5256 | Google Sites: A Tale of Five Vulnerabilities |
XSS
LFI
HTML injection |
Google |
Bitquark (@bitquark) |
Bug Bounty | 2013-12-30 | 2023-06-13 |
5006 | Chain the vulnerabilities and take your report impact on the moon (CSRF to HTML INJECTION which results OPEN REDIRECT and could steal USER CREDENTIALS) |
CSRF
HTML injection |
Legal Robot |
Armaan Pathan (@armaancrockroax) |
Bug Bounty | 2017-08-12 | 2023-06-13 |
4901 | "F**k you Thomas" - ToyTalk bug bounty writeup |
Authentication bypass
HTML injection |
ToyTalk |
Jahmel Harris |
Bug Bounty | 2018-01-04 | 2023-06-13 |
4817 | How I caught Multiple vulnerabilities in Udemy.com, But not rewarded for serious XSS vulnerability :( |
XSS
HTML injection |
Udemy |
Satyendra Shrivastava |
Bug Bounty | 2018-04-05 | 2023-06-13 |
4805 | How I hacked companies related to the crypto currency and earned $60,000 |
Authorization flaw
CSRF
IDOR
Stored XSS
HTML injection |
okex.com
livecoin.net |
Max (@0xw2w) |
Bug Bounty | 2018-04-14 | 2023-06-13 |
4653 | Sending out phishing e-mails from @microsoft.com |
HTML injection |
Microsoft |
SI9INT (@si9int) |
Bug Bounty | 2018-08-07 | 2023-06-13 |
4426 | My first bug bounty writeup |
XSS
HTML injection |
Indeed |
Sampanna Chimoriya |
Bug Bounty | 2018-12-10 | 2023-06-13 |
4372 | When Cookie Hijacking + HTML Injection become dangerous |
Cookie hijacking
HTML injection |
NA |
Daniel V. (@d4niel_v) |
Bug Bounty | 2019-01-07 | 2023-06-13 |
4252 | WordPress 5.1 CSRF to Remote Code Execution |
CSRF
RCE
HTML injection |
WordPress |
Simon Scannell (@scannell_simon) |
Bug Bounty | 2019-03-13 | 2023-06-13 |
4206 | Unauthenticated Account Takeover Through HTTP Leak |
HTML injection
HTTP Leak
Account takeover |
NA |
Nikhil (niks) (@niksthehacker) |
Bug Bounty | 2019-04-11 | 2023-06-13 |
4147 | A base64 encoded parameter. |
HTML injection |
NA |
Navneet (@na5n33t) |
Bug Bounty | 2019-05-19 | 2023-06-13 |
4022 | Not a fancy bug, just HTML Injection in Clause - clause.io (Write Up) |
HTML injection |
Clause |
Evan Ricafort (@evanricafort) |
Bug Bounty | 2019-07-21 | 2023-06-13 |
3796 | HTML Injection to XSS bypass in [REDACTED.com] |
Reflected XSS |
NA |
Evan Ricafort (@evanricafort) |
Bug Bounty | 2019-12-07 | 2023-06-13 |
3777 | Stored Iframe Injection + CSRF = Account Takeover 😎😎 |
HTML injection
CSRF |
NA |
Rounak Dhadiwal (@XploiteR_D) |
Bug Bounty | 2019-12-16 | 2023-06-13 |
3744 | Exploiting HTML Injection in Email |
HTML injection |
NA |
Shuaib Oladigbolu (@_sawzeeyy) |
Bug Bounty | 2019-12-31 | 2023-06-13 |
3733 | HTML Injection(Unique Exploitation) |
HTML injection |
NA |
Pratik Yadav (@PratikY9967) |
Bug Bounty | 2020-01-07 | 2023-06-13 |
3729 | Hunting Good Bugs with only <HTML> |
Open redirect
HTML injection
SSRF |
NA |
Ak1T4 (@akita_zen) |
Bug Bounty | 2020-01-10 | 2023-06-13 |
3659 | My First Bounty From Google. |
Self-XSS
HTML injection |
Google |
Syahri Ramadan (@adonkidz7) |
Bug Bounty | 2020-02-18 | 2023-06-13 |
3624 | Google Ads Self-XSS & Html Injection $5000 |
Self-XSS
HTML injection |
Google |
Syahri Ramadan (@adonkidz7) |
Bug Bounty | 2020-03-07 | 2023-06-13 |
3618 | Got Easiest Bounty with HTML injection via email confirmation! |
HTML injection |
NA |
Shaurya Sharma (@ShauryaSharma05) |
Bug Bounty | 2020-03-11 | 2023-06-13 |
3275 | Bug HTML Injection On Tokopedia ! |
HTML injection |
Tokopedia |
jowi |
Bug Bounty | 2020-07-28 | 2023-06-13 |
3215 | How I was able to send Authentic Emails as others — Google VRP [Resolved] |
Logic flaw
HTML injection
Email spoofing
Open mail relay |
Google |
Sriram Kesavan (@sriramoffcl) |
Bug Bounty | 2020-08-15 | 2023-06-13 |
3076 | How i got 250$ in 5 munites using my phone |
HTML injection |
Basecamp |
Abdelkader Mouaz (@hamzadzworm) |
Bug Bounty | 2020-10-26 | 2023-06-13 |
2734 | Stored XSS in Google Ads Android Application— $3133.70 |
Stored XSS
HTML injection |
Google |
Ashish Dhone (@ashketchum_16) |
Bug Bounty | 2021-03-07 | 2023-06-13 |
2672 | XSS in Large Messenger and Payment App - a Shout Out to Parameter Guessing |
XSS
HTML injection |
NA |
Lauritz Holtmann (@_lauritz_) |
Bug Bounty | 2021-04-02 | 2023-06-13 |