Vulnerability Disclosure Program (VDP)
VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.
/engagements/overstockvdp
7
In Scope
2
Out of Scope
In-Scope Assets (7)
| Asset | Category | Bounty | Quick Links | |
|---|---|---|---|---|
| https://*.bedbathandbeyond.com | URL | No | ||
| https://*.supplieroasis.com | URL | No | ||
| https://api.bedbathandbeyond.com | URL | No | ||
| https://apps.apple.com/us/app/overstock-com-mobile-shopping/id339883869 | IOS | No | - | |
| https://edge.supplieroasis.com | URL | No | ||
| https://play.google.com/store/apps/details?id=com.overstock&hl=en_US | ANDROID | No | ||
| www.bedbathandbeyond.com | URL | No |
Out-of-Scope Assets (2)
| Asset | Category | Bounty | |
|---|---|---|---|
| help.overstock.com | URL | No | |
| investors.overstock.com | URL | No |