5195 | A Hilarious ESET Broken Authentication Vulnerability (one click free purchase) |
Authentication flaw
SQL injection |
ESET |
Mohamed A. Baset |
Bug Bounty | 2016-02-12 | 2023-06-13 |
5182 | Facebook ClickJacking – How we put a new dress on Facebook UI |
Clickjacking |
Meta / Facebook |
Mohamed A. Baset |
Bug Bounty | 2016-04-22 | 2023-06-13 |
5181 | Official Telegram Web Client ClickJacking Vulnerability – When crypto is strong and client is weak |
Clickjacking |
Telegram |
Mohamed A. Baset |
Bug Bounty | 2016-04-28 | 2023-06-13 |
5180 | WhatsApp Clickjacking Vulnerability – Yet another web client failure! |
Clickjacking |
Meta / Facebook |
Mohamed A. Baset |
Bug Bounty | 2016-05-04 | 2023-06-13 |
5179 | Facebook movies recommendation vulnerability – A bug capable of erasing all your important notifications! |
Logic flaw
DoS |
Meta / Facebook |
Mohamed A. Baset |
Bug Bounty | 2016-05-05 | 2023-06-13 |
5177 | FirefoxOS Find My Device Service Clickjacking Bug results in Changing PINs, Wiping and Locking Phones! |
Clickjacking |
Mozilla |
Mohamed A. Baset |
Bug Bounty | 2016-05-12 | 2023-06-13 |
5176 | Fiverr.com Full Accounts Takeover – A Vulnerability Puts $50 Million Company At Risk |
CSRF |
Fiverr |
Mohamed A. Baset |
Bug Bounty | 2016-05-13 | 2023-06-13 |
5172 | When your privacy disclosure is a “feature” not a “bug” – Badoo & HotorNot failure! |
Information disclosure |
Badoo
Hot Or Not |
Mohamed A. Baset |
Bug Bounty | 2016-05-17 | 2023-06-13 |
5171 | Microsoft Yammer Clickjacking – Exploiting HTML5 Security Features |
Clickjacking |
Microsoft |
Mohamed A. Baset |
Bug Bounty | 2016-05-18 | 2023-06-13 |
5169 | RunKeeper Stored XSS Vulnerability – Where worms are able to run too! |
Stored XSS
CSRF |
RunKeeper |
Mohamed A. Baset |
Bug Bounty | 2016-06-06 | 2023-06-13 |
5162 | TopCoder.com Vulnerabilities – A tail of site-wide bugs leads to accounts compromise & payments hijacking |
CSRF
Account takeover |
Topcoder.com |
Mohamed A. Baset |
Bug Bounty | 2016-06-28 | 2023-06-13 |
5154 | BMW Vulnerabilities – Hijack Cars ConnectedDrive™ Service! |
Clickjacking
CSRF |
BMW |
Mohamed A. Baset |
Bug Bounty | 2016-07-24 | 2023-06-13 |
5059 | Godaddy XSS affects parked domains redirector/processor! |
Reflected XSS |
GoDaddy |
Mohamed A. Baset |
Bug Bounty | 2017-06-11 | 2023-06-13 |
5058 | Vulnerability in Metasploit Project aka CVE-2017-5244 |
CSRF |
Rapid7 |
Mohamed A. Baset |
Bug Bounty | 2017-06-12 | 2023-06-13 |
5049 | CVE-2017-10711: Reflected XSS vulnerability in SimpleRisk – Open Source Risk Management System |
Reflected XSS |
SimpleRisk |
Mohamed A. Baset |
Bug Bounty | 2017-06-28 | 2023-06-13 |
5046 | OpenProject Session Management Security Vulnerability aka CVE-2017-11667 |
Session management issue |
OpenProject |
Mohamed A. Baset |
Bug Bounty | 2017-06-30 | 2023-06-13 |
4845 | Re-dressing Instagram – Leaking Application Tokens via Instagram ClickJacking Vulnerability! |
Clickjacking |
Meta / Facebook |
Mohamed A. Baset |
Bug Bounty | 2018-02-25 | 2023-06-13 |
4844 | The 2.5mins or 2.5k$ hawk-eye bug – A Facebook Pages Admins Disclosure Vulnerability! |
Information disclosure |
Meta / Facebook |
Mohamed A. Baset |
Bug Bounty | 2018-02-25 | 2023-06-13 |
4807 | Hijacking User’s Private Information access_token from Microsoft Office360 facebook App |
Logic flaw |
Microsoft |
Mohamed A. Baset |
Bug Bounty | 2018-04-13 | 2023-06-13 |
4771 | Asus Control Center – An Information Disclosure and a database connection Clear-Text password leakage Vulnerability |
Authorization flaw
Information disclosure |
Asus |
Mohamed A. Baset |
Bug Bounty | 2018-05-08 | 2023-06-13 |