Top reports from U.S. Dept Of Defense program at HackerOne:
- Stored Xss Vulnerability on ████████ to U.S. Dept Of Defense - 149 upvotes, $0
- Public instance of Jenkins on https://██████████/ with /script enabled to U.S. Dept Of Defense - 107 upvotes, $0
- XXE in DoD website that may lead to RCE to U.S. Dept Of Defense - 86 upvotes, $0
- Remote Code Execution (RCE) in a DoD website to U.S. Dept Of Defense - 80 upvotes, $0
- Remote Code Execution in ██████ to U.S. Dept Of Defense - 78 upvotes, $0
- SQL Injection on www.██████████ on countID parameter to U.S. Dept Of Defense - 76 upvotes, $0
- SQL Injection in ████ to U.S. Dept Of Defense - 68 upvotes, $0
- RCE on █████ via CVE-2017-10271 to U.S. Dept Of Defense - 67 upvotes, $0
- Remote Code Execution through DNN Cookie Deserialization to U.S. Dept Of Defense - 49 upvotes, $0
- Information disclousure by clicking on the link shown in http://████████/ to U.S. Dept Of Defense - 45 upvotes, $0
- SQL Injection in ████ to U.S. Dept Of Defense - 41 upvotes, $0
- Gateway information leakage to U.S. Dept Of Defense - 40 upvotes, $0
- SQL Injection vulnerability located at ████████ to U.S. Dept Of Defense - 40 upvotes, $0
- Local File Inclusion vulnerability on an Army system allows downloading local files to U.S. Dept Of Defense - 38 upvotes, $0
- Remote code execution on an Army website to U.S. Dept Of Defense - 31 upvotes, $0
- LFI with potential to RCE on ██████ using CVE-2019-3396 to U.S. Dept Of Defense - 31 upvotes, $0
- Unrestricted File Upload to U.S. Dept Of Defense - 29 upvotes, $0
- Remote Code Execution (RCE) in a DoD website to U.S. Dept Of Defense - 29 upvotes, $0
- SOAP WSDL Parser SQL Code Execution to U.S. Dept Of Defense - 29 upvotes, $0
- Pulse Secure File disclosure, clear text and potential RCE to U.S. Dept Of Defense - 29 upvotes, $0
- Remote Code Execution via Insecure Deserialization in Telerik UI to U.S. Dept Of Defense - 29 upvotes, $0
- XXE on DoD web server to U.S. Dept Of Defense - 28 upvotes, $0
- SSRF+XSS to U.S. Dept Of Defense - 27 upvotes, $0
- SQL injection to U.S. Dept Of Defense - 26 upvotes, $0
- Trace.axd page leaks sensitive information to U.S. Dept Of Defense - 25 upvotes, $0
- Information Disclosure to U.S. Dept Of Defense - 23 upvotes, $0
- [██████] Cross-origin resource sharing misconfiguration (CORS) to U.S. Dept Of Defense - 23 upvotes, $0
- ████ - Complete account takeover to U.S. Dept Of Defense - 22 upvotes, $0
- SQL injection on the https://████/ to U.S. Dept Of Defense - 21 upvotes, $0
- SSRF vulnerability on ██████████ leaks internal IP and various sensitive information to U.S. Dept Of Defense - 21 upvotes, $0
- [Partial] SSN & [PII] exposed through iPERMs Presentation Slide. to U.S. Dept Of Defense - 21 upvotes, $0
- Command Injection (via CVE-2019-11510 and CVE-2019-11539) to U.S. Dept Of Defense - 21 upvotes, $0
- RCE on a Department of Defense website to U.S. Dept Of Defense - 19 upvotes, $0
- Access to all █████████ files, including CAC authentication bypass to U.S. Dept Of Defense - 19 upvotes, $0
- SSRF on █████████ Allowing internal server data access to U.S. Dept Of Defense - 19 upvotes, $0
- Publicly accessible Order confirmations leaking User Emails on ███ to U.S. Dept Of Defense - 19 upvotes, $0
- ███ exposes sensitive shipment information to public web to U.S. Dept Of Defense - 18 upvotes, $0
- [REMOTE] Full Account Takeover At https://██████████████/CAS/ to U.S. Dept Of Defense - 18 upvotes, $0
- Examples directory is PUBLIC on https://████████mil, leading to multiple vulns to U.S. Dept Of Defense - 18 upvotes, $0
- Remote code execution vulnerability on a DoD website to U.S. Dept Of Defense - 17 upvotes, $0
- Partial SSN exposed through Presentation slides on ██████████ to U.S. Dept Of Defense - 17 upvotes, $0
- Arbitrary File Reading leads to RCE in the Pulse Secure SSL VPN on the https://███ to U.S. Dept Of Defense - 17 upvotes, $0
- SQL injection vulnerability on a DoD website to U.S. Dept Of Defense - 16 upvotes, $0
- Remote Code Execution (RCE) in DoD Websites to U.S. Dept Of Defense - 16 upvotes, $0
- Request smuggling on ████████ to U.S. Dept Of Defense - 16 upvotes, $0
- PII leakage due to scrceenshot of health records to U.S. Dept Of Defense - 16 upvotes, $0
- ███████ Site Exposes █████████ forms to U.S. Dept Of Defense - 15 upvotes, $0
- Video player on ███ allows arbitrary remote videos to be played to U.S. Dept Of Defense - 15 upvotes, $0
- Misconfigured password reset vulnerability on a DoD website to U.S. Dept Of Defense - 14 upvotes, $0
- Blind SQLi vulnerability in a DoD Website to U.S. Dept Of Defense - 14 upvotes, $0
- Open FTP server on a DoD system to U.S. Dept Of Defense - 14 upvotes, $0
- PII leakage due to caching of Order/Contract ID's on █████████ to U.S. Dept Of Defense - 14 upvotes, $0
- Blind SQL injection on ████████ to U.S. Dept Of Defense - 14 upvotes, $0
- [█████] — DOM-based XSS on endpoint
/?s=
to U.S. Dept Of Defense - 14 upvotes, $0 - SQL injection vulnerability on a DoD website to U.S. Dept Of Defense - 13 upvotes, $0
- PII leakage-Full SSN on ███ to U.S. Dept Of Defense - 13 upvotes, $0
- XSS on www.██████ alerts and a number of other pages to U.S. Dept Of Defense - 13 upvotes, $0
- http://████/data.json showing users sensitive information via json file to U.S. Dept Of Defense - 13 upvotes, $0
- Self XSS combine CSRF at https://████████/index.php to U.S. Dept Of Defense - 13 upvotes, $0
- DOM Based XSS on an Army website to U.S. Dept Of Defense - 12 upvotes, $0
- Remote Code Execution (RCE) in a DoD website to U.S. Dept Of Defense - 12 upvotes, $0
- [Critical] Full local fylesystem access (LFI/LFD) as admin via Path Traversal in the misconfigured Java servlet on the https://███/ to U.S. Dept Of Defense - 12 upvotes, $0
- SSN leak due to editable slides to U.S. Dept Of Defense - 12 upvotes, $0
- Unrestricted File Download / Path Traversal to U.S. Dept Of Defense - 11 upvotes, $0
- Reflected cross-site scripting vulnerability on a DoD website to U.S. Dept Of Defense - 11 upvotes, $0
- SQL injections to U.S. Dept Of Defense - 11 upvotes, $0
- IDOR on DoD Website exposes FTP users and passes linked to all accounts! to U.S. Dept Of Defense - 11 upvotes, $0
- Local file inclusion vulnerability on a DoD website to U.S. Dept Of Defense - 10 upvotes, $0
- Remote Code Execution (RCE) in a DoD website to U.S. Dept Of Defense - 10 upvotes, $0
- SQL Injection vulnerability in a DoD website to U.S. Dept Of Defense - 10 upvotes, $0
- Remote Code Execution - Unauthenticated Remote Command Injection (via Microsoft SharePoint CVE-2019-0604) to U.S. Dept Of Defense - 10 upvotes, $0
- Previously Compromised PulseSSL VPN Hosts to U.S. Dept Of Defense - 10 upvotes, $0
- Privilege Escalation on a DoD Website to U.S. Dept Of Defense - 9 upvotes, $0
- Authentication bypass vulnerability on a DoD website to U.S. Dept Of Defense - 9 upvotes, $0
- Reflected XSS on a DoD website to U.S. Dept Of Defense - 9 upvotes, $0
- Blind SQLi in a DoD Website to U.S. Dept Of Defense - 9 upvotes, $0
- Time Based SQL Injection vulnerability on a DoD website to U.S. Dept Of Defense - 9 upvotes, $0
- [Critical] Possibility to takeover any user account #2 without interaction on the https://██████████ to U.S. Dept Of Defense - 9 upvotes, $0
- Path traversal on ████████ to U.S. Dept Of Defense - 9 upvotes, $0
- SQL injection on █████ due to tech.cfm to U.S. Dept Of Defense - 9 upvotes, $0
- MSSQL injection via param Customwho in https://█████/News/Transcripts/Search/Sort/ and WAF bypass to U.S. Dept Of Defense - 9 upvotes, $0
- Reflected XSS in a Navy website to U.S. Dept Of Defense - 8 upvotes, $0
- Reflected XSS on an Army website to U.S. Dept Of Defense - 8 upvotes, $0
- Reflected XSS on a Department of Defense website to U.S. Dept Of Defense - 8 upvotes, $0
- Reflected XSS on a Department of Defense website to U.S. Dept Of Defense - 8 upvotes, $0
- Personal information disclosure on a DoD website to U.S. Dept Of Defense - 8 upvotes, $0
- File upload vulnerability on a DoD website to U.S. Dept Of Defense - 8 upvotes, $0
- Remote code execution (RCE) in multiple DoD websites to U.S. Dept Of Defense - 8 upvotes, $0
- Remote Code Execution (RCE) in a DoD website to U.S. Dept Of Defense - 8 upvotes, $0
- Server-Side Request Forgery (SSRF) to U.S. Dept Of Defense - 8 upvotes, $0
- [CVE-2019-11510 ] Path Traversal on ████████ leads to leaked passwords, RCE, etc to U.S. Dept Of Defense - 8 upvotes, $0
- Reflected XSS on a Navy website to U.S. Dept Of Defense - 7 upvotes, $0
- QuickTime Promotion on a DoD website to U.S. Dept Of Defense - 7 upvotes, $0
- Exposed Access Control Data Backup Files on DoD Website to U.S. Dept Of Defense - 7 upvotes, $0
- Reflected XSS vulnerability on a DoD website to U.S. Dept Of Defense - 7 upvotes, $0
- Information disclosure on a DoD website to U.S. Dept Of Defense - 7 upvotes, $0
- Remote Command Execution on a DoD website to U.S. Dept Of Defense - 7 upvotes, $0
- Bypass file access control vulnerability on a DoD website to U.S. Dept Of Defense - 7 upvotes, $0
- XSS on a DoD website to U.S. Dept Of Defense - 7 upvotes, $0
- SQL injection vulnerability on a DoD website to U.S. Dept Of Defense - 7 upvotes, $0
- Information disclosure vulnerability on a DoD website to U.S. Dept Of Defense - 7 upvotes, $0
- Server-side include injection vulnerability in a DoD website to U.S. Dept Of Defense - 7 upvotes, $0
- Information disclosure on a DoD website to U.S. Dept Of Defense - 7 upvotes, $0
- Cross-site scripting (XSS) vulnerability on a DoD website to U.S. Dept Of Defense - 7 upvotes, $0
- X-XSS-Protection -> Misconfiguration to U.S. Dept Of Defense - 7 upvotes, $0
- Root Remote Code Execution on https://███ to U.S. Dept Of Defense - 7 upvotes, $0
- RCE on https://█████/ Using CVE-2017-9248 to U.S. Dept Of Defense - 7 upvotes, $0
- Exposed ███████ Administrative Interface (ColdFusion 11) to U.S. Dept Of Defense - 7 upvotes, $0
- Corda Server XSS ████████ to U.S. Dept Of Defense - 7 upvotes, $0
- Reflected cross-site scripting vulnerability on a DoD website to U.S. Dept Of Defense - 7 upvotes, $0
- No Rate Limiting on https://██████/██████████/accounts/password/reset/ endpoint leads to Denial of Service to U.S. Dept Of Defense - 7 upvotes, $0
- SQL Injection vulnerability on a DoD website to U.S. Dept Of Defense - 6 upvotes, $0
- Information leakage on a Department of Defense website to U.S. Dept Of Defense - 6 upvotes, $0
- Cross-site scripting (XSS) vulnerability on a DoD website to U.S. Dept Of Defense - 6 upvotes, $0
- Remote file inclusion vulnerability on a DoD website to U.S. Dept Of Defense - 6 upvotes, $0
- HTML injection vulnerability on a DoD website to U.S. Dept Of Defense - 6 upvotes, $0
- Insecure direct object reference vulnerability on a DoD website to U.S. Dept Of Defense - 6 upvotes, $0
- Reflected XSS on a DoD website to U.S. Dept Of Defense - 6 upvotes, $0
- Reflected XSS in a DoD Website to U.S. Dept Of Defense - 6 upvotes, $0
- SQL injection vulnerability on a DoD website to U.S. Dept Of Defense - 6 upvotes, $0
- Remote code execution vulnerability on a DoD website to U.S. Dept Of Defense - 6 upvotes, $0
- Arbitary file download vulnerability on a DoD website to U.S. Dept Of Defense - 6 upvotes, $0
- Limited code execution vulnerability on a DoD website to U.S. Dept Of Defense - 6 upvotes, $0
- Information disclosure vulnerability on a DoD website to U.S. Dept Of Defense - 6 upvotes, $0
- Remote Code Execution (RCE) vulnerability in a DoD website to U.S. Dept Of Defense - 6 upvotes, $0
- ██████ Authenticated User Data Disclosure to U.S. Dept Of Defense - 6 upvotes, $0
- Information Disclosure (can access all ███s) within ███████ view █████████ Portal to U.S. Dept Of Defense - 6 upvotes, $0
- Out-of-date Version (Apache) to U.S. Dept Of Defense - 6 upvotes, $0
- Open FTP on ███ to U.S. Dept Of Defense - 6 upvotes, $0
- Default page exposes admin functions and all metods and classes available. on https://██████/█████/dwr/index.html to U.S. Dept Of Defense - 6 upvotes, $0
- Admin Salt Leakage on DoD site. to U.S. Dept Of Defense - 6 upvotes, $0
- Partial PII leakage due to public set gitlab to U.S. Dept Of Defense - 6 upvotes, $0
- [███] SQL injection & Reflected XSS to U.S. Dept Of Defense - 6 upvotes, $0
- [█████] Get all tickets (IDOR) to U.S. Dept Of Defense - 6 upvotes, $0
- ██████████ bruteforceable RIC Codes allowing information on contracts to U.S. Dept Of Defense - 6 upvotes, $0
- [████████] Boolean SQL Injection (/personnel.php?content=profile&rcnum=*) to U.S. Dept Of Defense - 6 upvotes, $0
- [█████] Reflected GET XSS (/personnel.php?...&rcnum=*) with mouse action to U.S. Dept Of Defense - 6 upvotes, $0
- Unrestricted File Upload to U.S. Dept Of Defense - 6 upvotes, $0
- Null byte Injection in https://████/ to U.S. Dept Of Defense - 6 upvotes, $0
- XSS vulnerability on an Army website to U.S. Dept Of Defense - 5 upvotes, $0
- Open Redirect in a DoD website to U.S. Dept Of Defense - 5 upvotes, $0
- Cross-site request forgery vulnerability on a DoD website to U.S. Dept Of Defense - 5 upvotes, $0
- Password reset vulnerability on a DoD website to U.S. Dept Of Defense - 5 upvotes, $0
- Remote command execution (RCE) vulnerability on a DoD website to U.S. Dept Of Defense - 5 upvotes, $0
- Information disclosure vulnerability on a DoD website to U.S. Dept Of Defense - 5 upvotes, $0
- Information disclosure vulnerability on a DoD website to U.S. Dept Of Defense - 5 upvotes, $0
- Information disclosure vulnerability on a DoD website to U.S. Dept Of Defense - 5 upvotes, $0
- Information disclosure vulnerability on a DoD website to U.S. Dept Of Defense - 5 upvotes, $0
- Open redirect vulnerability in a DoD website to U.S. Dept Of Defense - 5 upvotes, $0
- Reflected cross-site scripting (XSS) vulnerability on a DoD website to U.S. Dept Of Defense - 5 upvotes, $0
- SQL Injection vulnerability in a DoD website to U.S. Dept Of Defense - 5 upvotes, $0
- Arbitary file download vulnerability on a DoD website to U.S. Dept Of Defense - 5 upvotes, $0
- Arbitary file download vulnerability on a DoD website to U.S. Dept Of Defense - 5 upvotes, $0
- Violation of secure design principles on a DoD website to U.S. Dept Of Defense - 5 upvotes, $0
- Server Side Request Forgery (SSRF) vulnerability in a DoD website to U.S. Dept Of Defense - 5 upvotes, $0
- Information disclosure vulnerability on a DoD website to U.S. Dept Of Defense - 5 upvotes, $0
- Insecure Direct Object Reference (IDOR) vulnerability in a DoD website to U.S. Dept Of Defense - 5 upvotes, $0
- Account takeover due to CSRF in "Account details" option on █████████ to U.S. Dept Of Defense - 5 upvotes, $0
- https://█████████ Vulnerable to CVE-2018-0296 Cisco ASA Path Traversal Authentication Bypass to U.S. Dept Of Defense - 5 upvotes, $0
- sql injection on /messagecenter/messagingcenter at https://www.███████/ to U.S. Dept Of Defense - 5 upvotes, $0
- Remote Code Execution (RCE) in a DoD website to U.S. Dept Of Defense - 5 upvotes, $0
- Remote File Inclusion, Malicious File Hosting, and Cross-site Scripting (XSS) in ████████ to U.S. Dept Of Defense - 5 upvotes, $0
- HTML Injection on ████ to U.S. Dept Of Defense - 5 upvotes, $0
- SSRF in ███████ to U.S. Dept Of Defense - 5 upvotes, $0
- SharePoint exposed web services to U.S. Dept Of Defense - 5 upvotes, $0
- LDAP Injection at ██████ to U.S. Dept Of Defense - 5 upvotes, $0
- Email PII disclosure due to Insecure Password Reset field to U.S. Dept Of Defense - 5 upvotes, $0
- PII Leak via https://████████ to U.S. Dept Of Defense - 5 upvotes, $0
- SQL Injection in Login Page: https://█████/█████████/login.php to U.S. Dept Of Defense - 5 upvotes, $0
- Persistent XSS vulnerability on a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
- Cross-site scripting vulnerability on a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
- Cross-site scripting (XSS) vulnerability on a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
- HTML Injection/Load Images vulnerability on a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
- SQL injection vulnerability on a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
- Reflected XSS on a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
- Reflected XSS on a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
- Reflected XSS on a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
- Reflected XSS vulnerability on a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
- Information disclosure vulnerability on a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
- Cross-site request forgery (CSRF) vulnerability in a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
- Reflected XSS vulnerability on a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
- Information disclosure vulnerability in a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
- SQL Injection vulnerability in a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
- SQL Injection vulnerability in a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
- SQL injection vulnerability in a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
- Reflective XSS vulnerability on a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
- Information disclosure vulnerability on a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
- Default credentials on a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
- SQL injection vulnerability on a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
- Remote Code Execution (RCE) vulnerability in multiple DoD websites to U.S. Dept Of Defense - 4 upvotes, $0
- Cross-site scripting (XSS) vulnerability on a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
- Information disclosure vulnerability on a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
- Cross-site scripting (XSS) on a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
- SQL Injection vulnerability in a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
- SQL Injection in the get_publications.php on the https://█████ to U.S. Dept Of Defense - 4 upvotes, $0
- ████████ SQL to U.S. Dept Of Defense - 4 upvotes, $0
- Code reversion allowing SQLI again in ███████ to U.S. Dept Of Defense - 4 upvotes, $0
- Remote Code Execution (RCE) in a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
- WebLogic Server Side Request Forgery to U.S. Dept Of Defense - 4 upvotes, $0
- SharePoint exposed web services to U.S. Dept Of Defense - 4 upvotes, $0
- [████████] Reflected XSS to U.S. Dept Of Defense - 4 upvotes, $0
- [███████] Reflected GET XSS (/mission.php?...&missionDate=*) to U.S. Dept Of Defense - 4 upvotes, $0
- File Upload Restriction Bypass to U.S. Dept Of Defense - 4 upvotes, $0
- Full Account Take-Over of ████████ Members via IDOR to U.S. Dept Of Defense - 4 upvotes, $0
- DNS Misconfiguration to U.S. Dept Of Defense - 3 upvotes, $0
- XSS vulnerability on a DoD website to U.S. Dept Of Defense - 3 upvotes, $0
- Arbitrary Script Injection (Mail) in a DoD Website to U.S. Dept Of Defense - 3 upvotes, $0
- Potentially sensitive information disclosure on a DoD website to U.S. Dept Of Defense - 3 upvotes, $0
- Misconfigured user account settings on DoD website to U.S. Dept Of Defense - 3 upvotes, $0
- Stored cross-site scripting (XSS) on a DoD website to U.S. Dept Of Defense - 3 upvotes, $0
- Cross-Site Scripting (XSS) on a DoD website to U.S. Dept Of Defense - 3 upvotes, $0
- Information disclosure vulnerability on a DoD website to U.S. Dept Of Defense - 3 upvotes, $0
- Remote Code Execution (RCE) in a DoD website to U.S. Dept Of Defense - 3 upvotes, $0
- Remote Code Execution (RCE) in a DoD website to U.S. Dept Of Defense - 3 upvotes, $0
- Server side information disclosure on a DoD website to U.S. Dept Of Defense - 3 upvotes, $0
- Reflected XSS on a DoD website to U.S. Dept Of Defense - 3 upvotes, $0
- Reflected XSS on a DoD website to U.S. Dept Of Defense - 3 upvotes, $0
- Reflected XSS on a DoD website to U.S. Dept Of Defense - 3 upvotes, $0
- DOM Based XSS on a DoD website to U.S. Dept Of Defense - 3 upvotes, $0
- Time Based SQL Injection vulnerability on a DoD website to U.S. Dept Of Defense - 3 upvotes, $0
- Reflected XSS vulnerability on a DoD website to U.S. Dept Of Defense - 3 upvotes, $0
- Cross-site request forgery (CSRF) vulnerability on a DoD website to U.S. Dept Of Defense - 3 upvotes, $0
- Information disclosure vulnerability on a DoD website to U.S. Dept Of Defense - 3 upvotes, $0
- Remote code execution vulnerability on a DoD website to U.S. Dept Of Defense - 3 upvotes, $0
- Stored cross site scripting (XSS) vulnerability on a DoD website to U.S. Dept Of Defense - 3 upvotes, $0
- Reflected XSS vulnerability on a DoD website to U.S. Dept Of Defense - 3 upvotes, $0
- Remote OS command Execution in the 3 more Oracle Weblogic on the ████████, ████, ███████ [CVE-2017-10352] to U.S. Dept Of Defense - 3 upvotes, $0
- Online training material disclosing username and password to U.S. Dept Of Defense - 3 upvotes, $0
- https://████████ Impacted by DNN ImageHandler SSRF to U.S. Dept Of Defense - 3 upvotes, $0
- Admin panel take over | User info leakage | Mass Comprimise to U.S. Dept Of Defense - 3 upvotes, $0
- Sensitive Email disclosure Due to Insecure Reactivate Account field to U.S. Dept Of Defense - 3 upvotes, $0
- Able to view Backend Database dur to improper authentication to U.S. Dept Of Defense - 3 upvotes, $0
- █████ - DOM-based XSS to U.S. Dept Of Defense - 3 upvotes, $0
- █████ - DOM-based XSS to U.S. Dept Of Defense - 3 upvotes, $0
- [██████] Reflected GET XSS (/personnel.php?..&folder=*) with mouse action to U.S. Dept Of Defense - 3 upvotes, $0
- ████ █████ exposes highly sensitive information to public to U.S. Dept Of Defense - 3 upvotes, $0
- [██████████] Unauthorized access to admin panel to U.S. Dept Of Defense - 3 upvotes, $0
- Bypassing CORS Misconfiguration Leads to Sensitive Exposure to U.S. Dept Of Defense - 3 upvotes, $0
- Domian Takeover in [███████] to U.S. Dept Of Defense - 3 upvotes, $0
- [████████] — XSS on
/███████_flight/images
viaadvanced_val
parameter to U.S. Dept Of Defense - 3 upvotes, $0 - [Critical] Insufficient Access Control On Registration Page of Webapps Website Allows Privilege Escalation to Administrator to U.S. Dept Of Defense - 3 upvotes, $0
- Server side information disclosure to U.S. Dept Of Defense - 2 upvotes, $0
- Information disclosure on a DoD website to U.S. Dept Of Defense - 2 upvotes, $0
- Reflected XSS vulnerability in a DoD website to U.S. Dept Of Defense - 2 upvotes, $0
- Stored XSS vulnerability on a DoD website to U.S. Dept Of Defense - 2 upvotes, $0
- Reflected XSS on a DoD website to U.S. Dept Of Defense - 2 upvotes, $0
- Information disclosure vulnerability on a DoD website to U.S. Dept Of Defense - 2 upvotes, $0
- Reflected XSS on a DoD website to U.S. Dept Of Defense - 2 upvotes, $0
- SQL Injection vulnerability in a DoD website to U.S. Dept Of Defense - 2 upvotes, $0
- SQL Injection vulnerability in a DoD website to U.S. Dept Of Defense - 2 upvotes, $0
- 2 vulnerabilities of arbitrary code in ████████ - CVE-2017-5929 to U.S. Dept Of Defense - 2 upvotes, $0
- SSRF on ████████ to U.S. Dept Of Defense - 2 upvotes, $0
- Attackers can control which security questions they are presented (████████) to U.S. Dept Of Defense - 2 upvotes, $0
- Illegal account registration in ████████ to U.S. Dept Of Defense - 2 upvotes, $0
- Insecure Direct Object Reference on in-scope .mil website to U.S. Dept Of Defense - 2 upvotes, $0
- Exposed FTP Credentials on ███████ to U.S. Dept Of Defense - 2 upvotes, $0
- Blind SQL Injection on DoD Site to U.S. Dept Of Defense - 2 upvotes, $0
- █████████ - Insecure download cookie generation allows bypass of CAC authentication, access to deleted and locked files to U.S. Dept Of Defense - 2 upvotes, $0
- Followup - SQL Injection - https://██████████/██████/MSI.portal to U.S. Dept Of Defense - 2 upvotes, $0
- Improper Neutralization of Input During Web Page Generation to U.S. Dept Of Defense - 2 upvotes, $0
- Username&password is Disclosure in readme file in [https://█████████] to U.S. Dept Of Defense - 2 upvotes, $0
- Application level DoS via xmlrpc.php to U.S. Dept Of Defense - 2 upvotes, $0
- No ACL on S3 Bucket in [https://www.██████████/] to U.S. Dept Of Defense - 2 upvotes, $0
- Sensitive Information Leaking Through Navy Website. [█████] to U.S. Dept Of Defense - 2 upvotes, $0
- XSS Reflected to U.S. Dept Of Defense - 2 upvotes, $0
- Unrestricted file upload leads to stored xss on https://████████/ to U.S. Dept Of Defense - 2 upvotes, $0
- Cross-site scripting (XSS) vulnerability on a DoD website to U.S. Dept Of Defense - 1 upvotes, $0
- Critical information disclosure at https://█████████ to U.S. Dept Of Defense - 1 upvotes, $0
- Access to job creation web page on http://████████ to U.S. Dept Of Defense - 1 upvotes, $0
- Content-Injection/XSS ████ to U.S. Dept Of Defense - 1 upvotes, $0
- SQL injection on https://███████ to U.S. Dept Of Defense - 1 upvotes, $0
- Multiple cryptographic vulnerabilities in login page on ███████ to U.S. Dept Of Defense - 1 upvotes, $0
- CRLF Injection on ███████ to U.S. Dept Of Defense - 1 upvotes, $0
- Sensitive Information Leaking Through DoD Owned Website. [██████████] to U.S. Dept Of Defense - 1 upvotes, $0
- █████ - Pre-generation of VIEWSTATE allows CAC bypass to U.S. Dept Of Defense - 1 upvotes, $0
- Firewall rules for ████████ can be bypassed to leak site authors to U.S. Dept Of Defense - 1 upvotes, $0
- [https://███] Local File Inclusion via graph.php to U.S. Dept Of Defense - 1 upvotes, $0
- Internal IP Address Disclosed to U.S. Dept Of Defense - 1 upvotes, $0
- Publicly accessible Grafana install allows pivoting to Prometheus datasource to U.S. Dept Of Defense - 1 upvotes, $0
- idor on upload profile functionality to U.S. Dept Of Defense - 1 upvotes, $0
- CORS Misconfiguration Leads to Exposing User Data to U.S. Dept Of Defense - 1 upvotes, $0
- Padding Oracle ms10-070 in the a DoD website (https://██████/) to U.S. Dept Of Defense - 1 upvotes, $0
- Sensitive Information Leaking Through DARPA Website. [█████████] to U.S. Dept Of Defense - 1 upvotes, $0
- SQL injection found in US Navy Website (http://███/) to U.S. Dept Of Defense - 0 upvotes, $0
- Two Error-Based SQLi in courses.aspx on ██████████ to U.S. Dept Of Defense - 0 upvotes, $0
- SQL Injection - https://███/█████████/MSI.portal to U.S. Dept Of Defense - 0 upvotes, $0
- Unencrypted __VIEWSTATE parameter in a DoD website to U.S. Dept Of Defense - 0 upvotes, $0
- Admin Login Credential Leak for DoD Gitlab EE instance to U.S. Dept Of Defense - 0 upvotes, $0
- [██████████] — Directory traversal via
/aerosol-bin/███████/display_directory_████_t.cgi
to U.S. Dept Of Defense - 0 upvotes, $0