5288 | Facebook FBML DOM Traversal (Information Disclosure) |
Information disclosure |
Meta / Facebook |
Matt Austin (@mattaustin) |
Bug Bounty | 2011-08-23 | 2023-06-13 |
5255 | How I hacked Github again. |
Open redirect
Account takeover
Information disclosure |
GitHub |
Egor Homakov (@homakov) |
Bug Bounty | 2014-02-07 | 2023-06-13 |
5254 | How I was able to track the location of any Tinder user. |
Information disclosure |
Tinder |
Max Veytsman (@mveytsman) |
Bug Bounty | 2014-02-19 | 2023-06-13 |
5251 | Google Exploit – Steal Account Login Email Addresses |
Information disclosure |
Google |
Tom Anthony (@TomAnthonySEO) |
Bug Bounty | 2014-03-08 | 2023-06-13 |
5247 | Google Docs %27ClickJacking%27 (Information Disclosure) |
Clickjacking |
Google |
Matt Austin (@mattaustin) |
Bug Bounty | 2014-05-13 | 2023-06-13 |
5240 | Yahoo phpinfo.php disclosure |
Information disclosure |
Yahoo! / Verizon Media |
Patrik Fehrenbach (@ITSecurityguard) |
Bug Bounty | 2014-10-16 | 2023-06-13 |
5221 | Telegram App Store Secret-Chat Messages in Plain-Text Database |
Privacy issue
Information disclosure |
Telegram |
Jon Paterson (@shellprompt) |
Bug Bounty | 2015-02-23 | 2023-06-13 |
5192 | Hacking Magento eCommerce For Fun And 17.000 USD |
Information disclosure
LFI
RFI |
Adobe |
Egidio Romano / EgiX |
Bug Bounty | 2016-03-03 | 2023-06-13 |
5185 | Facebook Invitees Email Address Disclosure |
Information disclosure |
Meta / Facebook |
Shahar Albeck |
Bug Bounty | 2016-04-03 | 2023-06-13 |
5172 | When your privacy disclosure is a “feature” not a “bug” – Badoo & HotorNot failure! |
Information disclosure |
Badoo
Hot Or Not |
Mohamed A. Baset |
Bug Bounty | 2016-05-17 | 2023-06-13 |
5168 | Popping the Pornhub Cherry |
Information disclosure |
PornHub |
Andy Gill (@ZephrFish) |
Bug Bounty | 2016-06-07 | 2023-06-13 |
5167 | Why you shouldn’t share links on Facebook |
Information disclosure |
Meta / Facebook |
Inti De Ceukelaire (@securinti) |
Bug Bounty | 2016-06-09 | 2023-06-13 |
5163 | Uber Hacking: How we found out who you are, where you are and where you went |
Bruteforce
Information disclosure
Logic flaw
IDOR |
Uber |
Vitor “r0t” Oliveira (@r0t1v) |
Bug Bounty | 2016-06-24 | 2023-06-13 |
5159 | Stealing Facebook access_tokens using CSRF in device login flow |
CSRF
OAuth
Information disclosure |
Meta / Facebook |
Josip Franjkovic (@josipfranjkovic) |
Bug Bounty | 2016-07-19 | 2023-06-13 |
5157 | Twitter%27s Vine Source code dump - $10080 |
Source code disclosure
Information disclosure |
Twitter |
avicoder (@avicoder) |
Bug Bounty | 2016-07-22 | 2023-06-13 |
5106 | Bypassed Facebook Phone Number Security |
Authorization flaw
Logic flaw
Information disclosure |
Meta / Facebook |
Zahid Ali |
Bug Bounty | 2017-02-10 | 2023-06-13 |
5084 | Critical information disclosure on Wappalyzer.com |
Information disclosure |
Wappalyzer |
Davide Tampellini (@tampe125) |
Bug Bounty | 2017-03-24 | 2023-06-13 |
5034 | How to find internal subdomains? YQL, Yahoo! and bug bounty. |
Information disclosure |
Yahoo! / Verizon Media |
Wojciech |
Bug Bounty | 2017-07-16 | 2023-06-13 |
5013 | How i found massive information disclosure of 1500 famous people |
Information disclosure |
NA |
Valeriy Shevchenko (@Krevetk0Valeriy) |
Bug Bounty | 2017-07-31 | 2023-06-13 |
4973 | Stored XSS to Full Information disclosure |
Stored XSS |
Terapeak |
Shubham Gupta (@hackerspider1) |
Bug Bounty | 2017-09-21 | 2023-06-13 |
4959 | How I was Able to see someone’s all private files with a single file share link through Atom feed & Never Give Up #togetherwehitharder HackerOne |
Information disclosure |
NA |
Yogendra Jaiswal (@vulnh0lic) |
Bug Bounty | 2017-10-13 | 2023-06-13 |
4955 | Sensitive data exposure by requesting a resource with a different content type |
Information disclosure |
NA |
Yogendra Jaiswal (@vulnh0lic) |
Bug Bounty | 2017-10-17 | 2023-06-13 |
4948 | Senstive Information Leak Lead To join any Organisation |
Information disclosure |
NA |
Shivbihari Pandey (@ninja_pandit_) |
Bug Bounty | 2017-11-04 | 2023-06-13 |
4890 | My Research on Misconfigured Jenkins Servers |
Information disclosure
Missing authentication
Exposed Jenkins instance |
Google
Tesco
Pearson
News Uk |
Mikail Tunç (@emtunc) |
Bug Bounty | 2018-01-18 | 2023-06-13 |
4875 | Getting access to prompt debug dialog and serialized tool on main website facebook.com |
Information disclosure
Debug mode enabled |
Meta / Facebook |
Omar Espino (@omespino) |
Bug Bounty | 2018-01-31 | 2023-06-13 |