Report Email Alerts Open Bug Bounty: 102382 coordinated disclosures
Full Disclosure: 32224 vulnerabilities
Total Vulnerabilities Fixed: 34592
112063 vulnerable websites, 12400 VIP websites
2629 security researchers, 3729 notification subscribers

Coordinated Vulnerability Disclosure

On the 10.01.2017 security researcher k0t Approved XSS vulnerabilities: 520
Approved XSS vulnerabilities on VIP websites: 234
reported a XSS vulnerability affecting the uswitch.com website via the Open Bug Bounty vulnerability disclosure program. We verified the vulnerability and confirmed its existence.

Technical details of the vulnerability are currently hidden ("On Hold") to give website owner time to patch the vulnerability without putting any of its users at risk.

If you are the website owner, administrator or authorized third-party, please contact the researcher directly for vulnerability details and coordinated disclosure.

Important: we never act as intermediary between you and the researcher. It's completely up to you to decide if, and how, to thank the researcher. In some cases a 'thank you' email is enough, in others something more remarkable would be good to recognize his, or her, efforts and time. A recommendation may be a good idea.

uswitch.com Description

Energy Comparison of Gas & Electricity | Broadband Deals & Mobile Phones | uSwitch.com. Compare and switch gas and electricity suppliers, also compare broadband deals, mobile phone deals, car & home insurance, credit cards, boiler cover & more.

Notification & Disclosure Timeline

10 January, 2017 at 00:03 GMTVulnerability reported via Open Bug Bounty
10 January, 2017 at 00:06 GMTNotification sent to generic security emails
10 January, 2017 at 02:17 GMTNotification sent to subscribers (without technical details)

uswitch.com Ranking:

Alexa Rank12103
VIP website statusYes
Check uswitch.com for malware:Click here

Comments:

Please login via twitter to be the first one to comment.


Latest Vulnerabilities on *.uswitch.com

Vulnerability Reported by Type Status Reported on
Open Bug Bounty
On Hold
10.01.2017
Open Bug Bounty
On Hold
07.01.2017
Open Bug Bounty
On Hold
03.01.2017
Open Bug Bounty
On Hold
30.12.2016
Full Disclosure
unpatched
12.05.2016
Full Disclosure
patched
06.12.2015
Full Disclosure
patched
06.12.2015
Full Disclosure
patched
06.12.2015
Full Disclosure
patched
06.12.2015

Latest Vulnerabilities Reported by k0t

Domain Type Status Reported
Open Bug Bounty
On Hold
24.02.2017
Open Bug Bounty
On Hold
24.02.2017
Open Bug Bounty
On Hold
24.02.2017
Open Bug Bounty
On Hold
24.02.2017
Open Bug Bounty
On Hold
24.02.2017
Open Bug Bounty
On Hold
14.02.2017
Open Bug Bounty
On Hold
09.02.2017
Open Bug Bounty
On Hold
08.02.2017
Open Bug Bounty
On Hold
07.02.2017
Open Bug Bounty
On Hold
07.02.2017
Open Bug Bounty
On Hold
07.02.2017
Open Bug Bounty
On Hold
07.02.2017
Open Bug Bounty
On Hold
07.02.2017
Open Bug Bounty
On Hold
07.02.2017
Open Bug Bounty
On Hold
06.02.2017
Open Bug Bounty
On Hold
06.02.2017
Open Bug Bounty
On Hold
06.02.2017
Open Bug Bounty
On Hold
06.02.2017
Open Bug Bounty
On Hold
06.02.2017
Open Bug Bounty
On Hold
06.02.2017

Latest VIP Submissions

asrock.com
Reported by DrStache Twitter: @DrStache_
Recommendations received: 24
Approved XSS vulnerabilities: 3870
Approved XSS vulnerabilities on VIP websites: 142
on 24.02.2017
stayfriends.de
Reported by k0t Recommendations received: 4
Approved XSS vulnerabilities: 520
Approved XSS vulnerabilities on VIP websites: 234
on 24.02.2017
mp-success.com
Reported by k0t Recommendations received: 4
Approved XSS vulnerabilities: 520
Approved XSS vulnerabilities on VIP websites: 234
on 24.02.2017
commandesparcs-parksorders.ca
Reported by Spam404 Twitter: @Spam404Online
Recommendations received: 61
Approved XSS vulnerabilities: 21972
Approved XSS vulnerabilities on VIP websites: 1555
on 24.02.2017
josbank.com
Reported by Spam404 Twitter: @Spam404Online
Recommendations received: 61
Approved XSS vulnerabilities: 21972
Approved XSS vulnerabilities on VIP websites: 1555
on 24.02.2017
debenhams.com
Reported by Spam404 Twitter: @Spam404Online
Recommendations received: 61
Approved XSS vulnerabilities: 21972
Approved XSS vulnerabilities on VIP websites: 1555
on 24.02.2017
worldofwatches.com
Reported by Spam404 Twitter: @Spam404Online
Recommendations received: 61
Approved XSS vulnerabilities: 21972
Approved XSS vulnerabilities on VIP websites: 1555
on 24.02.2017
childrensplace.com
Reported by Spam404 Twitter: @Spam404Online
Recommendations received: 61
Approved XSS vulnerabilities: 21972
Approved XSS vulnerabilities on VIP websites: 1555
on 24.02.2017
menswearhouse.com
Reported by Spam404 Twitter: @Spam404Online
Recommendations received: 61
Approved XSS vulnerabilities: 21972
Approved XSS vulnerabilities on VIP websites: 1555
on 24.02.2017
sunglasshut.com
Reported by Spam404 Twitter: @Spam404Online
Recommendations received: 61
Approved XSS vulnerabilities: 21972
Approved XSS vulnerabilities on VIP websites: 1555
on 24.02.2017

Latest Submissions

divmebel.ru
Reported by Disst Recommendations received: 2
Approved XSS vulnerabilities: 489
Approved XSS vulnerabilities on VIP websites: 53
on 24.02.2017
zapekankin.ru
Reported by Disst Recommendations received: 2
Approved XSS vulnerabilities: 489
Approved XSS vulnerabilities on VIP websites: 53
on 24.02.2017
yapl.ru
Reported by Disst Recommendations received: 2
Approved XSS vulnerabilities: 489
Approved XSS vulnerabilities on VIP websites: 53
on 24.02.2017
tw.asrock.com
Reported by DrStache Twitter: @DrStache_
Recommendations received: 24
Approved XSS vulnerabilities: 3870
Approved XSS vulnerabilities on VIP websites: 142
on 24.02.2017
icade.fr
Reported by DrStache Twitter: @DrStache_
Recommendations received: 24
Approved XSS vulnerabilities: 3870
Approved XSS vulnerabilities on VIP websites: 142
on 24.02.2017
toutatice.fr
Reported by DrStache Twitter: @DrStache_
Recommendations received: 24
Approved XSS vulnerabilities: 3870
Approved XSS vulnerabilities on VIP websites: 142
on 24.02.2017
moderation.ados.fr
Reported by DrStache Twitter: @DrStache_
Recommendations received: 24
Approved XSS vulnerabilities: 3870
Approved XSS vulnerabilities on VIP websites: 142
on 24.02.2017
gba.cnam.fr
Reported by DrStache Twitter: @DrStache_
Recommendations received: 24
Approved XSS vulnerabilities: 3870
Approved XSS vulnerabilities on VIP websites: 142
on 24.02.2017
wajbety.com
Reported by hussain_0x3c Guest Researcher Profile on 24.02.2017
support.kodak.com
Reported by hussain_0x3c Guest Researcher Profile on 24.02.2017