5071 | Android Browser All Versions - Address Bar Spoofing Vulnerability - CVE-2015-3830 |
Address Bar Spoofing |
Google |
Rafay Baloch (@rafaybaloch) |
Bug Bounty | 2017-06-01 | 2023-06-13 |
5041 | Medium Content Spoofing Leads to XSS |
Content spoofing
Stored XSS |
Medium |
Abdullah Hussam (@Abdulahhusam) |
Bug Bounty | 2017-07-08 | 2023-06-13 |
4998 | Bypassing Rate Limit Protection by spoofing originating IP |
Bruteforce |
NA |
Arbaz Hussain (@ArbazKiraak) |
Bug Bounty | 2017-08-30 | 2023-06-13 |
4793 | Google Bug: Posting on groups as any user’s behalf |
Email spoofing |
Google |
ssid (@newp_th) |
Bug Bounty | 2018-04-18 | 2023-06-13 |
4654 | FakesApp: A Vulnerability in WhatsApp |
Content spoofing
Authorization flaw
Privacy issue |
Meta / Facebook |
Dikla Barda |
Bug Bounty | 2018-08-07 | 2023-06-13 |
4648 | This is how can I spoof ANY Sentry.Io log infinitely and create fake error-logs |
Content spoofing |
HackerOne
Sentry |
Carlos Daniel Giovanella |
Bug Bounty | 2018-08-09 | 2023-06-13 |
4595 | Apple Safari & Microsoft Edge Browser Address Bar Spoofing - Writeup |
Address Bar Spoofing |
Microsoft
Apple |
Rafay Baloch (@rafaybaloch) |
Bug Bounty | 2018-09-10 | 2023-06-13 |
4561 | IDOR, Content Spoofing and Url Redirection via unsubscribe email in Confluent |
IDOR
Content spoofing
Open redirect |
Confluent |
Divyanshu Shukla (@justm0rph3u5) |
Bug Bounty | 2018-09-28 | 2023-06-13 |
4472 | Spoofing file extensions on HackerOne |
Unrestricted file upload |
HackerOne |
Anurag Jain (@csanuragjain) |
Bug Bounty | 2018-11-16 | 2023-06-13 |
4215 | Email content spoofing at IKEA.com |
Email content spoofing |
Ikea |
Jonathan Bouman (@JonathanBouman) |
Bug Bounty | 2019-04-06 | 2023-06-13 |
4167 | From NA to $3000 : Facebook’s URL spoofing vulnerability |
URL spoofing |
Meta / Facebook |
Rahul Kankrale (@RahulKankrale) |
Bug Bounty | 2019-04-30 | 2023-06-13 |
3950 | Address bar spoofing in Firefox Lite for Android ...and the idiocy that followed |
Address Bar Spoofing
URL spoofing |
Mozilla |
Piyush Raj (@0x48piraj) |
Bug Bounty | 2019-08-01 | 2023-06-13 |
3636 | Discord embed spoofing |
Phishing |
Discord |
DarkMatterMatt |
Bug Bounty | 2020-03-02 | 2023-06-13 |
3427 | IP-in-IP protocol routes arbitrary traffic by default |
DoS
Spoofing |
Internet Bug Bounty |
yannayl (@Yannayli) |
Bug Bounty | 2020-06-02 | 2023-06-13 |
3215 | How I was able to send Authentic Emails as others — Google VRP [Resolved] |
Logic flaw
HTML injection
Email spoofing
Open mail relay |
Google |
Sriram Kesavan (@sriramoffcl) |
Bug Bounty | 2020-08-15 | 2023-06-13 |
3200 | A perfect duplicate or how to send an email with a spoofed invoice’s content |
Email spoofing
Open mail relay
Missing authentication |
NA |
Mateusz Olejarka (@molejarka) |
Bug Bounty | 2020-08-19 | 2023-06-13 |
3090 | Multiple Address Bar Spoofing Vulnerabilities In Mobile Browsers |
Authentication bypass
JWT
Android |
NHS COVID-19 App |
James Sanderson (@zofrex) |
Bug Bounty | 2020-10-20 | 2023-06-13 |
3089 | Multiple Address Bar Spoofing Vulnerabilities In Mobile Browsers |
Address Bar Spoofing |
Yandex
Apple
Opera |
Rafay Baloch (@rafaybaloch) |
Bug Bounty | 2020-10-20 | 2023-06-13 |
3069 | Rate Limit Bypassing Allowing Identity Spoofing |
Rate limiting bypass
OTP bypass |
NA |
Mohamed Talaat (@T4144t) |
Bug Bounty | 2020-10-29 | 2023-06-13 |
2981 | "Important, Spoofing" - zero-click, wormable, cross-platform remote code execution in Microsoft Teams |
RCE
Stored XSS
CSP bypass
CSTI |
Microsoft |
Oskars Vegeris |
Bug Bounty | 2020-12-07 | 2023-06-13 |
2947 | Full Address Bar Spoofing On Opera Mini Android |
Address Bar Spoofing |
Opera
Google |
Piyush Raj ~ Rex (@0x48piraj) |
Bug Bounty | 2020-12-26 | 2023-06-13 |
2923 | Nick%27s infrequently updated blog |
WAF bypass
IP spoofing |
Cloudflare |
Nick Booher |
Bug Bounty | 2021-01-06 | 2023-06-13 |
2845 | Spoofing and Attacking With Skype |
Spoofing |
Microsoft |
mr.d0x (@mrd0x) |
Bug Bounty | 2021-02-02 | 2023-06-13 |
2746 | Microsoft Edge Browser For IOS - Address Bar Spoofing Vulnerability |
Address Bar Spoofing |
Microsoft |
Rafay Baloch (@rafaybaloch) |
Bug Bounty | 2021-03-02 | 2023-06-13 |
2529 | Content Spoofing Vulnerability in Shibboleth Service Provider |
Content spoofing |
NA |
Toni Huttunen |
Bug Bounty | 2021-05-24 | 2023-06-13 |