5275 | How I found my way into Instagram%27s Ganglia, and a bug with Facebook likes. |
Reflected XSS
IDOR |
Meta / Facebook |
Josip Franjkovic (@josipfranjkovic) |
Bug Bounty | 2013-07-23 | 2023-06-13 |
5249 | A Tale of 7 Vulnerabilities |
Stored XSS
Reflected XSS
Default credentials
Privilege escalation |
Paypal |
Patrik Fehrenbach (@ITSecurityguard) |
Bug Bounty | 2014-04-20 | 2023-06-13 |
5245 | ebay bug bounty |
Reflected XSS |
Ebay |
Matthew Bryant (@IAmMandatory) |
Bug Bounty | 2014-06-06 | 2023-06-13 |
5235 | Reflected Cross Site Scripting BillMeLater |
Reflected XSS |
BillMeLater |
Patrik Fehrenbach (@ITSecurityguard) |
Bug Bounty | 2014-11-17 | 2023-06-13 |
5234 | Google Bug Bounty: Nice Catch on Google Cloud Platform Live |
Reflected XSS |
Google |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2014-11-20 | 2023-06-13 |
5230 | Reflected Cross Site Scripting at Paypal.com |
Reflected XSS |
Paypal |
Patrik Fehrenbach (@ITSecurityguard) |
Bug Bounty | 2014-12-15 | 2023-06-13 |
5225 | admin.google.com Reflected Cross-Site Scripting (XSS) |
Reflected XSS |
Google |
Brett Buerhaus (@bbuerhaus) |
Bug Bounty | 2015-01-21 | 2023-06-13 |
5121 | Bypassing Ebay XSS Protection to launch XSS by Nirmal Dahal |
Reflected XSS |
Ebay |
Nirmal Dahal (@TheNittam) |
Bug Bounty | 2016-11-18 | 2023-06-13 |
5115 | Stealing passwords from McDonald%27s users |
Reflected XSS
AngularJS sandbox bypass |
McDonalds |
Tijme Gommers (@tijme) |
Bug Bounty | 2017-01-09 | 2023-06-13 |
5059 | Godaddy XSS affects parked domains redirector/processor! |
Reflected XSS |
GoDaddy |
Mohamed A. Baset |
Bug Bounty | 2017-06-11 | 2023-06-13 |
5057 | XSS on Bugcrowd and so many other website’s main Domain |
Reflected XSS |
Bugcrowd |
Bull (@v0sx9b) |
Bug Bounty | 2017-06-14 | 2023-06-13 |
5049 | CVE-2017-10711: Reflected XSS vulnerability in SimpleRisk – Open Source Risk Management System |
Reflected XSS |
SimpleRisk |
Mohamed A. Baset |
Bug Bounty | 2017-06-28 | 2023-06-13 |
5028 | That Escalated Quickly : From partial CSRF to reflected XSS to complete CSRF to Stored XSS |
CSRF
Reflected XSS
Stored XSS |
NA |
Mandeep Jadon (@1337tr0lls) |
Bug Bounty | 2017-07-19 | 2023-06-13 |
5016 | Cracking the lens: targeting HTTP%27s hidden attack-surface |
Reflected XSS
SSRF |
Yahoo! / Verizon Media
BT
New Relic |
James Kettle (@albinowax) |
Bug Bounty | 2017-07-27 | 2023-06-13 |
5005 | Reflected XSS on www.yahoo.com |
Reflected XSS |
Yahoo! / Verizon Media |
Samuel (@saamux) |
Bug Bounty | 2017-08-12 | 2023-06-13 |
4993 | Reflected XSS in Yahoo! |
Reflected XSS |
Yahoo! / Verizon Media |
Shahzada AL Shahriar Khan (@TheShahzada) |
Bug Bounty | 2017-08-31 | 2023-06-13 |
4991 | My write up about UBER Cross-site scripting by help of KNOXSS |
Reflected XSS |
Uber |
Emad Shanab (@Alra3ees) |
Bug Bounty | 2017-09-02 | 2023-06-13 |
4988 | How I found Reflective XSS in Yahoo Subdomain |
Reflected XSS |
Yahoo! / Verizon Media |
Syntax Error (@SYNTAXERRORBA) |
Bug Bounty | 2017-09-03 | 2023-06-13 |
4987 | Reflective XSS and Open Redirect on Indeed.com subdomain |
Reflected XSS
Open redirect |
Indeed |
Syntax Error (@SYNTAXERRORBA) |
Bug Bounty | 2017-09-04 | 2023-06-13 |
4979 | Exploiting a Single Request for Multiple Vulnerabilities |
Stored XSS
Reflected XSS
SSRF
OS command injection |
NA |
Osama Ansari (@AnsariOsama10) |
Bug Bounty | 2017-09-19 | 2023-06-13 |
4976 | All About Hackerone Private Program Terapeak |
IDOR
Reflected XSS |
Terapeak |
Shubham Gupta (@hackerspider1) |
Bug Bounty | 2017-09-20 | 2023-06-13 |
4969 | Filter Bypass to Reflected XSS on https://finance.yahoo.com (mobile version) |
Reflected XSS |
Yahoo! / Verizon Media |
Samuel (@saamux) |
Bug Bounty | 2017-09-24 | 2023-06-13 |
4967 | Craft CMS – Why case matters |
Reflected XSS
Content injection |
Craft CMS |
Markus Krell (@MarkusKrell) |
Bug Bounty | 2017-10-01 | 2023-06-13 |
4945 | Non-persistent XSS at Microsoft -Adesh Kolte |
Reflected XSS |
Microsoft |
Adesh Nandkishor kolte (@AdeshKolte) |
Bug Bounty | 2017-11-05 | 2023-06-13 |
4929 | VMware Official VCDX Reflected XSS |
Reflected XSS |
VMware |
Honc (@honcbb) |
Bug Bounty | 2017-11-19 | 2023-06-13 |