2394 | Escalating Self-XSS To Stored XSS via Image injection + IDOR |
Self-XSS
Stored XSS
IDOR |
NA |
Demon (@R29k_) |
Bug Bounty | 2021-07-21 | 2023-06-13 |
2378 | Abusing JSON Web Token to steal accounts — 3000$ |
IDOR |
NA |
Filipe Azevedo (@filipaze_) |
Bug Bounty | 2021-07-27 | 2023-06-13 |
2371 | How I found my first IDOR in HackerOne |
IDOR |
NA |
N1GHTMAR3 (@n1ghtmar3_2421) |
Bug Bounty | 2021-07-29 | 2023-06-13 |
2366 | Facebook Vulnerability: Expose Group Member — $3000 |
IDOR |
Meta / Facebook |
Muhammad Sholikhin (@MuhammadLikhin) |
Bug Bounty | 2021-07-30 | 2023-06-13 |
2364 | How I escalate my Self-Stored XSS to Account Takeover with the help of IDOR |
Self-XSS
IDOR
Account takeover |
HackerEarth |
Jefferson Gonzales (@gonzxph) |
Bug Bounty | 2021-07-31 | 2023-06-13 |
2355 | Privilege Escalation | stealing user’s point | Bugcrowd |
IDOR
Privilege escalation |
NA |
Abhind Abhi |
Bug Bounty | 2021-08-02 | 2023-06-13 |
2354 | ~/BugBounty/IDOR/”How I was able to exfiltrate any user’s credit coupons” |
IDOR |
NA |
Jai Sharma (@ja1sharma) |
Bug Bounty | 2021-08-02 | 2023-06-13 |
2337 | What is BOLA? 3-digit bounty from Topcoder ($$$) |
IDOR |
Topcoder |
can1337 (@canmustdie) |
Bug Bounty | 2021-08-09 | 2023-06-13 |
2336 | Fuzzing + IDOR = Admin TakeOver |
IDOR
Account takeover |
NA |
Gonzalo Carrasco (@0xCGonzalo) |
Bug Bounty | 2021-08-09 | 2023-06-13 |
2329 | How I found read/write access to the personal data of 3 million users of an E-commerce website? |
IDOR |
NA |
Prashant Singh / SecGeek_one0one |
Bug Bounty | 2021-08-13 | 2023-06-13 |
2313 | Account Takeover via Access Token Leakage |
IDOR
Information disclosure
Account takeover |
NA |
Tuhin Bose (@tuhin1729_) |
Bug Bounty | 2021-08-19 | 2023-06-13 |
2307 | MonkeyType.com Stored Cross-Site Scripting |
Stored XSS
Authentication bypass
IDOR |
MonkeyType.com |
Tyle Butler (@tbutler0x90) |
Bug Bounty | 2021-08-22 | 2023-06-13 |
2306 | Story Of Unexpected Bugs |
IDOR
XSS |
NA |
Neh Patel (@thecyberneh) |
Bug Bounty | 2021-08-22 | 2023-06-13 |
2301 | How i was able to steal private files of any user on Larksuite |
IDOR |
NA |
Imran Nissar (@Imrannissar3) |
Bug Bounty | 2021-08-24 | 2023-06-13 |
2295 | Retrieve Archived Stories Of Any Public Instagram Account. |
IDOR
GraphQL |
Meta / Facebook |
Naveen |
Bug Bounty | 2021-08-25 | 2023-06-13 |
2290 | Oauth client secret leak and possible IDOR leading to PII Disclosure |
IDOR
OAuth
Information disclosure |
NA |
Monke (@pmofcats) |
Bug Bounty | 2021-08-26 | 2023-06-13 |
2287 | How I Scored 2K Bounty via an IDOR |
IDOR |
Mail.ru |
Sicksec (@OriginalSicksec) |
Bug Bounty | 2021-08-27 | 2023-06-13 |
2277 | Two account takeover bugs worth $4300 🎁 |
Account takeover
Privilege escalation
403 bypass
IDOR |
NA |
Usama Varikkottil (@usama_dev) |
Bug Bounty | 2021-08-29 | 2023-06-13 |
2266 | Hacking Dutch Government For a lousy T-shirt |
IDOR
Information disclosure |
Dutch Government |
Veshraj Ghimire (@GhimireVeshraj) |
Bug Bounty | 2021-09-02 | 2023-06-13 |
2263 | Breaking Application’s Logic to DOS Attack |
IDOR
DoS |
NA |
Abhijeet Singh (@abhiunix) |
Bug Bounty | 2021-09-02 | 2023-06-13 |
2256 | IDOR Vulnerability In GraphQL Api On Website |
IDOR
GraphQL |
NA |
Aidil Arief |
Bug Bounty | 2021-09-03 | 2023-06-13 |
2247 | 2 CSRF 1 IDOR on Google Marketing Platform |
IDOR
CSRF |
Google |
apapedulimu / Nosa Shandy (@LocalHost31337) |
Bug Bounty | 2021-09-06 | 2023-06-13 |
2229 | Exposing Millions of IRCTC Passengers%27 ticket details. |
IDOR |
IRCTC |
Renganathan (@IamRenganathan) |
Bug Bounty | 2021-09-12 | 2023-06-13 |
2222 | How I hacked worldwide Tiktok users |
IDOR |
TikTok |
s3c (@s3c_krd) |
Bug Bounty | 2021-09-15 | 2023-06-13 |
2216 | A Small Tale of Account Takeover … |
IDOR
Account takeover |
NA |
Saugat Pokharel (@saugatpk5) |
Bug Bounty | 2021-09-16 | 2023-06-13 |