MeanEYE / Sunflower

Small and highly customizable twin-panel file manager for Linux with support for plugins.
GNU General Public License v3.0
428 stars 42 forks source link

Found CRITICAL Vulnerability on your website ! #506

Closed imchiragprajapati closed 2 years ago

imchiragprajapati commented 2 years ago

Hello I am Chirag Prajapati a Certified Penetration Tester and Ethical Hacker my License no is: 10188-161-078-1726.

I found a CRITICAL Vulnerability on your website: sunflower-fm.org

For more information I request you to kindly revert me back so that I can share with you the report ! Looking forward to hearing from you !

MeanEYE commented 2 years ago

Revert you back? Am okay talking about it publicly. Do continue here.

ArseniyK commented 2 years ago

Typical ransomware, I'm more than sure he can't provide any proof.

MeanEYE commented 2 years ago

Sounds like it to me as well, but I'll give the benefit of the doubt. Whole "license number" is obviously complete bullshit.

imchiragprajapati commented 2 years ago

Hello, I am really Sorry I was Out of Office. Please revert me on my mail: imchiragprajapat@gmail.com So I can share you the report.

I have found a Bug in your website, If you don't believe me, please see the attached Proof of Concept.

You can visit to my LinkedIn: https://www.linkedin.com/in/imchiragprajapati/ My website: cybertix.in

image

MeanEYE commented 2 years ago

If you logged in or similar thing, I'd be more inclined to believe. What are you presenting with this screen shot?

MeanEYE commented 2 years ago

Closed as invalid due to bullshit and reported to GitHub for abuse of license agreement.

imchiragprajapati commented 2 years ago

Okay, so I am deleting all the Vulnerabilities I have found and making it Public. Thanks for "YOUR BULLSHIT TIME."

MeanEYE commented 2 years ago
alert(document.cookie);

This can hardly be called a vulnerability. Further more, I have already asked to make all of them public before being asked to contact privately.