TripAdvisor
Bounty Full Safe Harbor
Up to USD $5,000
Program Details
- Managed
- Yes
- Allows Disclosure
- No
Scope (27 targets)
web: 12 mobile: 3 api: 12 In Scope
- api.production.cde.tamg.cloud api bounty-eligible
- partnerapi.tapayments.com api bounty-eligible
- partnerapi1.tapayments.com api bounty-eligible
- partnerapi2.tapayments.com api bounty-eligible
- walletproxy.tapayments.com api bounty-eligible
- walletproxy1.tapayments.com api bounty-eligible
- walletproxy2.tapayments.com api bounty-eligible
- www.tripadvisor.com web bounty-eligible
- Localized versions of www.tripadvisor.com available from the site's header or footer web bounty-eligible
- api.tripadvisor.com api bounty-eligible
- service.platform.tripadvisor.com api bounty-eligible
- gwapi.tripadvisor.com api bounty-eligible
- gwapi1.tripadvisor.com api bounty-eligible
- gwapi2.tripadvisor.com api bounty-eligible
- Any publicly accessible Tripadvisor web asset or host (domains, ip space, etc) - except for assets listed as Out-of-Scope below. web bounty-eligible
- Tripadvisor Android App mobile bounty-eligible
- Tripadvisor iOS App mobile bounty-eligible
- rentals.tripadvisor.com web bounty-eligible
- *.vacationhomerentals.com web bounty-eligible
- *.holidaylettings.com web bounty-eligible
- and 7 more targets
Out of Scope
*.bokun.eu, *.bokun.website, *.bokun.tools, *.bokun.team, ir.tripadvisor.com, *.tripadviser.at, *.tripadvisor.cn, *.tripadvisor.*/Trips, *.tripadvisor.*/Mobile*, *.tripadvisor.*/engineering, *.tripadvisor.*/WidgetEmbed-*, spotlight-dev.tripadvisor.com, spotlight.tripadvisor.*, careers.tripadvisor.com, *.tripadvisoradexpress.*, *.tripadvisorwifi.*, *.bokun.io, *.bokun.is, *.bokun.com, *.bokun.app, taplus.*, tripadvisor-plus.*, tripadvisorplus.*, *.experiences.zone, travelermail.com, *.bokunmobile.website
Additional Info
- Sources
- bugcrowd