4728 | Unvalidated Open Redirect Bol.com |
Open redirect |
Bol.com |
Jonathan Bouman (@JonathanBouman) |
Bug Bounty | 2018-06-12 | 2023-06-13 |
4723 | Reflected Client XSS at Amazon.com |
Reflected XSS |
Amazon |
Jonathan Bouman (@JonathanBouman) |
Bug Bounty | 2018-06-15 | 2023-06-13 |
4715 | How I hacked Apple.com (Unrestricted File Upload) |
Unrestricted file upload |
Apple |
Jonathan Bouman (@JonathanBouman) |
Bug Bounty | 2018-06-22 | 2023-06-13 |
4698 | Persistent XSS at AH.nl |
Stored XSS |
AH.nl |
Jonathan Bouman (@JonathanBouman) |
Bug Bounty | 2018-07-09 | 2023-06-13 |
4592 | XXE at Bol.com |
XXE |
Bol.com |
Jonathan Bouman (@JonathanBouman) |
Bug Bounty | 2018-09-11 | 2023-06-13 |
4581 | Reflected XSS at Philips.com |
Reflected XSS |
Philips |
Jonathan Bouman (@JonathanBouman) |
Bug Bounty | 2018-09-17 | 2023-06-13 |
4576 | Local file inclusion at IKEA.com |
LFI |
Ikea |
Jonathan Bouman (@JonathanBouman) |
Bug Bounty | 2018-09-19 | 2023-06-13 |
4551 | Persistent XSS (Unvalidated oEmbed) at Medium.com |
Stored XSS |
Medium |
Jonathan Bouman (@JonathanBouman) |
Bug Bounty | 2018-10-04 | 2023-06-13 |
4543 | Persistent XSS (unvalidated Open Graph embed) at LinkedIn.com |
Stored XSS |
LinkedIn |
Jonathan Bouman (@JonathanBouman) |
Bug Bounty | 2018-10-07 | 2023-06-13 |
4221 | Leaked Salesforce API access token at IKEA.com |
Information disclosure
Salesforce |
Ikea |
Jonathan Bouman (@JonathanBouman) |
Bug Bounty | 2019-04-04 | 2023-06-13 |
4215 | Email content spoofing at IKEA.com |
Email content spoofing |
Ikea |
Jonathan Bouman (@JonathanBouman) |
Bug Bounty | 2019-04-06 | 2023-06-13 |
3243 | Blind SQL Injection at fasteditor.hema.com |
SQL injection |
Hema |
Jonathan Bouman (@JonathanBouman) |
Bug Bounty | 2020-08-06 | 2023-06-13 |
3242 | Reflected XSS at fotoservice.hema.nl |
Reflected XSS
Open redirect |
Hema |
Jonathan Bouman (@JonathanBouman) |
Bug Bounty | 2020-08-06 | 2023-06-13 |
690 | Unprotected API endpoint at HAwebsso.nl leads to data leak of +15k medical doctor usernames & password hashes |
SSO
IDOR
Missing authentication |
HAwebsso.nl |
Jonathan Bouman (@JonathanBouman) |
Bug Bounty | 2022-12-14 | 2023-06-13 |