http://agoradesk.i2p/nojs/security-bounty-whitehat?dismissNotice=true
Eligibility In general, anything which has the potential for financial loss or data breach is of sufficient severity is eligible, including: • XSS • CSRF • Authentication bypass or privilege escalation • Click jacking • Remote code execution • Obtaining user information • Accounting errors In general, the following would not meet the threshold for severity: • Lack of password length restrictions • Session-related issues (session fixation etc.) • Merely showing that a page...