4963 | Subdomain Takeover Through Expired Cloudfront Distribution | live.lamborghini.co |
Subdomain takeover |
Lamborghini |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2017-10-10 | 2023-06-13 |
4962 | Exploiting Insecure Cross Origin Resource Sharing ( CORS ) | api.artsy.net |
CORS misconfiguration |
Artsy |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2017-10-10 | 2023-06-13 |
4961 | Bugcrowd’s Domain & Subdomain Takeover vulnerability! |
Subdomain takeover |
Bugcrowd |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2017-10-10 | 2023-06-13 |
4947 | Accessing Localhost via Vhost |
vHost misconfiguration |
NA |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2017-11-04 | 2023-06-13 |
4927 | UBER Wildcard Subdomain Takeover | BugBounty POC |
Subdomain takeover |
Uber |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2017-11-20 | 2023-06-13 |
4911 | Unrestricted File Upload to RCE | Bug Bounty POC |
RCE |
Meta / Facebook |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2017-12-19 | 2023-06-13 |
4766 | How I was able to get subscription of $120/year For Free |
Payment bypass |
WeTransfer |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2018-05-18 | 2023-06-13 |
4604 | RCE Unsecure Jenkins Instance | Bug Bounty POC |
RCE
Exposed Jenkins instance |
NA |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2018-09-07 | 2023-06-13 |
4602 | SQL Injection Vulnerability bootcamp.nutanix.com | Bug Bounty POC |
SQL injection |
Nutanix |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2018-09-08 | 2023-06-13 |
4598 | ZOL Zimbabwe Authentication Bypass to XSS & SQLi Vulnerability – Bug Bounty POC |
XSS
SQL injection |
ZOL Zimbabwe |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2018-09-09 | 2023-06-13 |
4594 | Authentication Bypass Using SQL Injection AutoTrader Webmail – Bug Bounty POC |
SQL injection |
AutoTrader |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2018-09-10 | 2023-06-13 |
4584 | IDOR User Account Takeover By Connecting My Facebook Account with victims Account |
IDOR |
Meta / Facebook |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2018-09-16 | 2023-06-13 |
4569 | Subdomain Takeover via Unsecured S3 Bucket Connected to the Website |
Subdomain takeover |
NA |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2018-09-24 | 2023-06-13 |
4500 | P1 Like a Boss | Information Disclosure via Github leads to Employee Account Takeover | Bug Bounty POC |
Information disclosure |
NA |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2018-11-01 | 2023-06-13 |
3705 | Improper Input Validation | Add Custom Text and URLs In SMS send by Snapchat | Bug Bounty POC |
Parameter tampering |
Meta / Facebook |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2020-01-26 | 2023-06-13 |
3689 | Exploiting Insecure Firebase Database! |
Insecure Firebase database
Android |
NA |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2020-02-04 | 2023-06-13 |
3656 | Hacking SMS API Service Provider of a Company |Android App Static Security Analysis | Bug Bounty POC |
Information disclosure
Hardcoded credentials |
NA |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2020-02-19 | 2023-06-13 |
3571 | Microsoft Apache Solr RCE Velocity Template | Bug Bounty POC |
RCE |
Microsoft |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2020-03-31 | 2023-06-13 |
3355 | Using Inspect Element to Bypass Security restrictions | Bug Bounty POC |
Client-side enforcement of server-side security |
NA |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2020-06-30 | 2023-06-13 |
1778 | Hacking Subscription Plans for free service. |
Payment bypass
OTP bypass |
NA |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2022-02-27 | 2023-06-13 |
179 | How I Manipulated My Rank on the Bugcrowd Platform |
Logic flaw |
Bugcrowd |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2023-04-19 | 2023-06-13 |