1228 | XSS via Angular Template Injection |
CSTI
XSS
WAF bypass |
NA |
Bartłomiej Bergier (@_bergee_) |
Bug Bounty | 2022-08-13 | 2023-06-13 |
1225 | URL filter bypass, RFI and XSS |
Stored XSS
RFI |
NA |
Bartłomiej Bergier (@_bergee_) |
Bug Bounty | 2022-08-14 | 2023-06-13 |
1224 | The forgotten API and XSS filter bypass |
XSS |
NA |
Bartłomiej Bergier (@_bergee_) |
Bug Bounty | 2022-08-14 | 2023-06-13 |
1223 | Five-minute hunting for hidden XSS |
Reflected XSS |
NA |
Bartłomiej Bergier (@_bergee_) |
Bug Bounty | 2022-08-15 | 2023-06-13 |
1195 | Blind command injection |
RCE
OS command injection |
NA |
Bartłomiej Bergier (@_bergee_) |
Bug Bounty | 2022-08-21 | 2023-06-13 |
1124 | Turning cookie based XSS into account takeover |
XSS
Account takeover |
Terrahost |
Bartłomiej Bergier (@_bergee_) |
Bug Bounty | 2022-09-06 | 2023-06-13 |
1032 | Blind account takeover |
Account takeover |
NA |
Bartłomiej Bergier (@_bergee_) |
Bug Bounty | 2022-09-25 | 2023-06-13 |
908 | Chaining multiple vulnerabilities for credential stealing |
CSRF
Self-XSS
XSS |
NA |
Bartłomiej Bergier (@_bergee_) |
Bug Bounty | 2022-10-25 | 2023-06-13 |
648 | How I found multiple critical bugs in Red Bull |
Authentication bypass
HTTP response manipulation
Path traversal
LFI
XSS
SQL injection
RCE
Unrestricted file upload
RFI
Security code review |
Red Bull |
Bartłomiej Bergier (@_bergee_) |
Bug Bounty | 2022-12-26 | 2023-06-13 |
375 | Broken links hijacking and CDN takeover |
Broken link hijacking
Subdomain takeover |
NA |
Bartłomiej Bergier (@_bergee_) |
Bug Bounty | 2023-02-28 | 2023-06-13 |