Public
OWOX, Inc.
bug reports.
4,419
Bug Reports -
$2,030,173
Paid Out
Last Updated:
12th September, 2017
Team
Bounty
Title
OWOX, Inc.
-
Broken Authentication & Session Management (Login Bypass) at support.owox.com
OWOX, Inc.
-
Subdomain takeover in many subdomains
OWOX, Inc.
-
Stored XSS at https://finance.owox.com/customer/accountList
OWOX, Inc.
-
Access to Grafana Dashboard
OWOX, Inc.
-
Subdomain Takeover on OWOX.RU
OWOX, Inc.
-
Subdomain Takeover on http://blog.owox.com/
OWOX, Inc.
-
invalid URL parsing with and '@'
OWOX, Inc.
-
Direct IP Access
OWOX, Inc.
-
ClickJacking
OWOX, Inc.
-
Subdomain Takeover on http://kiosk.owox.com/
OWOX, Inc.
-
HTTP Response Splitting(CRLF injection) in bi.owox.com