Report Email Alerts Open Bug Bounty: 203,355 coordinated disclosures
Total Vulnerabilities Fixed: 96,947
186,320 vulnerable websites, 17,612 VIP websites
4,530 security researchers, 5,850 notification subscribers

Open Bug Bounty ID

OBB-190193

gamepass.nfl.com Security Vulnerability

On the 31.10.2016 security researcher TvM Helped patch 591 vulnerabilities
Received 5 Coordinated Disclosure badges
Received 22 recommendations
disclosed XSS vulnerability affecting gamepass.nfl.com website.

On our side, we have notified website owner via all reasonable communication channels about the vulnerability, so it can be patched as quickly as possible.

Currently the vulnerability is patched and does not represent any security risk for the website or its visitors.

Vulnerability Details


gamepass.nfl.com Description

Watch NFL Games Live | NFL Game Pass - NFL.com. Users outside the USA can watch NFL games online, streaming in HD quality. Watch both live and post game recaps.

Vulnerable URL:

Other details:

Patched:Yes, at 13.09.2017
Latest check for patch:13.09.2017 08:01 GMT
Vulnerability type:XSS
Vulnerability status:Publicly disclosed
Alexa RankUnknown / Not calculated
VIP website status:No
Check gamepass.nfl.com for malware:Click here
Check gamepass.nfl.com SSL connection:Click here (Grade: A) Refresh Results

Mirror: Click here to view the mirror

Coordinated Disclosure Timeline

Vulnerability submitted via Open Bug Bounty31 October, 2016 21:23 GMT
Vulnerability existence verified and confirmed 1 November, 2016 09:54 GMT
Generic security notifications sent to website owner1 November, 2016 09:54 GMT
Notification sent to subscribers (without technical details)1 November, 2016 10:17 GMT
Vulnerability details disclosed by researcher24 January, 2017 10:15 GMT
Vulnerability patched by the website owner13 September, 2017 08:01 GMT

User Comments:

Please login via twitter to be the first one to comment.


Latest Vulnerabilities on *.gamepass.nfl.com

OBB-ID Reported by Status Reported on
patched
31.10.2016

Latest Vulnerabilities Reported by TvM

OBB-ID Vulnerability Status Reported
patched
06.07.2017
patched
06.07.2017
patched
21.06.2017
unpatched
19.06.2017
unpatched
26.05.2017
patched
22.05.2017
patched
22.05.2017
unpatched
22.05.2017
patched
22.05.2017
unpatched
19.05.2017
unpatched
19.05.2017
unpatched
19.05.2017
unpatched
18.05.2017
patched
18.05.2017
patched
18.05.2017
unpatched
18.05.2017
patched
18.05.2017
unpatched
18.05.2017
patched
18.05.2017
unpatched
17.05.2017


LATEST VIP SUBMISSIONS

argonne180.rssing.com
Reported by OmniGooch Helped patch 1799 vulnerabilities
Received 5 Coordinated Disclosure badges
Received 7 recommendations
on 16.01.2018
harry.rssing.com
Reported by OmniGooch Helped patch 1799 vulnerabilities
Received 5 Coordinated Disclosure badges
Received 7 recommendations
on 16.01.2018
moneyscience37308.rssing.com
Reported by OmniGooch Helped patch 1799 vulnerabilities
Received 5 Coordinated Disclosure badges
Received 7 recommendations
on 16.01.2018
informit.com
Reported by OmniGooch Helped patch 1799 vulnerabilities
Received 5 Coordinated Disclosure badges
Received 7 recommendations
on 16.01.2018
livehelpnow.net
Reported by OmniGooch Helped patch 1799 vulnerabilities
Received 5 Coordinated Disclosure badges
Received 7 recommendations
on 16.01.2018
elcomercio.es
Reported by OmniGooch Helped patch 1799 vulnerabilities
Received 5 Coordinated Disclosure badges
Received 7 recommendations
on 16.01.2018
overdrive.com
Reported by OmniGooch Helped patch 1799 vulnerabilities
Received 5 Coordinated Disclosure badges
Received 7 recommendations
on 16.01.2018
save-video.com
Reported by OmniGooch Helped patch 1799 vulnerabilities
Received 5 Coordinated Disclosure badges
Received 7 recommendations
on 16.01.2018
gss.princeton.edu
Reported by RiceNinja248 Helped patch 0 vulnerabilities
Received 0 Coordinated Disclosure badges
on 16.01.2018
instiz.net
Reported by OmniGooch Helped patch 1799 vulnerabilities
Received 5 Coordinated Disclosure badges
Received 7 recommendations
on 15.01.2018



LATEST SUBMISSIONS

hostix.de
Reported by SecuNinja Helped patch 1177 vulnerabilities
Received 8 Coordinated Disclosure badges
Received 37 recommendations
on 16.01.2018
webhost-germany.de
Reported by SecuNinja Helped patch 1177 vulnerabilities
Received 8 Coordinated Disclosure badges
Received 37 recommendations
on 16.01.2018
webhosterwissen.de
Reported by SecuNinja Helped patch 1177 vulnerabilities
Received 8 Coordinated Disclosure badges
Received 37 recommendations
on 16.01.2018
abonda.de
Reported by SecuNinja Helped patch 1177 vulnerabilities
Received 8 Coordinated Disclosure badges
Received 37 recommendations
on 16.01.2018
frontdesk.asus.com
Reported by DLS Helped patch 60 vulnerabilities
Received 2 Coordinated Disclosure badges
on 16.01.2018
advantage.asus.com
Reported by DLS Helped patch 60 vulnerabilities
Received 2 Coordinated Disclosure badges
on 16.01.2018
ecom-hosting.de
Reported by SecuNinja Helped patch 1177 vulnerabilities
Received 8 Coordinated Disclosure badges
Received 37 recommendations
on 16.01.2018
ascio.de
Reported by SecuNinja Helped patch 1177 vulnerabilities
Received 8 Coordinated Disclosure badges
Received 37 recommendations
on 16.01.2018
hr-recruit.asus.com
Reported by DLS Helped patch 60 vulnerabilities
Received 2 Coordinated Disclosure badges
on 16.01.2018
uk.store.asus.com
Reported by DLS Helped patch 60 vulnerabilities
Received 2 Coordinated Disclosure badges
on 16.01.2018