5190 | Command injection which got me "6000$" from #Google |
OS command injection |
Google |
Venkatesh Sivakumar (@pranavvenkats) |
Bug Bounty | 2016-03-15 | 2023-06-13 |
5131 | Command Injection Without Spaces |
OS command injection |
NA |
Fyoorer (@ƒyoorer) |
Bug Bounty | 2016-10-02 | 2023-06-13 |
4979 | Exploiting a Single Request for Multiple Vulnerabilities |
Stored XSS
Reflected XSS
SSRF
OS command injection |
NA |
Osama Ansari (@AnsariOsama10) |
Bug Bounty | 2017-09-19 | 2023-06-13 |
4707 | Unauthenticated Command Injection Vulnerability in VMware NSX SD-WAN by VeloCloud |
OS command injection
RCE |
VMware |
Brian Sullivan |
Bug Bounty | 2018-06-29 | 2023-06-13 |
4557 | Collecting Shells by the Sea of NAS Vulnerabilities |
OS command injection
XSS
CSRF |
Lenovo |
Rick Ramgattie (@RRamgattie) |
Bug Bounty | 2018-10-01 | 2023-06-13 |
4438 | Digging in to SCP Command Injection |
OS command injection |
JSch |
Dylan Katz (@Plazmaz) |
Bug Bounty | 2018-12-03 | 2023-06-13 |
4362 | Command Injection PoC |
OS command injection |
NA |
NoGe (@p4c3n0g3) |
Bug Bounty | 2019-01-15 | 2023-06-13 |
3492 | Pentesting Cisco SD-WAN Part 2: Breaking Routers |
OS command injection
Security code review |
Cisco |
Julien Legras (@Julien_Legras) |
Bug Bounty | 2020-05-07 | 2023-06-13 |
3409 | Cmd Hijack - a command/argument confusion with path traversal in cmd.exe |
OS command injection
Path traversal |
Microsoft |
Julian Horoszkiewicz |
Bug Bounty | 2020-06-10 | 2023-06-13 |
3224 | Blind OS Command Injection |
OS command injection |
NA |
Ashik B |
Bug Bounty | 2020-08-12 | 2023-06-13 |
3109 | We Hacked Apple for 3 Months: Here’s What We Found |
RCE
Authentication bypass
Authorization bypass
SSRF
XXE
Blind XSS
IDOR
OS command injection
SQL injection |
Apple |
Sam Curry (@samwcyo) |
Bug Bounty | 2020-10-07 | 2023-06-13 |
3065 | Beyond the wall: command injection still alive. |
OS command injection |
NA |
Ahmed Constant (@a_Constant_) |
Bug Bounty | 2020-10-31 | 2023-06-13 |
3030 | SD-PWN Part 2 — Citrix SD-WAN Center — Another Network Takeover |
RCE
Authentication bypass
Path traversal
OS command injection
Local Privilege Escalation |
Citrix Systems |
Realmode Labs (@RealmodeLabs) |
Bug Bounty | 2020-11-15 | 2023-06-13 |
3021 | Hacking into (RCE) Government Server operated for the US Department of Energy’s National Nuclear Security Administration. |
RCE
OS command injection |
US Department of Energy |
Shaheen Fazim |
Bug Bounty | 2020-11-16 | 2023-06-13 |
3007 | SD-PWN — Part 3 — Cisco vManage — Another Day, Another Network Takeover |
RCE
SSRF
Arbitrary file write
Path traversal
OS command injection
Local Privilege Escalation |
Cisco |
Realmode Labs (@RealmodeLabs) |
Bug Bounty | 2020-11-23 | 2023-06-13 |
2856 | Analysing Crash Messages To Achieve Blind Root Command Injection |
OS command injection |
NA |
Shawar Khan (@ShawarkOFFICIAL) |
Bug Bounty | 2021-01-28 | 2023-06-13 |
2713 | An unknown Linux secret that turned SSRF to OS Command injection |
SSRF
Command injection |
NA |
secureITmania (@secureitmania) |
Bug Bounty | 2021-03-17 | 2023-06-13 |
2667 | Code execution as root via AT commands on the Quectel EG25-G modem |
OS command injection
RCE |
Quectel |
nns |
Bug Bounty | 2021-04-03 | 2023-06-13 |
2645 | Advisory: Cisco RV34X Series – Authentication Bypass and Remote Command Execution |
Authentication bypass
OS command injection
RCE |
Cisco |
T. Shiomitsu |
Bug Bounty | 2021-04-13 | 2023-06-13 |
2634 | Discoure themes OS Command Injection |
RCE
OS command injection |
Discourse |
joernchen (@joernchen) |
Bug Bounty | 2021-04-18 | 2023-06-13 |
2110 | How I found Command Injection via Obsolete PHPThumb |
OS command injection
RCE |
NA |
Sushant Kamble |
Bug Bounty | 2021-10-30 | 2023-06-13 |
2065 | A Story of an Epic Blind Remote Code Execution(RCE) |
RCE
OS command injection |
NA |
Akash Solanki (@MAALP1225) |
Bug Bounty | 2021-11-18 | 2023-06-13 |
1881 | Command Injection in Google Cloud Shell |
RCE
OS command injection |
Google |
Ademar Nowasky Junior |
Bug Bounty | 2022-01-28 | 2023-06-13 |
1819 | Advisory: Western Digital My Cloud Pro Series PR4100 RCE |
RCE
OS command injection |
Western Digital |
Quentin Kaiser (@QKaiser) |
Bug Bounty | 2022-02-15 | 2023-06-13 |
1809 | Advisory: Cisco RV340 Dual WAN Gigabit VPN Router (RCE over LAN) |
RCE
Unrestricted file upload
OS command injection |
Cisco |
Quentin Kaiser (@QKaiser) |
Bug Bounty | 2022-02-17 | 2023-06-13 |