAD BALANCER + URI XSS) to Yahoo! - 2 upvotes, $300
  36. XSS in Yahoo! Web Analytics to Yahoo! - 2 upvotes, $100
  37. Vulnerability found, XSS (Cross site Scripting) to Yahoo! - 2 upvotes, $0
  38. HTML Code Injection to Yahoo! - 2 upvotes, $0
  39. Open Redirect via Request-URI to Yahoo! - 2 upvotes, $0
  40. XSS using yql and developers console proxy to Yahoo! - 2 upvotes, $0
  41. Bypass of anti-SSRF defenses in YahooCacheSystem (affecting at least YQL and Pipes) to Yahoo! - 2 upvotes, $0
  42. XSS Reflected - Yahoo Travel to Yahoo! - 2 upvotes, $0
  43. Yahoo mail login page bruteforce protection bypass to Yahoo! - 2 upvotes, $0
  44. Clickjacking at surveylink.yahoo.com to Yahoo! - 2 upvotes, $0
  45. Almost all the subdomains are infected. to Yahoo! - 2 upvotes, $0
  46. http://us.rd.yahoo.com/ to Yahoo! - 2 upvotes, $0
  47. XSS on Every sports.yahoo.com page to Yahoo! - 1 upvotes, $1500
  48. Server Side Request Forgery to Yahoo! - 1 upvotes, $500
  49. XSS in https://hk.user.auctions.yahoo.com to Yahoo! - 1 upvotes, $500
  50. Comment Spoofing at http://suggestions.yahoo.com/detail/?prop=directory&fid=97721 to Yahoo! - 1 upvotes, $500
  51. Cross-origin issue on rmaiauth.ads.vip.bf1.yahoo.com to Yahoo! - 1 upvotes, $250
  52. Yahoo! Reflected XSS to Yahoo! - 1 upvotes, $250
  53. Yahoo open redirect using ad to Yahoo! - 1 upvotes, $0
  54. A csrf vulnerability which add and remove a favorite team from a user account. to Yahoo! - 1 upvotes, $0
  55. Insufficient validation of redirect URL on login page allows hijacking user name and password to Yahoo! - 1 upvotes, $0
  56. Reflected XSS in mail.yahoo.com to Yahoo! - 1 upvotes, $0
  57. Authentication bypass at fast.corp.yahoo.com to Yahoo! - 1 upvotes, $0
  58. Information Disclosure, groups.yahoo.com,6-april-2014, #SpringClean to Yahoo! - 1 upvotes, $0
  59. clickjacking on leaving group(flick) to Yahoo! - 1 upvotes, $0
  60. Yahoo! Messenger v11.5.0.228 emoticons.xml shortcut Value Handling Stack-Based Buffer Overflow to Yahoo! - 1 upvotes, $0
  61. Open Proxy, http://www.smushit.com/ysmush.it/, 4/09/14, #SpringClean to Yahoo! - 0 upvotes, $2000
  62. CSRF Token missing on http://baseball.fantasysports.yahoo.com/b1/127146/messages to Yahoo! - 0 upvotes, $400
  63. Infrastructure and Application Admin Interfaces (OWASP‐CM‐007) to Yahoo! - 0 upvotes, $250
  64. Yahoo Sports Fantasy Golf (Join Public Group) to Yahoo! - 0 upvotes, $200
  65. CSRF Token is missing on DELETE message option on http://baseball.fantasysports.yahoo.com/b1/127146/messages to Yahoo! - 0 upvotes, $200
  66. Testing for user enumeration (OWASP‐AT‐002) - https://gh.bouncer.login.yahoo.com to Yahoo! - 0 upvotes, $100
  67. Authorization issue on creative.yahoo.com to Yahoo! - 0 upvotes, $50
  68. Open redirect on tw.money.yahoo.com to Yahoo! - 0 upvotes, $0
  69. TESTING FOR REFLECTED CROSS SITE SCRIPTING (OWASP‐DV‐001) to Yahoo! - 0 upvotes, $0
  70. Multiple vulnerabilities to Yahoo! - 0 upvotes, $0
  71. URL Redirection to Yahoo! - 0 upvotes, $0
  72. clickjacking to Yahoo! - 0 upvotes, $0
  73. Authentication Bypass in Yahoo Groups to Yahoo! - 0 upvotes, $0
  74. Open URL Redirection to Yahoo! - 0 upvotes, $0
  75. Out of date version to Yahoo! - 0 upvotes, $0
  76. Authentication Bypass due to Session Mismanagement to Yahoo! - 0 upvotes, $0