4899 | RCE Vulnerabilite in Yahoo Subdomain! ( Yahoo! RCE via Spring Engine SSTI ) By tghawkins |
RCE |
Yahoo! / Verizon Media |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2018-01-05 | 2023-06-13 |
4889 | Reflected File Download ( RFD ) in www.Google.com |
Reflected File Download |
Google |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2018-01-18 | 2023-06-13 |
4883 | Reflected XSS + Possible Server Side Template Injection in HubSpot CMS ( All Websites Uses HubSpot was affected ) |
Reflected XSS |
HubSpot |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2018-01-24 | 2023-06-13 |
4827 | Reflected XSS Moogaloop SWF ( Version < 6.2.x ) |
Flash XSS
Reflected XSS |
Vimeo |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2018-03-26 | 2023-06-13 |
4822 | XSS In sports.tw.campaign.yahoo.net |
Reflected XSS |
Yahoo! / Verizon Media |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2018-03-31 | 2023-06-13 |
4821 | XSS in Yahoo Subdomain |
Flash XSS |
Yahoo! / Verizon Media |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2018-03-31 | 2023-06-13 |
4820 | My Best Small Report Bounty Report in Private Program ( Django REST framework Admin Login ByPass ) |
SQL injection
Authentication bypass
Account takeover |
NA |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2018-04-01 | 2023-06-13 |
4815 | Link injection on 2 Twitter Subdomain |
Hyperlink injection |
Twitter |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2018-04-05 | 2023-06-13 |
4813 | Reflected XSS on www.zomato.com By Mustafa Hasan |
Reflected XSS |
Zomato |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2018-04-07 | 2023-06-13 |
4746 | Reflected XSS in Yahoo Subdomain ( hk.movies.yahoo.com ) |
Reflected XSS |
Yahoo! / Verizon Media |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2018-05-30 | 2023-06-13 |
4665 | Shipt Subdomain TakeOver via HeroKu ( test.shipt.com ) |
Subdomain takeover |
Shipt |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2018-08-01 | 2023-06-13 |
4647 | My Disclosed Report about Basic auth Api details at Reverb.com |
Information disclosure |
Reverb |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2018-08-09 | 2023-06-13 |
4620 | Reflected Swf XSS at ( https://plugins.svn.wordpress.org ) |
Flash XSS
Reflected XSS |
WordPress |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2018-09-07 | 2023-06-13 |
4616 | Reflected XSS in Django REST Framework Api at MapBox Subdomain |
Reflected XSS |
Mapbox |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2018-08-29 | 2023-06-13 |
4558 | Subdomain Takeover via Shopify Vendor ( blog.exchangemarketplace.com ) with Steps |
Subdomain takeover |
Shopify |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2018-10-01 | 2023-06-13 |
4306 | [SSRF] Server Side Request Forgery in a private Program developers.example.com |
SSRF |
NA |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2019-02-14 | 2023-06-13 |
4303 | Souq.com Subdomain Takeover via jazzhr.com service |
Subdomain takeover |
Souq.com |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2019-02-15 | 2023-06-13 |
4302 | Subdomain Takeover via HubSpot |
Subdomain takeover |
NA |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2019-02-15 | 2023-06-13 |
4299 | Subdomain Takeover via Wufoo Service in a Private Program |
Subdomain takeover |
NA |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2019-02-16 | 2023-06-13 |
4294 | 2 Subdomains Takeover via Unbounce in a Private Program |
Subdomain takeover |
NA |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2019-02-18 | 2023-06-13 |
4283 | Subdomain Misconfiguration lead to AWS S3 Buckets Reader |
Subdomain takeover |
NA |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2019-02-22 | 2023-06-13 |
4276 | [Still work] Redirect Yahoo Subdomain XSS Reflected from americangreetings.com |
Reflected XSS |
Yahoo! / Verizon Media |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2019-02-26 | 2023-06-13 |
4205 | [RCE] Remote code execution at api.PrivateProgram.com (CVE-2017-5638) |
RCE |
NA |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2019-04-12 | 2023-06-13 |
4009 | Old GitHub Profile Takeover! |
Github account takeover |
NA |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2019-07-28 | 2023-06-13 |
4006 | SQL Injection in private-site.com/login.php |
SQL injection |
NA |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2019-07-30 | 2023-06-13 |