# An experience with Daimler's vulnerability reporting program

DevFeed: [An experience with Daimler's vulnerability reporting program](<https://devfeed.tech/articles/an-experience-with-daimler-s-vulnerability-reporting-program-32595.md>)

Original publisher: [Read original article](<https://eaton-works.com/2019/12/19/an-experience-with-daimlers-vulnerability-reporting-program/>)

Author: Eaton

Published: 2019-12-19T19:13:31Z

Content type: opinion

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Website](<https://devfeed.tech/topics/website.md>), [Google Search](<https://devfeed.tech/topics/google-search.md>), [pdf](<https://devfeed.tech/topics/pdf.md>), [Query (disambiguation)](<https://devfeed.tech/topics/query.md>)

Tags: [enumeration](<https://devfeed.tech/tags/enumeration.md>), [google-search](<https://devfeed.tech/tags/google-search.md>), [pdf](<https://devfeed.tech/tags/pdf.md>), [query](<https://devfeed.tech/tags/query.md>), [reporting](<https://devfeed.tech/tags/reporting.md>), [script](<https://devfeed.tech/tags/script.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [website](<https://devfeed.tech/tags/website.md>)

## AI overview

A firsthand account of finding sensitive and confidential documents indexed on Mercedes-Benz USA's Dealer Help Center website. The article describes how varying PDF ID numbers exposed additional documents through an unsecured endpoint and characterizes this as an enumeration attack, while noting that no customer data was found or believed to be at risk.

## Source excerpt

Reporting sensitive content exposure on an MBUSA website to Daimler.