5033 | ctrl+c & ctrl+v to Steal SESSIONID |
Clickjacking |
NA |
Arbaz Hussain (@ArbazKiraak) |
Bug Bounty | 2017-07-18 | 2023-06-13 |
5032 | IDOR While Connecting Social Account in Hackster.io |
IDOR |
Hackster.io |
Arbaz Hussain (@ArbazKiraak) |
Bug Bounty | 2017-07-18 | 2023-06-13 |
5031 | Stealing Access Token of One-drive Integration By Chaining CSRF Vulnerability |
OAuth
CSRF |
NA |
Arbaz Hussain (@ArbazKiraak) |
Bug Bounty | 2017-07-18 | 2023-06-13 |
5030 | Exploiting Misconfigured CORS on popular BTC Site |
CORS misconfiguration |
NA |
Arbaz Hussain (@ArbazKiraak) |
Bug Bounty | 2017-07-19 | 2023-06-13 |
5029 | Xss using dynamically generated js file |
XSS |
NA |
Arbaz Hussain (@ArbazKiraak) |
Bug Bounty | 2017-07-19 | 2023-06-13 |
5026 | Self XSS to Good XSS Clickjacking |
XSS
Clickjacking |
NA |
Arbaz Hussain (@ArbazKiraak) |
Bug Bounty | 2017-07-20 | 2023-06-13 |
5025 | Race Condition bypassing team limit |
Race condition |
NA |
Arbaz Hussain (@ArbazKiraak) |
Bug Bounty | 2017-07-20 | 2023-06-13 |
5024 | Missing Authorization check in Facebook Pages Manager |
Authorization flaw |
Meta / Facebook |
Arbaz Hussain (@ArbazKiraak) |
Bug Bounty | 2017-07-20 | 2023-06-13 |
5020 | Stored XSS on Rockstar Game |
XSS |
Rockstar Games |
Arbaz Hussain (@ArbazKiraak) |
Bug Bounty | 2017-07-26 | 2023-06-13 |
5014 | Referer Based XSS |
XSS |
NA |
Arbaz Hussain (@ArbazKiraak) |
Bug Bounty | 2017-07-30 | 2023-06-13 |
5000 | Pre-domain wildcard CORS Exploitation |
CORS misconfiguration |
NA |
Arbaz Hussain (@ArbazKiraak) |
Bug Bounty | 2017-08-26 | 2023-06-13 |
4998 | Bypassing Rate Limit Protection by spoofing originating IP |
Bruteforce |
NA |
Arbaz Hussain (@ArbazKiraak) |
Bug Bounty | 2017-08-30 | 2023-06-13 |
4997 | Improper Storage of Private Project’s Files |
IDOR |
NA |
Arbaz Hussain (@ArbazKiraak) |
Bug Bounty | 2017-08-30 | 2023-06-13 |
4992 | Stealing 0Auth Token (MITM) |
OAuth |
NA |
Arbaz Hussain (@ArbazKiraak) |
Bug Bounty | 2017-09-01 | 2023-06-13 |
4982 | Stored XSS] with arbitrary cookie installation |
XSS |
NA |
Arbaz Hussain (@ArbazKiraak) |
Bug Bounty | 2017-09-17 | 2023-06-13 |