5280 | PayPal Bug Bounty: PayPaltech.com XSS |
XSS |
Paypal |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2013-04-13 | 2023-06-13 |
5270 | PayPal Bug Bounty: PayPaltech.com E-Mail Injection |
Email injection |
Paypal |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2013-09-26 | 2023-06-13 |
5248 | Magix Bug Bounty: magix.com (RCE, SQLi) and xara.com (LFI, XSS) |
RCE
SQL injection
LFI
XSS |
Magix |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2014-04-26 | 2023-06-13 |
5234 | Google Bug Bounty: Nice Catch on Google Cloud Platform Live |
Reflected XSS |
Google |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2014-11-20 | 2023-06-13 |
5211 | CVE-2014-7216: A Journey Through Yahoo’s Bug Bounty Program |
Buffer Overflow
Memory corruption |
Yahoo! / Verizon Media |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2015-09-03 | 2023-06-13 |
5193 | Ubiquiti Bug Bounty: UniFi v3.2.10 Generic CSRF Protection Bypass |
CSRF |
Ubiquity Networks |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2016-02-23 | 2023-06-13 |
5093 | Ok Google, Give Me All Your Internal DNS Information! |
SSRF |
Google |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2017-03-01 | 2023-06-13 |
4999 | Upgrade from LFI to RCE via PHP Sessions |
LFI
RCE |
NA |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2017-08-28 | 2023-06-13 |
4210 | Dell KACE K1000 Remote Code Execution — the Story of Bug K1–18652 |
RCE |
Dropbox |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2019-04-09 | 2023-06-13 |
4085 | About a Sucuri RCE...and How Not to Handle Bug Bounty Reports |
RCE |
Sucuri |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2019-06-20 | 2023-06-13 |
3931 | H1-4420: From Quiz to Admin - Chaining Two 0-Days to Compromise An Uber Wordpress |
Stored XSS
SQL injection |
Uber |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2019-09-10 | 2023-06-13 |
3034 | Smuggling an (Un)exploitable XSS |
HTTP Request Smuggling
XSS |
NA |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2020-11-13 | 2023-06-13 |
1328 | WordPress Transposh: Exploiting a Blind SQL Injection via XSS - RCE Security |
SQL injection
XSS
Account takeover |
WordPress |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2022-07-22 | 2023-06-13 |
784 | From Zero to Hero Part 1: Bypassing Intel DCM’s Authentication by Spoofing Kerberos and LDAP Responses (CVE-2022-33942) |
Authentication bypass
Kerberos
RCE
Privilege escalation
Security code review |
Intel |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2022-11-23 | 2023-06-13 |
746 | From Zero to Hero Part 2: From SQL Injection to RCE on Intel DCM (CVE-2022-21225) |
SQL injection
Kerberos
RCE
Privilege escalation
Security code review |
Intel |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2022-12-01 | 2023-06-13 |
207 | SecurePwn Part 1: Bypassing SecurePoint UTM’s Authentication (CVE-2023-22620) |
Authentication bypass |
SecurePoint |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2023-04-11 | 2023-06-13 |
203 | SecurePwn Part 2: Leaking Remote Memory Contents (CVE-2023-22897) |
Memory leak |
SecurePoint |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2023-04-12 | 2023-06-13 |