5261 | Heroku Directory Transversal |
Path traversal |
Heroku |
Shashank (@cyberboyIndia) |
Bug Bounty | 2013-12-03 | 2023-06-13 |
5246 | Prezi (map.prezi.com) Path Traversal |
Path traversal |
Prezi |
Patrik Fehrenbach (@ITSecurityguard) |
Bug Bounty | 2014-05-21 | 2023-06-13 |
5091 | Airbnb – Chaining Third-Party Open Redirect into Server-Side Request Forgery (SSRF) via LivePerson Chat |
Open redirect
SSRF
Path traversal |
Airbnb |
Brett Buerhaus (@bbuerhaus) |
Bug Bounty | 2017-03-09 | 2023-06-13 |
4882 | No RCE? Then SSH to the box! |
LFI
Path traversal
RCE |
NA |
Jasmin Laundry (@JR0ch17) |
Bug Bounty | 2018-01-25 | 2023-06-13 |
4867 | How I gained access to Sony’s database |
Path traversal |
Sony |
Rahul R |
Bug Bounty | 2018-02-06 | 2023-06-13 |
4847 | #BugBounty — API keys leakage, Source code disclosure in India’s largest e-commerce health care company. |
Path traversal |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-02-25 | 2023-06-13 |
4747 | 5k$ for path traversal on *.paypal-corp.com subdomain |
Path traversal |
Paypal |
lalka (@0x01alka) |
Bug Bounty | 2018-05-30 | 2023-06-13 |
4720 | Manage Engine OpManager Multiple Authenticated RCE Vulnerabilities |
RCE
Path traversal
Unrestricted file upload
Information disclosure
Arbitrary file write |
Zoho (ManageEngine) |
Denis Andzakovic |
Bug Bounty | 2018-06-18 | 2023-06-13 |
4623 | Traversing the Path to RCE |
Path traversal
RCE |
NA |
hawkinsecurity |
Bug Bounty | 2018-08-27 | 2023-06-13 |
4528 | Path traversal while uploading results in RCE |
Path traversal
RCE |
NA |
Harsh Jaiswal (@rootxharsh) |
Bug Bounty | 2018-10-15 | 2023-06-13 |
4498 | CVE-2018-11759 – Apache mod_jk access control bypass |
Path traversal |
Apache HTTP Server |
Raphaël Arrouas |
Bug Bounty | 2018-11-01 | 2023-06-13 |
4494 | Unauthenticated RSFTP to Command Injection |
Path traversal
RCE |
NA |
Nicodemo Gawronski |
Bug Bounty | 2018-11-03 | 2023-06-13 |
4342 | Magento – RCE & Local File Read with low privilege admin rights |
LFI
RCE
Path traversal |
Magento |
Daniel Le Gall (@Blaklis_) |
Bug Bounty | 2019-01-24 | 2023-06-13 |
4324 | Reverse RDP Attack: Code Execution on RDP Clients |
Path traversal |
Microsoft |
Eyal Itkin |
Bug Bounty | 2019-02-05 | 2023-06-13 |
4320 | Remote Code Execution via Path Traversal in the Device Metadata Authoring Wizard |
Path traversal
RCE |
Microsoft |
Lee Christensen (@tifkin_) |
Bug Bounty | 2019-02-06 | 2023-06-13 |
4214 | Old but GOLD Dot Dot Slash to Get the Flag — Uber Microservice |
SSRF
Path traversal
Account takeover |
Uber |
Ron Chan (@ngalongc) |
Bug Bounty | 2019-04-07 | 2023-06-13 |
4195 | Code execution - Evernote |
RCE
Path traversal |
Evernote |
Dhiraj (@mishradhiraj_) |
Bug Bounty | 2019-04-17 | 2023-06-13 |
4124 | Simple PathTraversal bypass |
Path traversal |
NA |
fr0stNuLL |
Bug Bounty | 2019-06-03 | 2023-06-13 |
4123 | Chaining multiple low-impact bugs to arbitrary file read in GitLab |
Path traversal |
GitLab |
Li Rongxi (@nyan_gawa) |
Bug Bounty | 2019-06-04 | 2023-06-13 |
3944 | RCE using Path Traversal |
RCE
Path traversal |
NA |
inc0gbyt3 (@incogbyte) |
Bug Bounty | 2019-09-02 | 2023-06-13 |
3900 | Analysis of CVE-2019-14994 – Jira Service Desk Path Traversal leads to Massive Information Disclosure |
Path traversal |
Atlassian |
Sam Curry (@samwcyo) |
Bug Bounty | 2019-09-25 | 2023-06-13 |
3488 | Magic of the Back Slash |
Path traversal |
NA |
Anil Tom (mr_4nk) |
Bug Bounty | 2020-05-11 | 2023-06-13 |
3409 | Cmd Hijack - a command/argument confusion with path traversal in cmd.exe |
OS command injection
Path traversal |
Microsoft |
Julian Horoszkiewicz |
Bug Bounty | 2020-06-10 | 2023-06-13 |
3377 | Hacking Starbucks and Accessing Nearly 100 Million Customer Records |
Path traversal |
Starbucks |
Sam Curry (@samwcyo) |
Bug Bounty | 2020-06-20 | 2023-06-13 |
3362 | Bypassing file upload filter by source code review in Bolt CMS |
RCE
Unrestricted file upload
Path traversal
Security code review |
Bolt CMS |
Sivanesh Ashok (@sivaneshashok) |
Bug Bounty | 2020-06-27 | 2023-06-13 |