5282 | How I Rewarded with USD?K Just With a Simple Search Form |
SQL injection |
Paypal |
yappare (@yappare) |
Bug Bounty | 2013-04-11 | 2023-06-13 |
5274 | SQL injections in Nokia sites. |
SQL injection |
Nokia |
Josip Franjkovic (@josipfranjkovic) |
Bug Bounty | 2013-07-30 | 2023-06-13 |
5252 | Tesla Motors blind SQL injection |
SQL injection |
Tesla |
Bitquark (@bitquark) |
Bug Bounty | 2014-02-23 | 2023-06-13 |
5248 | Magix Bug Bounty: magix.com (RCE, SQLi) and xara.com (LFI, XSS) |
RCE
SQL injection
LFI
XSS |
Magix |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2014-04-26 | 2023-06-13 |
5242 | Popping a shell on the Oculus developer portal |
SQL injection
CSRF
RCE
IDOR |
Meta / Facebook |
Bitquark (@bitquark) |
Bug Bounty | 2014-08-31 | 2023-06-13 |
5241 | Step-by-step: exploiting SQL injection(s) in Oculus%27 website. |
SQL injection |
Meta / Facebook |
Josip Franjkovic (@josipfranjkovic) |
Bug Bounty | 2014-09-05 | 2023-06-13 |
5227 | Yahoo – Root Access SQL Injection – tw.yahoo.com |
SQL injection |
Yahoo! / Verizon Media |
Brett Buerhaus (@bbuerhaus) |
Bug Bounty | 2015-01-15 | 2023-06-13 |
5214 | Blind SQL Inejction [Hootsuite] |
Blind SQL injection |
Hootsuite |
Abdullah Hussam (@Abdulahhusam) |
Bug Bounty | 2015-08-01 | 2023-06-13 |
5195 | A Hilarious ESET Broken Authentication Vulnerability (one click free purchase) |
Authentication flaw
SQL injection |
ESET |
Mohamed A. Baset |
Bug Bounty | 2016-02-12 | 2023-06-13 |
5191 | SQL Injection On MEGA.NZ |
SQL injection |
MEGA |
Naresh LamGade (@nlamgade) |
Bug Bounty | 2016-03-11 | 2023-06-13 |
5107 | Type Juggling and PHP Object Injection, and SQLi, Oh My! |
Type juggling
PHP Object Injection
Insecure deserialization
SQL injection |
NA |
Justin Kennedy (@jstnkndy) |
Bug Bounty | 2017-02-07 | 2023-06-13 |
5102 | SQL injection in an UPDATE query - a bug bounty story! |
SQL injection |
NA |
Mahmoud Gamal (@Zombiehelp54) |
Bug Bounty | 2017-02-17 | 2023-06-13 |
5098 | Practical Exploitation of Error Based Sql Injection |
SQL injection |
NA |
Eslam Salem (@net_code) |
Bug Bounty | 2017-02-20 | 2023-06-13 |
5095 | Time-based Blind SQLi on news.starbucks.com |
Blind SQL injection |
Starbucks |
toctou |
Bug Bounty | 2017-02-26 | 2023-06-13 |
5079 | Tales of SugarCRM Security Horrors |
PHP Object Injection
SQL injection
Authentication bypass |
SugarCRM |
Egidio Romano / EgiX |
Bug Bounty | 2017-04-23 | 2023-06-13 |
5075 | Hacking the NHS for Fun and No Profit |
SQL injection
LFI |
NHS |
Nathan (@NathOnSecurity) |
Bug Bounty | 2017-05-22 | 2023-06-13 |
4977 | Multiple vulnerabilities in Oracle EBS |
SQL injection
XXE
XSS |
NA |
Shubham Gupta (@hackerspider1) |
Bug Bounty | 2017-09-19 | 2023-06-13 |
4933 | SQL in everywhere. |
SQL injection |
NA |
Utkarsh Agrawal (@agrawalsmart7) |
Bug Bounty | 2017-11-16 | 2023-06-13 |
4922 | SQL Injection in rog.asus.com |
SQL injection
Security code review |
Asus |
Corben Leo (@hacker_) |
Bug Bounty | 2017-11-30 | 2023-06-13 |
4868 | SQL injection with load file and into outfile |
SQL injection |
NA |
NoGe (@p4c3n0g3) |
Bug Bounty | 2018-02-05 | 2023-06-13 |
4836 | Union Based Sql injection Write up ->A private Company Site |
SQL injection |
NA |
Nur A Alam Dipu (@Dipu1A) |
Bug Bounty | 2018-03-12 | 2023-06-13 |
4820 | My Best Small Report Bounty Report in Private Program ( Django REST framework Admin Login ByPass ) |
SQL injection
Authentication bypass
Account takeover |
NA |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2018-04-01 | 2023-06-13 |
4810 | Source Code Analysis in YSurvey — Luminate bug |
Authentication bypass
Authorization flaw
SQL injection |
Yahoo! / Verizon Media |
Rojan Rijal (@uraniumhacker) |
Bug Bounty | 2018-04-10 | 2023-06-13 |
4808 | Please email me your password |
Blind XSS
Blind SQL injection
SMTP injection
Account takeover |
NA |
Jasmin Laundry (@JR0ch17) |
Bug Bounty | 2018-04-11 | 2023-06-13 |
4772 | A Five Minute SQL-I |
SQL injection |
NA |
Ashish Jha |
Bug Bounty | 2018-05-06 | 2023-06-13 |