Hall of Fame


In Scope


Out of Scope Vulnerabilities

Vulnerabilities below will be marked NA or Informative.

  • Logout CSRF
  • Session Fixation (We use session cookies and we like them __)
  • Insufficient Session Expiration
  • Weak Password Policy (See __)
  • Password Reuse (We allow any password, even passwords used previously)
  • CSRF Cookie Without 'HttpOnly' Flag
  • Beast Attack (Fixed in browsers not sever)
  • Username Enumeration
  • Software version disclosure
  • Denial of service
  • Spamming
  • Phishing
  • Social engineering

Please consolidate the same vulnerability reports when only the page/url/params changes.

