We are getting close to releasing BugBountyHunter v2 which will introduce a brand new website, including member platforms, new features, challenges, guides, videos, and the long awaited zseano methodology v2. Right now, all of the content on this website is considered out-dated, however our members section continues to operate for members.
Stay tuned for updates coming soon!
| Report Title | Event ID | Severity | Vulnerability Type |
|---|---|---|---|
| Stored XSS on | FirstBlood v1 | High | Stored XSS |
| POST Based Reflected XSS on Login | FirstBlood v1 | Medium | Reflective XSS |
| Reflected XSS via Javascript Scheme | FirstBlood v1 | Medium | Reflective XSS |
| Reflected XSS | FirstBlood v1 | Medium | Reflective XSS |
| Account Creation with same Username overrides the one made before. | FirstBlood v1 | High | Auth issues |
| IDOR to view Patient Information from a Lower Privileged User | FirstBlood v1 | CRITICAL | Application/Business Logic |
| IDOR in Search Patient Functionality Leads to PII Leakage | FirstBlood v1 | CRITICAL | Application/Business Logic |
| DOM XSS | FirstBlood v1 | Medium | Reflective XSS |