Skip to content

Latest commit

 

History

History
452 lines (448 loc) · 63.3 KB

TOPUSDEPTOFDEFENSE.md

File metadata and controls

452 lines (448 loc) · 63.3 KB

Back

Top reports from U.S. Dept Of Defense program at HackerOne:

  1. Stored Xss Vulnerability on ████████ to U.S. Dept Of Defense - 183 upvotes, $0
  2. Bypassing CORS Misconfiguration Leads to Sensitive Exposure to U.S. Dept Of Defense - 139 upvotes, $0
  3. Public instance of Jenkins on https://██████████/ with /script enabled to U.S. Dept Of Defense - 110 upvotes, $0
  4. Remote Code Execution in ██████ to U.S. Dept Of Defense - 91 upvotes, $0
  5. XXE in DoD website that may lead to RCE to U.S. Dept Of Defense - 87 upvotes, $0
  6. Remote Code Execution (RCE) in a DoD website to U.S. Dept Of Defense - 82 upvotes, $0
  7. [SQLI ]Time Bassed Injection at ██████████ via referer header to U.S. Dept Of Defense - 80 upvotes, $0
  8. SQL Injection on www.██████████ on countID parameter to U.S. Dept Of Defense - 78 upvotes, $0
  9. SQL Injection in ████ to U.S. Dept Of Defense - 71 upvotes, $0
  10. RCE on █████ via CVE-2017-10271 to U.S. Dept Of Defense - 68 upvotes, $0
  11. CVE-2020-3187 - Unauthenticated Arbitrary File Deletion to U.S. Dept Of Defense - 68 upvotes, $0
  12. [█████████] Administrative access to Oracle WebLogic Server using default credentials to U.S. Dept Of Defense - 61 upvotes, $0
  13. Remote Code Execution through DNN Cookie Deserialization to U.S. Dept Of Defense - 54 upvotes, $0
  14. Information disclousure by clicking on the link shown in http://████████/ to U.S. Dept Of Defense - 47 upvotes, $0
  15. SQL Injection in ████ to U.S. Dept Of Defense - 45 upvotes, $0
  16. Gateway information leakage to U.S. Dept Of Defense - 43 upvotes, $0
  17. SQL Injection vulnerability located at ████████ to U.S. Dept Of Defense - 42 upvotes, $0
  18. LFI with potential to RCE on ██████ using CVE-2019-3396 to U.S. Dept Of Defense - 42 upvotes, $0
  19. Leaked DB credentials on https://██████████.mil/███ to U.S. Dept Of Defense - 41 upvotes, $0
  20. Local File Inclusion vulnerability on an Army system allows downloading local files to U.S. Dept Of Defense - 39 upvotes, $0
  21. Account takeover through CSRF in http://███████/██████████/default.asp to U.S. Dept Of Defense - 39 upvotes, $0
  22. Remote Code Execution via Insecure Deserialization in Telerik UI to U.S. Dept Of Defense - 38 upvotes, $0
  23. Remote code execution on an Army website to U.S. Dept Of Defense - 31 upvotes, $0
  24. Pulse Secure File disclosure, clear text and potential RCE to U.S. Dept Of Defense - 31 upvotes, $0
  25. Unrestricted File Upload to U.S. Dept Of Defense - 30 upvotes, $0
  26. XXE on DoD web server to U.S. Dept Of Defense - 30 upvotes, $0
  27. [██████] Cross-origin resource sharing misconfiguration (CORS) to U.S. Dept Of Defense - 30 upvotes, $0
  28. Blind Stored XSS Payload fired at the backend on https://█████████/ to U.S. Dept Of Defense - 30 upvotes, $0
  29. Remote Code Execution (RCE) in a DoD website to U.S. Dept Of Defense - 29 upvotes, $0
  30. SOAP WSDL Parser SQL Code Execution to U.S. Dept Of Defense - 29 upvotes, $0
  31. SSRF+XSS to U.S. Dept Of Defense - 28 upvotes, $0
  32. Reflected Xss to U.S. Dept Of Defense - 28 upvotes, $0
  33. Information Disclosure to U.S. Dept Of Defense - 27 upvotes, $0
  34. SQL injection to U.S. Dept Of Defense - 27 upvotes, $0
  35. Trace.axd page leaks sensitive information to U.S. Dept Of Defense - 26 upvotes, $0
  36. SSRF vulnerability on ██████████ leaks internal IP and various sensitive information to U.S. Dept Of Defense - 25 upvotes, $0
  37. Command Injection (via CVE-2019-11510 and CVE-2019-11539) to U.S. Dept Of Defense - 24 upvotes, $0
  38. ████ - Complete account takeover to U.S. Dept Of Defense - 24 upvotes, $0
  39. SQL Injection in the move_papers.php on the https://██████████ to U.S. Dept Of Defense - 24 upvotes, $0
  40. Authentication bypass and RCE on the https://████ due to exposed Cisco TelePresence SX80 with default credentials to U.S. Dept Of Defense - 24 upvotes, $0
  41. CSRF Account Deletion on ███ Website to U.S. Dept Of Defense - 23 upvotes, $0
  42. 403 Forbidden Bypass at www.██████.mil to U.S. Dept Of Defense - 22 upvotes, $0
  43. RCE on a Department of Defense website to U.S. Dept Of Defense - 21 upvotes, $0
  44. SQL injection on the https://████/ to U.S. Dept Of Defense - 21 upvotes, $0
  45. [Partial] SSN & [PII] exposed through iPERMs Presentation Slide. to U.S. Dept Of Defense - 21 upvotes, $0
  46. Reflected XSS in https://www.██████/ to U.S. Dept Of Defense - 21 upvotes, $0
  47. █████████ IDOR leads to disclosure of PHI/PII to U.S. Dept Of Defense - 21 upvotes, $0
  48. Request smuggling on ████████ to U.S. Dept Of Defense - 20 upvotes, $0
  49. SSRF on █████████ Allowing internal server data access to U.S. Dept Of Defense - 20 upvotes, $0
  50. Video player on ███ allows arbitrary remote videos to be played to U.S. Dept Of Defense - 20 upvotes, $0
  51. CSRF - Close Account to U.S. Dept Of Defense - 20 upvotes, $0
  52. Reflected XSS in https://www.█████/ to U.S. Dept Of Defense - 20 upvotes, $0
  53. Full account takeover on https://████████.mil to U.S. Dept Of Defense - 20 upvotes, $0
  54. ███ exposes sensitive shipment information to public web to U.S. Dept Of Defense - 19 upvotes, $0
  55. Access to all █████████ files, including CAC authentication bypass to U.S. Dept Of Defense - 19 upvotes, $0
  56. Publicly accessible Order confirmations leaking User Emails on ███ to U.S. Dept Of Defense - 19 upvotes, $0
  57. Examples directory is PUBLIC on https://████████mil, leading to multiple vulns to U.S. Dept Of Defense - 19 upvotes, $0
  58. Arbitrary File Reading leads to RCE in the Pulse Secure SSL VPN on the https://███ to U.S. Dept Of Defense - 19 upvotes, $0
  59. Subdomain takeover due to an unclaimed Amazon S3 bucket on ███ to U.S. Dept Of Defense - 19 upvotes, $0
  60. [REMOTE] Full Account Takeover At https://██████████████/CAS/ to U.S. Dept Of Defense - 18 upvotes, $0
  61. Subdomain takeover of ████ to U.S. Dept Of Defense - 18 upvotes, $0
  62. https://██████ vulnerable to CVE-2020-3187 - Unauthenticated arbitrary file deletion in Cisco ASA/FTD to U.S. Dept Of Defense - 18 upvotes, $0
  63. Apache solr RCE via velocity template to U.S. Dept Of Defense - 18 upvotes, $0
  64. SQL injection vulnerability on a DoD website to U.S. Dept Of Defense - 17 upvotes, $0
  65. Remote code execution vulnerability on a DoD website to U.S. Dept Of Defense - 17 upvotes, $0
  66. Remote Code Execution (RCE) in DoD Websites to U.S. Dept Of Defense - 17 upvotes, $0
  67. Partial SSN exposed through Presentation slides on ██████████ to U.S. Dept Of Defense - 17 upvotes, $0
  68. Self XSS combine CSRF at https://████████/index.php to U.S. Dept Of Defense - 17 upvotes, $0
  69. Path traversal on https://███ allows arbitrary file read (CVE-2020-3452) to U.S. Dept Of Defense - 17 upvotes, $0
  70. Remote Code Execution on █████████ to U.S. Dept Of Defense - 17 upvotes, $0
  71. IDOR to Account Takeover on https://████/index.html to U.S. Dept Of Defense - 17 upvotes, $0
  72. [CVE-2018-7600] Remote Code Execution due to outdated Drupal server on www.█████████ to U.S. Dept Of Defense - 17 upvotes, $0
  73. CSRF to Cross-site Scripting (XSS) to U.S. Dept Of Defense - 17 upvotes, $0
  74. ███████ Site Exposes █████████ forms to U.S. Dept Of Defense - 16 upvotes, $0
  75. PII leakage due to scrceenshot of health records to U.S. Dept Of Defense - 16 upvotes, $0
  76. Reflected XSS on https://█████████/ to U.S. Dept Of Defense - 16 upvotes, $0
  77. Reflected XSS on ███ to U.S. Dept Of Defense - 16 upvotes, $0
  78. Misconfigured password reset vulnerability on a DoD website to U.S. Dept Of Defense - 15 upvotes, $0
  79. Blind SQLi vulnerability in a DoD Website to U.S. Dept Of Defense - 14 upvotes, $0
  80. Open FTP server on a DoD system to U.S. Dept Of Defense - 14 upvotes, $0
  81. PII leakage due to caching of Order/Contract ID's on █████████ to U.S. Dept Of Defense - 14 upvotes, $0
  82. Blind SQL injection on ████████ to U.S. Dept Of Defense - 14 upvotes, $0
  83. [█████] — DOM-based XSS on endpoint /?s= to U.S. Dept Of Defense - 14 upvotes, $0
  84. ███ is vulnerable to CVE-2020-3452 Read-Only Path Traversal Vulnerability to U.S. Dept Of Defense - 14 upvotes, $0
  85. Sensitive information about a ██████ to U.S. Dept Of Defense - 14 upvotes, $0
  86. Blind stored XSS due to insecure contact form at https://█████.mil leads to leakage of session token and to U.S. Dept Of Defense - 14 upvotes, $0
  87. critical information disclosure to U.S. Dept Of Defense - 14 upvotes, $0
  88. SQL injection vulnerability on a DoD website to U.S. Dept Of Defense - 13 upvotes, $0
  89. IDOR on DoD Website exposes FTP users and passes linked to all accounts! to U.S. Dept Of Defense - 13 upvotes, $0
  90. PII leakage-Full SSN on ███ to U.S. Dept Of Defense - 13 upvotes, $0
  91. XSS on www.██████ alerts and a number of other pages to U.S. Dept Of Defense - 13 upvotes, $0
  92. http://████/data.json showing users sensitive information via json file to U.S. Dept Of Defense - 13 upvotes, $0
  93. SSN leak due to editable slides to U.S. Dept Of Defense - 13 upvotes, $0
  94. Previously Compromised PulseSSL VPN Hosts to U.S. Dept Of Defense - 13 upvotes, $0
  95. Remote Code Execution via CVE-2019-18935 to U.S. Dept Of Defense - 13 upvotes, $0
  96. CSRF to Stored HTML injection at https://www.█████ to U.S. Dept Of Defense - 13 upvotes, $0
  97. DOM Based XSS on an Army website to U.S. Dept Of Defense - 12 upvotes, $0
  98. Remote Code Execution (RCE) in a DoD website to U.S. Dept Of Defense - 12 upvotes, $0
  99. [Critical] Full local fylesystem access (LFI/LFD) as admin via Path Traversal in the misconfigured Java servlet on the https://███/ to U.S. Dept Of Defense - 12 upvotes, $0
  100. SQL injections to U.S. Dept Of Defense - 12 upvotes, $0
  101. Remote Code Execution - Unauthenticated Remote Command Injection (via Microsoft SharePoint CVE-2019-0604) to U.S. Dept Of Defense - 12 upvotes, $0
  102. Reflected cross-site scripting vulnerability on a DoD website to U.S. Dept Of Defense - 12 upvotes, $0
  103. No Rate Limiting on https://██████/██████████/accounts/password/reset/ endpoint leads to Denial of Service to U.S. Dept Of Defense - 12 upvotes, $0
  104. Exposed Docker Registry at https://████ to U.S. Dept Of Defense - 12 upvotes, $0
  105. CSRF to account takeover in https://███████.mil/ to U.S. Dept Of Defense - 12 upvotes, $0
  106. XSS Reflect to POST █████ to U.S. Dept Of Defense - 12 upvotes, $0
  107. [SQLI ]Time Bassed Injection at ██████████ via /██████/library.php?c=G14 parameter to U.S. Dept Of Defense - 12 upvotes, $0
  108. Old Session Does Not Expires After Password Change to U.S. Dept Of Defense - 12 upvotes, $0
  109. Unauth RCE on Jenkins Instance at https://█████████/ to U.S. Dept Of Defense - 12 upvotes, $0
  110. Unrestricted File Download / Path Traversal to U.S. Dept Of Defense - 11 upvotes, $0
  111. Reflected cross-site scripting vulnerability on a DoD website to U.S. Dept Of Defense - 11 upvotes, $0
  112. SQL Injection in Login Page: https://█████/█████████/login.php to U.S. Dept Of Defense - 11 upvotes, $0
  113. PII/PHI data available on web https://████████Portals/22/Documents/Meetings to U.S. Dept Of Defense - 11 upvotes, $0
  114. Unrestricted File Upload Leads to XSS & Potential RCE to U.S. Dept Of Defense - 11 upvotes, $0
  115. Elmah.axd is publicly accessible and leaking Error Log for ROOT on █████_PRD_WEB1 █████████elmah.axd to U.S. Dept Of Defense - 11 upvotes, $0
  116. Local File Disclosure on the ████████ (https://████/) leads to the source code disclosure & DB credentials leak to U.S. Dept Of Defense - 11 upvotes, $0
  117. Password Reset link hijacking via Host Header Poisoning leads to account takeover to U.S. Dept Of Defense - 11 upvotes, $0
  118. Local file inclusion vulnerability on a DoD website to U.S. Dept Of Defense - 10 upvotes, $0
  119. Remote Code Execution (RCE) in a DoD website to U.S. Dept Of Defense - 10 upvotes, $0
  120. SQL Injection vulnerability in a DoD website to U.S. Dept Of Defense - 10 upvotes, $0
  121. RCE on https://█████/ Using CVE-2017-9248 to U.S. Dept Of Defense - 10 upvotes, $0
  122. MSSQL injection via param Customwho in https://█████/News/Transcripts/Search/Sort/ and WAF bypass to U.S. Dept Of Defense - 10 upvotes, $0
  123. Unauthenticated Arbitrary File Deletion ("CVE-2020-3187") in ████████ to U.S. Dept Of Defense - 10 upvotes, $0
  124. IDOR + Account Takeover [UNAUTHENTICATED] to U.S. Dept Of Defense - 10 upvotes, $0
  125. CORS misconfiguration which leads to the disclosure to U.S. Dept Of Defense - 10 upvotes, $0
  126. Reflected XSS on https://████/ (Bypass of #1002977) to U.S. Dept Of Defense - 10 upvotes, $0
  127. PII Leak of USCG Designated Examiner List at https://www.███ to U.S. Dept Of Defense - 10 upvotes, $0
  128. Sensitive Information Leaking Through DoD Owned Website https://www.█████.mil to U.S. Dept Of Defense - 10 upvotes, $0
  129. critical information disclosure to U.S. Dept Of Defense - 10 upvotes, $0
  130. Privilege Escalation on a DoD Website to U.S. Dept Of Defense - 9 upvotes, $0
  131. Authentication bypass vulnerability on a DoD website to U.S. Dept Of Defense - 9 upvotes, $0
  132. Reflected XSS on a DoD website to U.S. Dept Of Defense - 9 upvotes, $0
  133. Personal information disclosure on a DoD website to U.S. Dept Of Defense - 9 upvotes, $0
  134. Blind SQLi in a DoD Website to U.S. Dept Of Defense - 9 upvotes, $0
  135. Time Based SQL Injection vulnerability on a DoD website to U.S. Dept Of Defense - 9 upvotes, $0
  136. Path traversal on ████████ to U.S. Dept Of Defense - 9 upvotes, $0
  137. SQL injection on █████ due to tech.cfm to U.S. Dept Of Defense - 9 upvotes, $0
  138. [CVE-2019-11510 ] Path Traversal on ████████ leads to leaked passwords, RCE, etc to U.S. Dept Of Defense - 9 upvotes, $0
  139. Unrestricted File Upload to ███████SubmitRequest/Index.cfm?fwa=wizardform to U.S. Dept Of Defense - 9 upvotes, $0
  140. CSRF - Modify Company Info to U.S. Dept Of Defense - 9 upvotes, $0
  141. SSN is exposed on slides, previous critical report was not fixed in an appropriate way to U.S. Dept Of Defense - 9 upvotes, $0
  142. Reflected XSS on ███████ to U.S. Dept Of Defense - 9 upvotes, $0
  143. Local File Inclusion In Registration Page to U.S. Dept Of Defense - 9 upvotes, $0
  144. Reflected XSS In https://███████ to U.S. Dept Of Defense - 9 upvotes, $0
  145. Blind Stored XSS on ███████ leads to takeover admin account to U.S. Dept Of Defense - 9 upvotes, $0
  146. Reflected XSS at https://████████/███/... to U.S. Dept Of Defense - 9 upvotes, $0
  147. Reflected XSS in a Navy website to U.S. Dept Of Defense - 8 upvotes, $0
  148. Reflected XSS on an Army website to U.S. Dept Of Defense - 8 upvotes, $0
  149. Reflected XSS on a Department of Defense website to U.S. Dept Of Defense - 8 upvotes, $0
  150. Reflected XSS on a Department of Defense website to U.S. Dept Of Defense - 8 upvotes, $0
  151. File upload vulnerability on a DoD website to U.S. Dept Of Defense - 8 upvotes, $0
  152. Remote code execution (RCE) in multiple DoD websites to U.S. Dept Of Defense - 8 upvotes, $0
  153. Cross-site scripting (XSS) vulnerability on a DoD website to U.S. Dept Of Defense - 8 upvotes, $0
  154. [Critical] Possibility to takeover any user account #2 without interaction on the https://██████████ to U.S. Dept Of Defense - 8 upvotes, $0
  155. Remote Code Execution (RCE) in a DoD website to U.S. Dept Of Defense - 8 upvotes, $0
  156. Server-Side Request Forgery (SSRF) to U.S. Dept Of Defense - 8 upvotes, $0
  157. PII Leak via https://████████ to U.S. Dept Of Defense - 8 upvotes, $0
  158. (CORS) Cross-origin resource sharing misconfiguration to U.S. Dept Of Defense - 8 upvotes, $0
  159. RCE (Remote code execution) in one of DoD's websites to U.S. Dept Of Defense - 8 upvotes, $0
  160. Сode injection host █████████ to U.S. Dept Of Defense - 8 upvotes, $0
  161. SQLi in login form of █████ to U.S. Dept Of Defense - 8 upvotes, $0
  162. DOM XSS on https://www.███████ to U.S. Dept Of Defense - 8 upvotes, $0
  163. Unauthenticated Arbitrary File Deletion "CVE-2020-3187" in █████ to U.S. Dept Of Defense - 8 upvotes, $0
  164. PII Information Leak at https://████████.mil/ to U.S. Dept Of Defense - 8 upvotes, $0
  165. Reflected XSS www.█████ search form to U.S. Dept Of Defense - 8 upvotes, $0
  166. PII Leak via /████████ to U.S. Dept Of Defense - 8 upvotes, $0
  167. Git repo on https://██████.mil/ discloses API password to U.S. Dept Of Defense - 8 upvotes, $0
  168. RCE in ██████ subdomain via CVE-2017-1000486 to U.S. Dept Of Defense - 8 upvotes, $0
  169. Reflected XSS on a Navy website to U.S. Dept Of Defense - 7 upvotes, $0
  170. QuickTime Promotion on a DoD website to U.S. Dept Of Defense - 7 upvotes, $0
  171. Exposed Access Control Data Backup Files on DoD Website to U.S. Dept Of Defense - 7 upvotes, $0
  172. Reflected XSS vulnerability on a DoD website to U.S. Dept Of Defense - 7 upvotes, $0
  173. Information disclosure on a DoD website to U.S. Dept Of Defense - 7 upvotes, $0
  174. Remote Command Execution on a DoD website to U.S. Dept Of Defense - 7 upvotes, $0
  175. Bypass file access control vulnerability on a DoD website to U.S. Dept Of Defense - 7 upvotes, $0
  176. XSS on a DoD website to U.S. Dept Of Defense - 7 upvotes, $0
  177. SQL injection vulnerability on a DoD website to U.S. Dept Of Defense - 7 upvotes, $0
  178. Insecure direct object reference vulnerability on a DoD website to U.S. Dept Of Defense - 7 upvotes, $0
  179. Information disclosure vulnerability on a DoD website to U.S. Dept Of Defense - 7 upvotes, $0
  180. Server-side include injection vulnerability in a DoD website to U.S. Dept Of Defense - 7 upvotes, $0
  181. Information disclosure on a DoD website to U.S. Dept Of Defense - 7 upvotes, $0
  182. Arbitary file download vulnerability on a DoD website to U.S. Dept Of Defense - 7 upvotes, $0
  183. Insecure Direct Object Reference (IDOR) vulnerability in a DoD website to U.S. Dept Of Defense - 7 upvotes, $0
  184. X-XSS-Protection -> Misconfiguration to U.S. Dept Of Defense - 7 upvotes, $0
  185. Root Remote Code Execution on https://███ to U.S. Dept Of Defense - 7 upvotes, $0
  186. Exposed ███████ Administrative Interface (ColdFusion 11) to U.S. Dept Of Defense - 7 upvotes, $0
  187. Corda Server XSS ████████ to U.S. Dept Of Defense - 7 upvotes, $0
  188. Unrestricted File Upload to U.S. Dept Of Defense - 7 upvotes, $0
  189. Null byte Injection in https://████/ to U.S. Dept Of Defense - 7 upvotes, $0
  190. Tomcat examples available for public, Disclosure Apache Tomcat version, Critical/High/Medium CVE to U.S. Dept Of Defense - 7 upvotes, $0
  191. SharePoint Web Services Exposed to Anonymous Access Users to U.S. Dept Of Defense - 7 upvotes, $0
  192. Stored XSS via Comment Form at ████████ to U.S. Dept Of Defense - 7 upvotes, $0
  193. {███} It is posible download all information and files via S3 Bucket Misconfiguration to U.S. Dept Of Defense - 7 upvotes, $0
  194. SQL Injection in www.██████████ to U.S. Dept Of Defense - 7 upvotes, $0
  195. Reflected XSS on https://█████████html?url to U.S. Dept Of Defense - 7 upvotes, $0
  196. Password Cracking - Weak Password Used to Secure ████ Containing a Plaintext Password to U.S. Dept Of Defense - 7 upvotes, $0
  197. IDOR leads to Leakage an ██████████ Login Information to U.S. Dept Of Defense - 7 upvotes, $0
  198. CSRF to Cross-site Scripting (XSS) to U.S. Dept Of Defense - 7 upvotes, $0
  199. Improper Access Control - Generic on https://████ to U.S. Dept Of Defense - 7 upvotes, $0
  200. IDOR on https://██████ via POST UID enables database scraping to U.S. Dept Of Defense - 7 upvotes, $0
  201. SQL Injection vulnerability on a DoD website to U.S. Dept Of Defense - 6 upvotes, $0
  202. Information leakage on a Department of Defense website to U.S. Dept Of Defense - 6 upvotes, $0
  203. Cross-site scripting (XSS) vulnerability on a DoD website to U.S. Dept Of Defense - 6 upvotes, $0
  204. Remote file inclusion vulnerability on a DoD website to U.S. Dept Of Defense - 6 upvotes, $0
  205. HTML injection vulnerability on a DoD website to U.S. Dept Of Defense - 6 upvotes, $0
  206. Reflected XSS on a DoD website to U.S. Dept Of Defense - 6 upvotes, $0
  207. Reflected XSS in a DoD Website to U.S. Dept Of Defense - 6 upvotes, $0
  208. SQL injection vulnerability on a DoD website to U.S. Dept Of Defense - 6 upvotes, $0
  209. Remote code execution vulnerability on a DoD website to U.S. Dept Of Defense - 6 upvotes, $0
  210. Arbitary file download vulnerability on a DoD website to U.S. Dept Of Defense - 6 upvotes, $0
  211. Arbitary file download vulnerability on a DoD website to U.S. Dept Of Defense - 6 upvotes, $0
  212. Violation of secure design principles on a DoD website to U.S. Dept Of Defense - 6 upvotes, $0
  213. Limited code execution vulnerability on a DoD website to U.S. Dept Of Defense - 6 upvotes, $0
  214. Information disclosure vulnerability on a DoD website to U.S. Dept Of Defense - 6 upvotes, $0
  215. Remote Code Execution (RCE) vulnerability in a DoD website to U.S. Dept Of Defense - 6 upvotes, $0
  216. Account takeover due to CSRF in "Account details" option on █████████ to U.S. Dept Of Defense - 6 upvotes, $0
  217. ██████ Authenticated User Data Disclosure to U.S. Dept Of Defense - 6 upvotes, $0
  218. SSRF on ████████ to U.S. Dept Of Defense - 6 upvotes, $0
  219. Information Disclosure (can access all ███s) within ███████ view █████████ Portal to U.S. Dept Of Defense - 6 upvotes, $0
  220. Out-of-date Version (Apache) to U.S. Dept Of Defense - 6 upvotes, $0
  221. Open FTP on ███ to U.S. Dept Of Defense - 6 upvotes, $0
  222. SSRF in ███████ to U.S. Dept Of Defense - 6 upvotes, $0
  223. Default page exposes admin functions and all metods and classes available. on https://██████/█████/dwr/index.html to U.S. Dept Of Defense - 6 upvotes, $0
  224. Admin Salt Leakage on DoD site. to U.S. Dept Of Defense - 6 upvotes, $0
  225. LDAP Injection at ██████ to U.S. Dept Of Defense - 6 upvotes, $0
  226. Partial PII leakage due to public set gitlab to U.S. Dept Of Defense - 6 upvotes, $0
  227. [███] SQL injection & Reflected XSS to U.S. Dept Of Defense - 6 upvotes, $0
  228. [█████] Get all tickets (IDOR) to U.S. Dept Of Defense - 6 upvotes, $0
  229. ██████████ bruteforceable RIC Codes allowing information on contracts to U.S. Dept Of Defense - 6 upvotes, $0
  230. [████████] Boolean SQL Injection (/personnel.php?content=profile&rcnum=*) to U.S. Dept Of Defense - 6 upvotes, $0
  231. [█████] Reflected GET XSS (/personnel.php?...&rcnum=*) with mouse action to U.S. Dept Of Defense - 6 upvotes, $0
  232. Full Account Take-Over of ████████ Members via IDOR to U.S. Dept Of Defense - 6 upvotes, $0
  233. xmlrpc.php FILE IS enable which enables attacker to XSPA Brute-force and even Denial of Service(DOS), in https://████/xmlrpc.php to U.S. Dept Of Defense - 6 upvotes, $0
  234. Stored XSS at ██████userprofile.aspx to U.S. Dept Of Defense - 6 upvotes, $0
  235. CSRF to account takeover in https://█████/ to U.S. Dept Of Defense - 6 upvotes, $0
  236. ███████mill is vulnerable to cross site request forgery that leads to full account take over. to U.S. Dept Of Defense - 6 upvotes, $0
  237. Stored XSS at https://www.█████████.mil to U.S. Dept Of Defense - 6 upvotes, $0
  238. Stored XSS via 64(?) vulnerable fields in ███ leads to credential theft/account takeover to U.S. Dept Of Defense - 6 upvotes, $0
  239. Bypassed a fix to gain access to PII of more than 100 Officers to U.S. Dept Of Defense - 6 upvotes, $0
  240. CVE 2020 14179 on jira instance to U.S. Dept Of Defense - 6 upvotes, $0
  241. Second Order XSS via █████ to U.S. Dept Of Defense - 6 upvotes, $0
  242. SSRF due to CVE-2021-26855 on ████████ to U.S. Dept Of Defense - 6 upvotes, $0
  243. Reflected XSS on ███████ to U.S. Dept Of Defense - 6 upvotes, $0
  244. Website vulnerable to POODLE (SSLv3) with expired certificate to U.S. Dept Of Defense - 6 upvotes, $0
  245. XSS vulnerability on an Army website to U.S. Dept Of Defense - 5 upvotes, $0
  246. Open Redirect in a DoD website to U.S. Dept Of Defense - 5 upvotes, $0
  247. Cross-site request forgery vulnerability on a DoD website to U.S. Dept Of Defense - 5 upvotes, $0
  248. Password reset vulnerability on a DoD website to U.S. Dept Of Defense - 5 upvotes, $0
  249. Remote command execution (RCE) vulnerability on a DoD website to U.S. Dept Of Defense - 5 upvotes, $0
  250. Information disclosure vulnerability on a DoD website to U.S. Dept Of Defense - 5 upvotes, $0
  251. Information disclosure vulnerability on a DoD website to U.S. Dept Of Defense - 5 upvotes, $0
  252. Information disclosure vulnerability on a DoD website to U.S. Dept Of Defense - 5 upvotes, $0
  253. Information disclosure vulnerability on a DoD website to U.S. Dept Of Defense - 5 upvotes, $0
  254. Open redirect vulnerability in a DoD website to U.S. Dept Of Defense - 5 upvotes, $0
  255. Reflected cross-site scripting (XSS) vulnerability on a DoD website to U.S. Dept Of Defense - 5 upvotes, $0
  256. Default credentials on a DoD website to U.S. Dept Of Defense - 5 upvotes, $0
  257. SQL Injection vulnerability in a DoD website to U.S. Dept Of Defense - 5 upvotes, $0
  258. Server Side Request Forgery (SSRF) vulnerability in a DoD website to U.S. Dept Of Defense - 5 upvotes, $0
  259. Information disclosure vulnerability on a DoD website to U.S. Dept Of Defense - 5 upvotes, $0
  260. https://█████████ Vulnerable to CVE-2018-0296 Cisco ASA Path Traversal Authentication Bypass to U.S. Dept Of Defense - 5 upvotes, $0
  261. SQL Injection in the get_publications.php on the https://█████ to U.S. Dept Of Defense - 5 upvotes, $0
  262. sql injection on /messagecenter/messagingcenter at https://www.███████/ to U.S. Dept Of Defense - 5 upvotes, $0
  263. Remote Code Execution (RCE) in a DoD website to U.S. Dept Of Defense - 5 upvotes, $0
  264. Remote File Inclusion, Malicious File Hosting, and Cross-site Scripting (XSS) in ████████ to U.S. Dept Of Defense - 5 upvotes, $0
  265. HTML Injection on ████ to U.S. Dept Of Defense - 5 upvotes, $0
  266. SharePoint exposed web services to U.S. Dept Of Defense - 5 upvotes, $0
  267. Email PII disclosure due to Insecure Password Reset field to U.S. Dept Of Defense - 5 upvotes, $0
  268. File Upload Restriction Bypass to U.S. Dept Of Defense - 5 upvotes, $0
  269. [Critical] Insufficient Access Control On Registration Page of Webapps Website Allows Privilege Escalation to Administrator to U.S. Dept Of Defense - 5 upvotes, $0
  270. Reflected XSS and HTML Injectionon a DoD website to U.S. Dept Of Defense - 5 upvotes, $0
  271. Directory Indexing on the ████ (https://████/) leads to the backups disclosure and credentials leak to U.S. Dept Of Defense - 5 upvotes, $0
  272. Improper Access Controls Allow PII Leak via ████ to U.S. Dept Of Defense - 5 upvotes, $0
  273. Knowledge Base Articles are Globally Modifiable via ██████ to U.S. Dept Of Defense - 5 upvotes, $0
  274. Support incident can be opened for any user via /███████ and PII leak via █████████ field to U.S. Dept Of Defense - 5 upvotes, $0
  275. Arbitrary file upload and stored XSS via ███ support request to U.S. Dept Of Defense - 5 upvotes, $0
  276. Access to requests and approvals via /█████ allows sensitive information gathering to U.S. Dept Of Defense - 5 upvotes, $0
  277. CRXDE Lite/CRX is on ██████ exposed that leads to PII disclosure to U.S. Dept Of Defense - 5 upvotes, $0
  278. RXSS - https://███/ to U.S. Dept Of Defense - 5 upvotes, $0
  279. Blind Stored XSS on https://█████████ after filling a request at https://█████ to U.S. Dept Of Defense - 5 upvotes, $0
  280. param allows any external resource to be downloadable | https://████████ to U.S. Dept Of Defense - 5 upvotes, $0
  281. External Service Interaction (HTTP/DNS) on https://www.███ (██████████ parameter) to U.S. Dept Of Defense - 5 upvotes, $0
  282. Reflected XSS on █████████ to U.S. Dept Of Defense - 5 upvotes, $0
  283. Sending trusted ████ and ██████████ emails through public API endpoint in ███████ site to U.S. Dept Of Defense - 5 upvotes, $0
  284. Persistent XSS vulnerability on a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
  285. Cross-site scripting vulnerability on a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
  286. Cross-site scripting (XSS) vulnerability on a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
  287. HTML Injection/Load Images vulnerability on a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
  288. SQL injection vulnerability on a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
  289. Reflected XSS on a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
  290. Reflected XSS on a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
  291. Remote Code Execution (RCE) in a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
  292. Reflected XSS on a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
  293. Reflected XSS vulnerability on a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
  294. Information disclosure vulnerability on a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
  295. Cross-site request forgery (CSRF) vulnerability in a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
  296. Reflected XSS vulnerability on a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
  297. Information disclosure vulnerability in a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
  298. SQL Injection vulnerability in a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
  299. SQL Injection vulnerability in a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
  300. SQL injection vulnerability in a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
  301. Reflective XSS vulnerability on a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
  302. Information disclosure vulnerability on a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
  303. SQL injection vulnerability on a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
  304. Remote Code Execution (RCE) vulnerability in multiple DoD websites to U.S. Dept Of Defense - 4 upvotes, $0
  305. Cross-site scripting (XSS) vulnerability on a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
  306. Information disclosure vulnerability on a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
  307. Cross-site scripting (XSS) on a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
  308. SQL Injection vulnerability in a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
  309. Admin panel take over | User info leakage | Mass Comprimise to U.S. Dept Of Defense - 4 upvotes, $0
  310. Code reversion allowing SQLI again in ███████ to U.S. Dept Of Defense - 4 upvotes, $0
  311. Remote Code Execution (RCE) in a DoD website to U.S. Dept Of Defense - 4 upvotes, $0
  312. WebLogic Server Side Request Forgery to U.S. Dept Of Defense - 4 upvotes, $0
  313. SharePoint exposed web services to U.S. Dept Of Defense - 4 upvotes, $0
  314. [████████] Reflected XSS to U.S. Dept Of Defense - 4 upvotes, $0
  315. [███████] Reflected GET XSS (/mission.php?...&missionDate=*) to U.S. Dept Of Defense - 4 upvotes, $0
  316. [██████████] Unauthorized access to admin panel to U.S. Dept Of Defense - 4 upvotes, $0
  317. Application level DoS via xmlrpc.php to U.S. Dept Of Defense - 4 upvotes, $0
  318. Unrestricted file upload leads to stored xss on https://████████/ to U.S. Dept Of Defense - 4 upvotes, $0
  319. CVE-2020-3452, unauthenticated file read in Cisco ASA & Cisco Firepower. to U.S. Dept Of Defense - 4 upvotes, $0
  320. Cross Site Scripting (XSS) – Reflected to U.S. Dept Of Defense - 4 upvotes, $0
  321. External Service Interaction | https://█████████.mil to U.S. Dept Of Defense - 4 upvotes, $0
  322. https://██████ vulnerable to CVE-2020-3187 - Unauthenticated arbitrary file deletion in Cisco ASA/FTD to U.S. Dept Of Defense - 4 upvotes, $0
  323. hardcoded password stored in javascript of https://████.mil to U.S. Dept Of Defense - 4 upvotes, $0
  324. View another user information with IDOR vulnerability to U.S. Dept Of Defense - 4 upvotes, $0
  325. PHP info page disclosure to U.S. Dept Of Defense - 4 upvotes, $0
  326. Insecure ███████ credentials on staging app at ████ leads to application takeover to U.S. Dept Of Defense - 4 upvotes, $0
  327. PII Leak of ████████ Personal at https://www.█████████ to U.S. Dept Of Defense - 4 upvotes, $0
  328. Dashboard sharing enables code injection into ████ emails to U.S. Dept Of Defense - 4 upvotes, $0
  329. PII Leak via /███████ to U.S. Dept Of Defense - 4 upvotes, $0
  330. PII Leak via /██████ to U.S. Dept Of Defense - 4 upvotes, $0
  331. HTML Injection + XSS Vulnerability - https://████████/ | Proof of Concept [PoC] to U.S. Dept Of Defense - 4 upvotes, $0
  332. Information Disclosure(PHPINFO/Credentials) on DoD Asset to U.S. Dept Of Defense - 4 upvotes, $0
  333. Stored XSS through name / last name on https://██████████/ to U.S. Dept Of Defense - 4 upvotes, $0
  334. reflected xss @ www.█████████ to U.S. Dept Of Defense - 4 upvotes, $0
  335. CVE-2021-26855 on ████████ resulting in SSRF to U.S. Dept Of Defense - 4 upvotes, $0
  336. Read-only path traversal (CVE-2020-3452) at https://██████.mil to U.S. Dept Of Defense - 4 upvotes, $0
  337. XML Injection on https://www.█████████ (███ parameter) to U.S. Dept Of Defense - 4 upvotes, $0
  338. DNS Misconfiguration to U.S. Dept Of Defense - 3 upvotes, $0
  339. XSS vulnerability on a DoD website to U.S. Dept Of Defense - 3 upvotes, $0
  340. Arbitrary Script Injection (Mail) in a DoD Website to U.S. Dept Of Defense - 3 upvotes, $0
  341. Potentially sensitive information disclosure on a DoD website to U.S. Dept Of Defense - 3 upvotes, $0
  342. Misconfigured user account settings on DoD website to U.S. Dept Of Defense - 3 upvotes, $0
  343. Stored cross-site scripting (XSS) on a DoD website to U.S. Dept Of Defense - 3 upvotes, $0
  344. Cross-Site Scripting (XSS) on a DoD website to U.S. Dept Of Defense - 3 upvotes, $0
  345. Information disclosure vulnerability on a DoD website to U.S. Dept Of Defense - 3 upvotes, $0
  346. Remote Code Execution (RCE) in a DoD website to U.S. Dept Of Defense - 3 upvotes, $0
  347. Server side information disclosure on a DoD website to U.S. Dept Of Defense - 3 upvotes, $0
  348. Reflected XSS on a DoD website to U.S. Dept Of Defense - 3 upvotes, $0
  349. Reflected XSS on a DoD website to U.S. Dept Of Defense - 3 upvotes, $0
  350. Reflected XSS on a DoD website to U.S. Dept Of Defense - 3 upvotes, $0
  351. DOM Based XSS on a DoD website to U.S. Dept Of Defense - 3 upvotes, $0
  352. Time Based SQL Injection vulnerability on a DoD website to U.S. Dept Of Defense - 3 upvotes, $0
  353. Reflected XSS vulnerability on a DoD website to U.S. Dept Of Defense - 3 upvotes, $0
  354. Cross-site request forgery (CSRF) vulnerability on a DoD website to U.S. Dept Of Defense - 3 upvotes, $0
  355. Information disclosure vulnerability on a DoD website to U.S. Dept Of Defense - 3 upvotes, $0
  356. Remote code execution vulnerability on a DoD website to U.S. Dept Of Defense - 3 upvotes, $0
  357. Stored cross site scripting (XSS) vulnerability on a DoD website to U.S. Dept Of Defense - 3 upvotes, $0
  358. Reflected XSS vulnerability on a DoD website to U.S. Dept Of Defense - 3 upvotes, $0
  359. Reflected XSS on a DoD website to U.S. Dept Of Defense - 3 upvotes, $0
  360. Remote OS command Execution in the 3 more Oracle Weblogic on the ████████, ████, ███████ [CVE-2017-10352] to U.S. Dept Of Defense - 3 upvotes, $0
  361. Online training material disclosing username and password to U.S. Dept Of Defense - 3 upvotes, $0
  362. https://████████ Impacted by DNN ImageHandler SSRF to U.S. Dept Of Defense - 3 upvotes, $0
  363. ████████ SQL to U.S. Dept Of Defense - 3 upvotes, $0
  364. Attackers can control which security questions they are presented (████████) to U.S. Dept Of Defense - 3 upvotes, $0
  365. Insecure Direct Object Reference on in-scope .mil website to U.S. Dept Of Defense - 3 upvotes, $0
  366. Sensitive Email disclosure Due to Insecure Reactivate Account field to U.S. Dept Of Defense - 3 upvotes, $0
  367. CRLF Injection on ███████ to U.S. Dept Of Defense - 3 upvotes, $0
  368. Able to view Backend Database dur to improper authentication to U.S. Dept Of Defense - 3 upvotes, $0
  369. █████ - DOM-based XSS to U.S. Dept Of Defense - 3 upvotes, $0
  370. █████ - DOM-based XSS to U.S. Dept Of Defense - 3 upvotes, $0
  371. [██████] Reflected GET XSS (/personnel.php?..&folder=*) with mouse action to U.S. Dept Of Defense - 3 upvotes, $0
  372. ████ █████ exposes highly sensitive information to public to U.S. Dept Of Defense - 3 upvotes, $0
  373. █████████ - Insecure download cookie generation allows bypass of CAC authentication, access to deleted and locked files to U.S. Dept Of Defense - 3 upvotes, $0
  374. Firewall rules for ████████ can be bypassed to leak site authors to U.S. Dept Of Defense - 3 upvotes, $0
  375. Internal IP Address Disclosed to U.S. Dept Of Defense - 3 upvotes, $0
  376. idor on upload profile functionality to U.S. Dept Of Defense - 3 upvotes, $0
  377. Improper Neutralization of Input During Web Page Generation to U.S. Dept Of Defense - 3 upvotes, $0
  378. No ACL on S3 Bucket in [https://www.██████████/] to U.S. Dept Of Defense - 3 upvotes, $0
  379. Domian Takeover in [███████] to U.S. Dept Of Defense - 3 upvotes, $0
  380. [████████] — XSS on /███████_flight/images via advanced_val parameter to U.S. Dept Of Defense - 3 upvotes, $0
  381. XSS Reflected to U.S. Dept Of Defense - 3 upvotes, $0
  382. Reflected XSS on ███████ page to U.S. Dept Of Defense - 3 upvotes, $0
  383. [██████████.mil] Cisco VPN Service Path Traversal to U.S. Dept Of Defense - 3 upvotes, $0
  384. [CVE-2020-3452] Unauthenticated file read in Cisco ASA to U.S. Dept Of Defense - 3 upvotes, $0
  385. Reflected XSS in https://███████ via search parameter to U.S. Dept Of Defense - 3 upvotes, $0
  386. PII Leak (such as CAC User ID) at https://████████/pages/login.aspx to U.S. Dept Of Defense - 3 upvotes, $0
  387. Apparent ██████████ website is publicly exposed, suggests default account details on page and has expired SSL/TLS cert to U.S. Dept Of Defense - 3 upvotes, $0
  388. Able to authenticate as administrator by navigating to https://█████/admin/ to U.S. Dept Of Defense - 3 upvotes, $0
  389. Able to log in with default ██████g creds at https█████████████████████.mil to U.S. Dept Of Defense - 3 upvotes, $0
  390. POST based RXSS on https://█████ via frm_email parameter to U.S. Dept Of Defense - 3 upvotes, $0
  391. Sensitive data exposure via https://███/secure/QueryComponent!Default.jspa - CVE-2020-14179 to U.S. Dept Of Defense - 3 upvotes, $0
  392. System Error Reveals Sensitive SQL Call Data to U.S. Dept Of Defense - 3 upvotes, $0
  393. Self XSS + CSRF Leads to Reflected XSS in https://████/ to U.S. Dept Of Defense - 3 upvotes, $0
  394. Misconfigured AWS S3 bucket leaks senstive data such of admin, Prdouction,beta, localhost and many more directories.... to U.S. Dept Of Defense - 3 upvotes, $0
  395. Reflected XSS in https://██████████ via "████████" parameter to U.S. Dept Of Defense - 3 upvotes, $0
  396. Server side information disclosure to U.S. Dept Of Defense - 2 upvotes, $0
  397. Information disclosure on a DoD website to U.S. Dept Of Defense - 2 upvotes, $0
  398. Reflected XSS vulnerability in a DoD website to U.S. Dept Of Defense - 2 upvotes, $0
  399. Stored XSS vulnerability on a DoD website to U.S. Dept Of Defense - 2 upvotes, $0
  400. Reflected XSS on a DoD website to U.S. Dept Of Defense - 2 upvotes, $0
  401. Information disclosure vulnerability on a DoD website to U.S. Dept Of Defense - 2 upvotes, $0
  402. SQL Injection vulnerability in a DoD website to U.S. Dept Of Defense - 2 upvotes, $0
  403. SQL Injection vulnerability in a DoD website to U.S. Dept Of Defense - 2 upvotes, $0
  404. 2 vulnerabilities of arbitrary code in ████████ - CVE-2017-5929 to U.S. Dept Of Defense - 2 upvotes, $0
  405. Critical information disclosure at https://█████████ to U.S. Dept Of Defense - 2 upvotes, $0
  406. Illegal account registration in ████████ to U.S. Dept Of Defense - 2 upvotes, $0
  407. Multiple cryptographic vulnerabilities in login page on ███████ to U.S. Dept Of Defense - 2 upvotes, $0
  408. Exposed FTP Credentials on ███████ to U.S. Dept Of Defense - 2 upvotes, $0
  409. Blind SQL Injection on DoD Site to U.S. Dept Of Defense - 2 upvotes, $0
  410. Sensitive Information Leaking Through DoD Owned Website. [██████████] to U.S. Dept Of Defense - 2 upvotes, $0
  411. Followup - SQL Injection - https://██████████/██████/MSI.portal to U.S. Dept Of Defense - 2 upvotes, $0
  412. CORS Misconfiguration Leads to Exposing User Data to U.S. Dept Of Defense - 2 upvotes, $0
  413. Padding Oracle ms10-070 in the a DoD website (https://██████/) to U.S. Dept Of Defense - 2 upvotes, $0
  414. Admin Login Credential Leak for DoD Gitlab EE instance to U.S. Dept Of Defense - 2 upvotes, $0
  415. Username&password is Disclosure in readme file in [https://█████████] to U.S. Dept Of Defense - 2 upvotes, $0
  416. Sensitive Information Leaking Through DARPA Website. [█████████] to U.S. Dept Of Defense - 2 upvotes, $0
  417. Sensitive Information Leaking Through Navy Website. [█████] to U.S. Dept Of Defense - 2 upvotes, $0
  418. HTML Injection leads to XSS on███ to U.S. Dept Of Defense - 2 upvotes, $0
  419. Reflected XSS on https://███████/ to U.S. Dept Of Defense - 2 upvotes, $0
  420. [████] SQL Injections on Referer Header exploitable via Time-Based method to U.S. Dept Of Defense - 2 upvotes, $0
  421. SharePoint Web Services Exposed to Anonymous Access to U.S. Dept Of Defense - 2 upvotes, $0
  422. Sensitive data exposure via https://███████/secure/QueryComponent!Default.jspa - CVE-2020-14179 to U.S. Dept Of Defense - 2 upvotes, $0
  423. Read-only path traversal (CVE-2020-3452) at https://█████ to U.S. Dept Of Defense - 2 upvotes, $0
  424. Read-only path traversal (CVE-2020-3452) at https://████████ to U.S. Dept Of Defense - 2 upvotes, $0
  425. Cross-site scripting (XSS) vulnerability on a DoD website to U.S. Dept Of Defense - 1 upvotes, $0
  426. Access to job creation web page on http://████████ to U.S. Dept Of Defense - 1 upvotes, $0
  427. Content-Injection/XSS ████ to U.S. Dept Of Defense - 1 upvotes, $0
  428. SQL injection on https://███████ to U.S. Dept Of Defense - 1 upvotes, $0
  429. █████ - Pre-generation of VIEWSTATE allows CAC bypass to U.S. Dept Of Defense - 1 upvotes, $0
  430. [https://███] Local File Inclusion via graph.php to U.S. Dept Of Defense - 1 upvotes, $0
  431. Publicly accessible Grafana install allows pivoting to Prometheus datasource to U.S. Dept Of Defense - 1 upvotes, $0
  432. Unencrypted __VIEWSTATE parameter in a DoD website to U.S. Dept Of Defense - 1 upvotes, $0
  433. PulseSSL VPN Site with Compromised Creds @ ████ to U.S. Dept Of Defense - 1 upvotes, $0
  434. https://█████ is vulnerable to CVE-2020-3452 Read-Only Path Traversal Vulnerability to U.S. Dept Of Defense - 1 upvotes, $0
  435. SharePoint Web Services Exposed to Anonymous Access to U.S. Dept Of Defense - 1 upvotes, $0
  436. Register with non accepted email types on https://███████ to U.S. Dept Of Defense - 1 upvotes, $0
  437. Reflected XSS on https://█████ to U.S. Dept Of Defense - 1 upvotes, $0
  438. SQL injection found in US Navy Website (http://███/) to U.S. Dept Of Defense - 0 upvotes, $0
  439. Two Error-Based SQLi in courses.aspx on ██████████ to U.S. Dept Of Defense - 0 upvotes, $0
  440. SQL Injection - https://███/█████████/MSI.portal to U.S. Dept Of Defense - 0 upvotes, $0
  441. [██████████] — Directory traversal via /aerosol-bin/███████/display_directory_████_t.cgi to U.S. Dept Of Defense - 0 upvotes, $0
  442. Stored XSS on ████████helpdesk to U.S. Dept Of Defense - 0 upvotes, $0
  443. Sensitive data exposure via https://████████.mil/secure/QueryComponent!Default.jspa - CVE-2020-14179 to U.S. Dept Of Defense - 0 upvotes, $0
  444. Access to Unclassified / FOUO Advanced Motion Platform of █████████.mil to U.S. Dept Of Defense - 0 upvotes, $0
  445. SSRF in login page using fetch API exposes victims IP address to attacker controled server to U.S. Dept Of Defense - 0 upvotes, $0

Back