Lucene search

K
hackeroneHudmiH1:294548
HistoryDec 02, 2017 - 7:50 p.m.

Mail.ru: Uninitilized server memory disclosure via ImageMagick

2017-12-0219:50:05
hudmi
hackerone.com
16

EPSS

0.018

Percentile

88.2%

It was possible to disclosure the part of server memory from uncontrolled location on the server belonging to “Moi Mir” (my.mail.ru) project via uploaded GIF image header manipulation.

my.mail.ru is not currently in the Bug Bounty scope, reward was paid as a bonus due to potential severity.