In Jan ’14 I reported three Cross-site Scripting vulnerabilities to the Yahoo Bug Bounty Program. And I know, it is really really hard, but … again … no feedback or bounty :)
Screenshots:
XSS on ‘celebrity.yahoo.com‘
|
XSS on ‘movies.yahoo.com‘
|
XSS on ‘music.yahoo.com’
|
|
|
|
Continue reading "Yahoo Bug Bounty Program Vulnerability #4 #5 #6 Cross-site Scripting vulnerabilities"
Here are the my last advisory which I’ve reported in 2013 to the Yahoo Bug Bounty Program. And again…the same story for this report as for my others :-/
If you’re interested, you can read it here:
Screenshots:
Video:
Here is my advisory for the XSS on de-mg42.mail.yahoo.com:
Continue reading "Yahoo Bug Bounty Program Vulnerability #3 XSS on de-mg42.mail.yahoo.com"
In Nov ’13 I reported a Cross-site Scripting vulnerability to the Yahoo Bug Bounty Program. As for my other reports, I’ve got no response or feedback, so I wrote a message to them via email this time and so on … blah blah :)
To cut a long story short, for all my reports the communication with Yahoo was really bad and of course: No bounty!
It seems this XSS is fixed, so here is my advisory:
Continue reading "Yahoo Bug Bounty Program Vulnerability #1 XSS on ads.yahoo.com"