2203 | A fever Worth 750$- [Accessing Private Projects ] |
IDOR
Information disclosure |
Mozilla |
Shakti Mohanty (@3ncryptSaan) |
Bug Bounty | 2021-09-22 | 2023-06-13 |
2135 | Unauthorized access to any Facebook user’s draft profile picture frames |
IDOR |
Meta / Facebook |
Sandeep Hodkasia (@sandeephodkasia) |
Bug Bounty | 2021-10-22 | 2023-06-13 |
2125 | A 7500$ Google sites IDOR |
IDOR |
Google |
Jalal (@r0ckin_) |
Bug Bounty | 2021-10-24 | 2023-06-13 |
2118 | Unauthorized access to any user’s account. |
IDOR
Authentication bypass
Account takeover |
NA |
vikram naidu (@ImVikram7msd) |
Bug Bounty | 2021-10-28 | 2023-06-13 |
2108 | Never Give Up — Story of Hacking Dutch Government and Earning that Dutch Swag. |
IDOR |
Dutch Government |
BabaBounty (@Rohan96867358) |
Bug Bounty | 2021-10-31 | 2023-06-13 |
2103 | HacktoberFest2k21 vulnerability: How users metadata can be changed via Auth JWT tokens leaking from waybackurls |
IDOR |
DigitalOcean |
Anurag__Verma |
Bug Bounty | 2021-11-04 | 2023-06-13 |
2099 | 4 Crits in 48 hours: Unicorn Programs |
Privilege escalation
Information disclosure
IDOR |
NA |
Monke (@pmofcats) |
Bug Bounty | 2021-11-06 | 2023-06-13 |
2094 | Becoming A Super Admin In Someone Elses Gsuite Organization And Taking It Over |
IDOR |
Google |
Cam (@secretlyhidden1) |
Bug Bounty | 2021-11-09 | 2023-06-13 |
2086 | From URL dumps digging to IDOR , BAC, Massive Phishing in Udemy |
Broken Access Control
Information disclosure
IDOR
HTML injection |
Udemy |
Mostafa Mamdoh |
Bug Bounty | 2021-11-12 | 2023-06-13 |
2085 | chaining improper authentication to idor and no rate limit for mass account takeover |
Account takeover
Lack of rate limiting
CSRF
IDOR |
NA |
mohit (@mohit29295572) |
Bug Bounty | 2021-11-12 | 2023-06-13 |
2083 | Privilege Escalation, worth of €300 |
Broken Access Control
IDOR
Privilege escalation |
NA |
Hemant Kumar |
Bug Bounty | 2021-11-12 | 2023-06-13 |
2023 | This is how i was able to See and Delete your Private Facebook Portal photos |
IDOR |
Meta / Facebook |
Abhishek Pathak (@pathleax) |
Bug Bounty | 2021-12-04 | 2023-06-13 |
2022 | Accidental IDOR in eLearnSecurity to Knowing Your Address and Cert You Bought. |
IDOR |
INE |
Anugrah SR (@cyph3r_asr) |
Bug Bounty | 2021-12-05 | 2023-06-13 |
2018 | How I was able to change Reddit acquired Dubsmash%27s music library sound tracks%27 titles |
IDOR |
Reddit |
Sandeep Hodkasia (@sandeephodkasia) |
Bug Bounty | 2021-12-07 | 2023-06-13 |
1995 | Gumtree – leaking your data and not really listening |
IDOR |
Gumtree |
Alan Monie (@AlanMonie) |
Bug Bounty | 2021-12-15 | 2023-06-13 |
1993 | Broken Access Control |
IDOR |
Microsoft |
Meareg |
Bug Bounty | 2021-12-16 | 2023-06-13 |
1987 | How I was able to reveal page admin of almost any page on Facebook |
IDOR |
Meta / Facebook |
Sudip Shah |
Bug Bounty | 2021-12-20 | 2023-06-13 |
1973 | Massive Users Account Takeovers(Chaining Vulnerabilities to IDOR)😲 |
Authentication bypass
IDOR
Lack of rate limiting |
NA |
Anurag__Verma |
Bug Bounty | 2021-12-25 | 2023-06-13 |
1955 | Bug Hunting Journey of 2021 |
Stored XSS
Open redirect
Token leak
CSRF
Logic flaw
Information disclosure
IDOR
Account takeover |
NA |
Sudhanshu Rajbhar (@sudhanshur705) |
Bug Bounty | 2021-12-31 | 2023-06-13 |
1951 | A tale of zero click account takeover |
Account takeover
IDOR |
NA |
Veshraj Ghimire (@GhimireVeshraj) |
Bug Bounty | 2022-01-01 | 2023-06-13 |
1946 | IDOR leads to leak Private Details |
IDOR |
NA |
annonymous |
Bug Bounty | 2022-01-03 | 2023-06-13 |
1941 | thisclosed_#1 - Full Account Takeover of ANY user via Insecure Direct Object Reference (IDOR) on reset password functionality |
IDOR
Password reset
Account takeover |
NA |
Samuele Gugliotta (@indevi0us) |
Bug Bounty | 2022-01-04 | 2023-06-13 |
1937 | How I was able to spoof any Instagram username on Instagram shop |
IDOR |
Meta / Facebook |
Nawaf Alkhaldi (@nvmeeet) |
Bug Bounty | 2022-01-06 | 2023-06-13 |
1920 | XSS Filter Evasion + IDOR |
XSS
IDOR |
NA |
JM Sanchez / 0xEchidonut (@jmrcsnchz) |
Bug Bounty | 2022-01-13 | 2023-06-13 |
1864 | IDOR vulnerability on invoice and weak password reset leads to account take over |
IDOR
Password reset
Account takeover
Payment tampering
Logic flaw |
NA |
Damaidec |
Bug Bounty | 2022-02-01 | 2023-06-13 |