Abdul muhaimin

Results 9 issues of Abdul muhaimin

## Description ## This package is vulnerable to MITM or Man-In-The-Middle attack due to a downloading resources through insecure protocols. It is possible for an attacker to intercept and alter...

pr-work-in-progress

![image](https://user-images.githubusercontent.com/36979660/131303375-5f8a5f93-9007-414e-8d89-2dbf8f4eb720.png) have tried downgradeing docker-compose but no hope ? any? thanks

i have discoverd a xss thru huntr please check it https://www.huntr.dev/bounties/1-TruthHun/DocHub

recently one of my old report got invalid because lack of poc , which accidentally deleted myself a month ago ![image](https://user-images.githubusercontent.com/36979660/131289801-28b47887-1a5d-4d22-a4bc-3567054ae7de.png) So add an option on the disclosure page to...

+8

Using SafeLoader instead of Loader to avoid security risks here is a example proof of concept : ![pocforloader](https://user-images.githubusercontent.com/36979660/136096450-7de00244-b5ea-4178-8070-2356163f2f32.png) for using Loader and here is proof of fix : ![pofyaml](https://user-images.githubusercontent.com/36979660/136096621-616ea192-ae6a-48a5-ad08-58c25a7ddd3d.png) **Hacktoberfest**

Here is old Gemfile ``` source 'https://rubygems.org' ruby "2.3.5" gem 'sinatra', '1.4.8' gem 'haml' gem 'rubyzip' gem 'json','1.8.6' gem 'nokogiri' gem 'data_mapper', '1.2.0' gem 'dm-sqlite-adapter', '1.2.0' ``` now its working...