4644 | Practical Web Cache Poisoning |
Web cache poisoning |
Mozilla
HubSpot
Cloudflare
Binary.com
Amazon (CloudFront) |
James Kettle (@albinowax) |
Bug Bounty | 2018-08-09 | 2023-06-13 |
4545 | Bypassing Web Cache Poisoning Countermeasures |
Web cache poisoning |
Cloudflare |
James Kettle (@albinowax) |
Bug Bounty | 2018-10-05 | 2023-06-13 |
4010 | Chaining Cache Poisoning To Stored XSS |
Web cache poisoning
Stored XSS |
NA |
Rohan aggarwal (@nahoragg) |
Bug Bounty | 2019-07-28 | 2023-06-13 |
3869 | CPDoS: Cache Poisoned Denial of Service |
DoS
Web cache poisoning |
Microsoft
Amazon
Akamai
Cloudflare
Yahoo! / Verizon Media
Play Framework |
Hoai Viet Nguyen (@hvnguyen86) |
Bug Bounty | 2019-10-22 | 2023-06-13 |
3866 | Responsible denial of service with web cache poisoning |
DoS
Web cache poisoning |
Tesla
HackerOne
Deliveroo
Bitbucket
Paypal
Meta / Facebook
Twitter |
James Kettle (@albinowax) |
Bug Bounty | 2019-10-24 | 2023-06-13 |
3527 | Web Cache Poisoning in Postmates [$1500] |
Web cache poisoning |
Postmates |
Aung Pyae Ko Ko (@BlcKVRtuL1) |
Bug Bounty | 2020-04-24 | 2023-06-13 |
3246 | The Case of the Missing Cache Keys |
Web cache poisoning |
NA |
Aaron Costello (@ConspiracyProof) |
Bug Bounty | 2020-08-05 | 2023-06-13 |
3237 | Bug Hunting with Param Miner: Cache poisoning with XSS, a peculiar case |
XSS
Web cache poisoning |
NA |
Vuk Ivanovic |
Bug Bounty | 2020-08-08 | 2023-06-13 |
3225 | Cache poisoning of wget |
Web cache poisoning |
NA |
Vuk Ivanovic |
Bug Bounty | 2020-08-12 | 2023-06-13 |
2948 | EN | Account Takeover via Web Cache Poisoning based Reflected XSS |
Reflected XSS
Web cache poisoning
Account takeover |
NA |
Lütfü Mert Ceylan (@lutfumertceylan) |
Bug Bounty | 2020-12-26 | 2023-06-13 |
2939 | Cache-Key Normalization - What could go wrong? |
Web cache poisoning
DoS |
NA |
Youstin (@iustinBB) |
Bug Bounty | 2020-12-29 | 2023-06-13 |
2899 | How I managed to trigger a Stored-XSS in an online store with the help of Cache Poisoning |
Web cache poisoning
Stored XSS |
NA |
Schizo! |
Bug Bounty | 2021-01-14 | 2023-06-13 |
2840 | How I was able to Turn a XSS into a Account Takeover |
Web cache poisoning
Stored XSS
Account takeover
OAuth
Logic flaw |
NA |
Josh Fam (@Pullerze) |
Bug Bounty | 2021-02-03 | 2023-06-13 |
2775 | Web Cache Poisoning to Account Takeover |
Web cache poisoning
Account takeover |
NA |
Josh Fam (@Pullerze) |
Bug Bounty | 2021-02-21 | 2023-06-13 |
2769 | Poisoning your Cache for 1000$ - Approach to Exploitation Walkthrough |
Web cache poisoning
Stored XSS |
NA |
Gal Nagli (@naglinagli) |
Bug Bounty | 2021-02-25 | 2023-06-13 |
2669 | Automate Cache Poisoning Vulnerability - Nuclei |
Web cache poisoning
Stored XSS |
NA |
Mohamed Elbadry (@_melbadry9) |
Bug Bounty | 2021-04-02 | 2023-06-13 |
2663 | Breaking GitHub Private Pages for $35k |
XSS
CRLF injection
Web cache poisoning |
GitHub |
Robert Chen (@NotDeGhost) |
Bug Bounty | 2021-04-04 | 2023-06-13 |
2545 | Finding my First Critical Web Cache Poisoning |
Web cache poisoning |
NA |
Yasser Khan (@N3T_hunt3r) |
Bug Bounty | 2021-05-18 | 2023-06-13 |
2284 | Cache Poisoning via SelfXSS + Path Parameter |
XSS
Web cache poisoning |
NA |
ElMahdi Mrhassel (@ElMrhassel) |
Bug Bounty | 2021-08-28 | 2023-06-13 |
1976 | Cache Poisoning at Scale |
Web cache poisoning |
GitHub
GitLab
HackerOne
Shopify
Cloudflare |
Youstin (@iustinBB) |
Bug Bounty | 2021-12-23 | 2023-06-13 |
1975 | How I found (and fixed) a vulnerability in Python |
Web cache poisoning |
Python |
Adam Goldschmidt (@AdamGolds) |
Bug Bounty | 2021-12-24 | 2023-06-13 |
1878 | How I Made $16,500 Hacking CDN Caching Servers — Part 1 |
Web cache poisoning
Stored XSS
Web cache deception |
NA |
Kevin (@bxmbn) |
Bug Bounty | 2022-01-29 | 2023-06-13 |
1333 | How I Test For Web Cache Vulnerabilities + Tips And Tricks |
Web cache poisoning
Web cache deception |
NA |
Kevin (@bxmbn) |
Bug Bounty | 2022-07-21 | 2023-06-13 |
1253 | Advanced Inter-Process Desynchronization in SAP’s HTTP Server |
Memory corruption
RCE
HTTP Request Smuggling
Web cache poisoning
Desync attack |
SAP |
Martin Doyhenard (@tincho_508) |
Bug Bounty | 2022-08-10 | 2023-06-13 |
1206 | Let%27s Dance in the Cache - Destabilizing Hash Table on Microsoft IIS! |
DoS
Web cache poisoning
Authentication bypass |
Microsoft |
Orange Tsai (@orange_8361) |
Bug Bounty | 2022-08-18 | 2023-06-13 |