5273 | Multiple Open URL Redirection Vulnerability on Facebook worth $1500 |
Open redirect |
Meta / Facebook |
Arul Kumar (@ArulVaiyapuri) |
Bug Bounty | 2022-08-05 | 2023-06-13 |
5255 | How I hacked Github again. |
Open redirect
Account takeover
Information disclosure |
GitHub |
Egor Homakov (@homakov) |
Bug Bounty | 2014-02-07 | 2023-06-13 |
5231 | Malicious redirect on mailroom.prezi.com |
Open redirect |
Prezi |
Patrik Fehrenbach (@ITSecurityguard) |
Bug Bounty | 2014-12-10 | 2023-06-13 |
5229 | How I discovered a 1000$ open redirect in Facebook |
Open redirect |
Meta / Facebook |
Yassine Aboukir (@Yassineaboukir) |
Bug Bounty | 2014-12-30 | 2023-06-13 |
5223 | Google.com – Mobile Feedback URL Redirect Regex/Validation Flaw |
Open redirect |
Google |
Brett Buerhaus (@bbuerhaus) |
Bug Bounty | 2015-02-03 | 2023-06-13 |
5208 | Open Redirect in Linkedin and Yahoo |
Open redirect |
LinkedIn
Yahoo! / Verizon Media |
Vitor “r0t” Oliveira (@r0t1v) |
Bug Bounty | 2015-09-24 | 2023-06-13 |
5130 | Open Redirect Scanner with Uber.com |
Open redirect |
Uber |
Ak1T4 (@akita_zen) |
Bug Bounty | 2016-10-10 | 2023-06-13 |
5091 | Airbnb – Chaining Third-Party Open Redirect into Server-Side Request Forgery (SSRF) via LivePerson Chat |
Open redirect
SSRF
Path traversal |
Airbnb |
Brett Buerhaus (@bbuerhaus) |
Bug Bounty | 2017-03-09 | 2023-06-13 |
5087 | Bypassing Safe Links in Exchange Online Advanced Threat Protection |
Open redirect |
Microsoft |
Mikail Tunç (@emtunc) |
Bug Bounty | 2017-03-16 | 2023-06-13 |
5055 | Authentication bypass on Airbnb via OAuth tokens theft |
OAuth
Login CSRF
Open redirect
Authentication bypass |
Airbnb |
Arne Swinnen (@ArneSwinnen) |
Bug Bounty | 2017-06-22 | 2023-06-13 |
5021 | pen Redirect In Flock | My First Swag pack |
Open redirect |
Flock |
Noman Shaikh (@nomanali181) |
Bug Bounty | 2017-07-24 | 2023-06-13 |
5019 | Rolling around and Bypassing Facebook’s Linkshim protection on iOS |
Open redirect |
Meta / Facebook |
Seif Elsallamy (@seifelsallamy) |
Bug Bounty | 2017-07-26 | 2023-06-13 |
5006 | Chain the vulnerabilities and take your report impact on the moon (CSRF to HTML INJECTION which results OPEN REDIRECT and could steal USER CREDENTIALS) |
CSRF
HTML injection |
Legal Robot |
Armaan Pathan (@armaancrockroax) |
Bug Bounty | 2017-08-12 | 2023-06-13 |
4987 | Reflective XSS and Open Redirect on Indeed.com subdomain |
Reflected XSS
Open redirect |
Indeed |
Syntax Error (@SYNTAXERRORBA) |
Bug Bounty | 2017-09-04 | 2023-06-13 |
4986 | Phishing with history.back() open redirect |
Open redirect |
NA |
Brian Hyde (@0xHyde) |
Bug Bounty | 2017-09-09 | 2023-06-13 |
4944 | Multiple Intel Vulnerabilities-Adesh Kolte |
Open redirect
Directory listing |
Intel |
Adesh Nandkishor kolte (@AdeshKolte) |
Bug Bounty | 2017-11-05 | 2023-06-13 |
4931 | Transforming a Domain into the Matrix (an open redirect story) |
Open redirect |
NA |
Ak1T4 (@akita_zen) |
Bug Bounty | 2017-11-17 | 2023-06-13 |
4928 | Amazon Bypass Open Redirect |
Open redirect |
Amazon |
Honc (@honcbb) |
Bug Bounty | 2017-11-19 | 2023-06-13 |
4925 | Story of bypassing Referer Header to make open redirect |
Open redirect |
NA |
Mohammed Eldeeb (@malcolmx0x) |
Bug Bounty | 2017-11-22 | 2023-06-13 |
4884 | #BugBounty @ Linkedln-How I was able to bypass Open Redirection Protection |
Open redirect |
LinkedIn |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-01-24 | 2023-06-13 |
4806 | How I bypassed Ebay process on redirect |
Open redirect |
Ebay |
Mohamed Sayed (@FlEx0Geek) |
Bug Bounty | 2018-04-13 | 2023-06-13 |
4788 | Three Cases, Three Open Redirect Bypasses |
Open redirect |
NA |
Mmohammed Eldeeb (@malcolmx0x) |
Bug Bounty | 2018-04-22 | 2023-06-13 |
4783 | How I earned 60K+ from private program |
Open redirect
Subdomain takeover
XSS
HTTP parameter pollution |
NA |
Siva Krishna Samireddi (@le4rner) |
Bug Bounty | 2018-04-25 | 2023-06-13 |
4777 | Story Of a Stored XSS Bypass |
Open redirect |
Zerocopter |
Prial Islam Khan (@prial261) |
Bug Bounty | 2018-04-30 | 2023-06-13 |
4728 | Unvalidated Open Redirect Bol.com |
Open redirect |
Bol.com |
Jonathan Bouman (@JonathanBouman) |
Bug Bounty | 2018-06-12 | 2023-06-13 |