5257 | Waze arbitrary file upload |
Unrestricted file upload
XSS |
Google (Waze) |
Shashank (@cyberboyIndia) |
Bug Bounty | 2013-12-25 | 2023-06-13 |
5233 | Reading local files from Facebook%27s server (fixed) |
LFI
Unrestricted file upload |
Meta / Facebook |
Josip Franjkovic (@josipfranjkovic) |
Bug Bounty | 2014-12-06 | 2023-06-13 |
5204 | Arbitary File Upload Vulnerability in Google Nest (Write Up) |
Unrestricted file upload
Stored XSS |
Google |
Evan Ricafort (@evanricafort) |
Bug Bounty | 2015-12-21 | 2023-06-13 |
5194 | How I Hacked [Oculus] OAuth +Ebay +IBM |
Unrestricted file upload
XSS |
Meta / Facebook
Ebay
IBM
AnswerHub |
Abdullah Hussam (@Abdulahhusam) |
Bug Bounty | 2016-02-12 | 2023-06-13 |
5114 | How I could have Hacked IIT Guwahati’s website |
Unrestricted file upload |
IIT Guwahati |
Sai Krishna Kothapalli (@kmskrishna) |
Bug Bounty | 2017-01-09 | 2023-06-13 |
4911 | Unrestricted File Upload to RCE | Bug Bounty POC |
RCE |
Meta / Facebook |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2017-12-19 | 2023-06-13 |
4720 | Manage Engine OpManager Multiple Authenticated RCE Vulnerabilities |
RCE
Path traversal
Unrestricted file upload
Information disclosure
Arbitrary file write |
Zoho (ManageEngine) |
Denis Andzakovic |
Bug Bounty | 2018-06-18 | 2023-06-13 |
4715 | How I hacked Apple.com (Unrestricted File Upload) |
Unrestricted file upload |
Apple |
Jonathan Bouman (@JonathanBouman) |
Bug Bounty | 2018-06-22 | 2023-06-13 |
4580 | Chain The Bugs to Pwn an Organisation ( LFI + Unrestricted File Upload = Remote Code Execution ) |
LFI
Unrestricted file upload
RCE |
NA |
Armaan Pathan (@armaancrockroax) |
Bug Bounty | 2018-09-18 | 2023-06-13 |
4472 | Spoofing file extensions on HackerOne |
Unrestricted file upload |
HackerOne |
Anurag Jain (@csanuragjain) |
Bug Bounty | 2018-11-16 | 2023-06-13 |
4388 | Abusing ACL Permissions to Overwrite other User’s Uploaded Files/Videos on s3 Bucket |
Unrestricted file upload
Authorization flaw |
NA |
Armaan Pathan (@armaancrockroax) |
Bug Bounty | 2018-12-30 | 2023-06-13 |
4313 | How I hacked ASUS? |
Unrestricted file upload
RCE |
Asus |
Mustafa Kemal Can (@muskecan) |
Bug Bounty | 2019-02-09 | 2023-06-13 |
4136 | From file upload to email:pass |
Unrestricted file upload |
NA |
fr0stNuLL |
Bug Bounty | 2019-05-24 | 2023-06-13 |
4104 | Complete Web Server Access |
Unrestricted file upload
RCE |
NA |
Saad Ahmed (@XSaadAhmedX) |
Bug Bounty | 2019-06-15 | 2023-06-13 |
3925 | Exploiting File Uploads Pt. 2 – A Tale of a $3k worth RCE. |
Unrestricted file upload
RCE |
NA |
HackerOn2Wheels (@HackerOn2Wheels) |
Bug Bounty | 2019-09-13 | 2023-06-13 |
3920 | Race Condition that could Result to RCE - (A story with an App that temporary stored an uploaded file within 2 seconds before moving it to Amazon S3) |
Race condition
RCE
Unrestricted file upload |
NA |
YoKo Kho (@YokoAcc) |
Bug Bounty | 2019-09-14 | 2023-06-13 |
3905 | [Bug Bounty] Exploiting Cookie Based XSS by Finding RCE |
Information disclosure
SQL injection
Authentication bypass
Unrestricted file upload
RCE
XSS |
NA |
Tomi (@noobe_io) |
Bug Bounty | 2019-09-22 | 2023-06-13 |
3878 | How I found RCE But Got Duplicated |
Unrestricted file upload
RCE |
NA |
Smile Hacker |
Bug Bounty | 2019-10-15 | 2023-06-13 |
3801 | Dank Writeup On Broken Access Control On An Indian Startup |
Unrestricted file upload
Authorization flaw |
NA |
Divyanshu Shukla (@justm0rph3u5) |
Bug Bounty | 2019-11-30 | 2023-06-13 |
3728 | My First RCE (Stressed Employee gets me 2x bounty) |
Unrestricted file upload
RCE |
NA |
Abhishek Yadav (@abhishake100) |
Bug Bounty | 2020-01-10 | 2023-06-13 |
3692 | Tumblr Bug Bounty ( $200) |
Unrestricted file upload
XSS
Authorization flaw |
Automattic |
Myo Min Thu (@myominthu1337) |
Bug Bounty | 2020-02-02 | 2023-06-13 |
3678 | Simple Remote Code Execution Vulnerability Examples for Beginners |
RCE
Unrestricted file upload |
NA |
Ozgur Alp (@ozgur_bbh) |
Bug Bounty | 2020-02-05 | 2023-06-13 |
3673 | External XML Entity via File Upload (SVG) |
XXE
Unrestricted file upload |
NA |
Atul (@atul_hax) |
Bug Bounty | 2020-02-08 | 2023-06-13 |
3664 | Uploading Backdoor For Fun And Profit. |
Unrestricted file upload
RCE |
NA |
Mohammed Abdul Raheem (@mohdaltaf163) |
Bug Bounty | 2020-02-17 | 2023-06-13 |
3663 | How I Gain Unrestricted File Upload Remote Code Execution Bug Bounty |
Unrestricted file upload |
NA |
Shay Grant (@kidshay) |
Bug Bounty | 2020-02-17 | 2023-06-13 |