We are getting close to releasing BugBountyHunter v2 which will introduce a brand new website, including member platforms, new features, challenges, guides, videos, and the long awaited zseano methodology v2. Right now, all of the content on this website is considered out-dated, however our members section continues to operate for members.
Stay tuned for updates coming soon!
| Report Title | Event ID | Severity | Vulnerability Type |
|---|---|---|---|
| Open URL Redirect on /drpanel/logout.php | FirstBlood v1 | Low | Open Redirect |
| Stored XSS on /drpanel/drapi/query.php?aptid=<ID> | FirstBlood v1 | High | Stored XSS |
| IDOR found on /api/ma.php | FirstBlood v1 | High | Insecure direct object reference |
| Can change email when modifying an appointment | FirstBlood v1 | High | Application/Business Logic |