4621 | How i found a 1500$ worth Deserialization vulnerability |
Misconfigured JSF ViewState
Insecure deserialization |
NA |
Ashish Kunwar (@D0rkerDevil) |
Bug Bounty | 2018-08-28 | 2023-06-13 |
4618 | A Infinite Loop Story. |
DoS |
NA |
Ashish Kunwar (@D0rkerDevil) |
Bug Bounty | 2018-08-29 | 2023-06-13 |
4617 | Finding hidden gems vol. 2: REAMDE.md, the story of a bit too helpful readme file |
Information disclosure |
NA |
Mateusz Olejarka (@molejarka) |
Bug Bounty | 2018-08-29 | 2023-06-13 |
4613 | https://medium.com/@mahitman1/i-own-your-customers-22e965761abd |
Information disclosure
Hardcoded credentials
AWS misconfiguration |
NA |
Muhammad Abdullah |
Bug Bounty | 2018-09-01 | 2023-06-13 |
4609 | P1 Vulnerability in 60 seconds |
Information disclosure
File disclosure |
NA |
Wh11teW0lf (@wh11tew0lf) |
Bug Bounty | 2018-09-05 | 2023-06-13 |
4608 | How I could download the source code of an Indian e-commerce website!! |
File disclosure
Source code disclosure |
NA |
Minali Arora (@AroraMinali) |
Bug Bounty | 2018-09-05 | 2023-06-13 |
4606 | Simple Login Brute Force / Current Password Requirement Bypass |
IDOR
Account takeover
Bruteforce |
NA |
Mandeep Jadon (@1337tr0lls) |
Bug Bounty | 2018-09-07 | 2023-06-13 |
4605 | Write-up - Love story, from closed as informative to $3,500 USD, XSS stored in Yahoo! iOS MaiL app |
Stored XSS |
Yahoo! / Verizon Media |
Omar Espino (@omespino) |
Bug Bounty | 2018-09-07 | 2023-06-13 |
4604 | RCE Unsecure Jenkins Instance | Bug Bounty POC |
RCE
Exposed Jenkins instance |
NA |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2018-09-07 | 2023-06-13 |
4599 | How I find Open-Redirect Vulnerability in redacted.com (One of the top online payment processing service website) |
Open redirect |
NA |
Muhammad Asim Shahzad (@protector47) |
Bug Bounty | 2018-09-09 | 2023-06-13 |
4597 | Making the Facebook app more secure - $8500 bounty |
Open redirect |
Meta / Facebook |
Ashley King (@AshleyKingUK) |
Bug Bounty | 2018-09-09 | 2023-06-13 |
4596 | Stored XSS Vulnerability in H1C Private site |
Stored XSS |
NA |
Anas Mahmood (@AnasIsHere) |
Bug Bounty | 2018-09-09 | 2023-06-13 |
4595 | Apple Safari & Microsoft Edge Browser Address Bar Spoofing - Writeup |
Address Bar Spoofing |
Microsoft
Apple |
Rafay Baloch (@rafaybaloch) |
Bug Bounty | 2018-09-10 | 2023-06-13 |
4590 | Open-Redirect Vulnerability in udacity.com |
Open redirect |
Udacity |
Anil Tom (mr_4nk) |
Bug Bounty | 2018-09-11 | 2023-06-13 |
4586 | How I hijacked your account when you opened my cat picture |
Logout CSRF |
NA |
Matti Bijnens (@MattiBijnens) |
Bug Bounty | 2018-09-14 | 2023-06-13 |
4585 | Persistent Cross-Site Scripting on redacted worth $2,000 |
Stored XSS |
NA |
Muhammad Asim Shahzad (@protector47) |
Bug Bounty | 2018-09-15 | 2023-06-13 |
4583 | User Account takeover in India’s largest digital business company |
Account takeover
OTP bypass |
NA |
Minali Arora (@AroraMinali) |
Bug Bounty | 2018-09-16 | 2023-06-13 |
4580 | Chain The Bugs to Pwn an Organisation ( LFI + Unrestricted File Upload = Remote Code Execution ) |
LFI
Unrestricted file upload
RCE |
NA |
Armaan Pathan (@armaancrockroax) |
Bug Bounty | 2018-09-18 | 2023-06-13 |
4577 | Bypassing Authentication Using Javascript Debugger. |
Authentication bypass |
NA |
Mohit Dabas (@mohitdabas08) |
Bug Bounty | 2018-09-18 | 2023-06-13 |
4572 | R-XSS -> CSRF bypass to account takeover/ |
Reflected XSS
CSRF |
NA |
Nirmal Dahal (@TheNittam) |
Bug Bounty | 2018-09-21 | 2023-06-13 |
4569 | Subdomain Takeover via Unsecured S3 Bucket Connected to the Website |
Subdomain takeover |
NA |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2018-09-24 | 2023-06-13 |
4568 | Weaponizing XSS Attacking Internal System |
Blind XSS |
NA |
Rahul R |
Bug Bounty | 2018-09-25 | 2023-06-13 |
4565 | Arbitrary File Read in one of the largest CRMs |
LFI |
NA |
Richard Clifford (@MantisSTS) |
Bug Bounty | 2018-09-26 | 2023-06-13 |
4564 | Thick Client — Attacking databases the fun/easy way |
Thick client
Credentials sent over unencrypted channel |
NA |
Richard Clifford (@MantisSTS) |
Bug Bounty | 2018-09-26 | 2023-06-13 |
4563 | #BugBounty — From finding Jenkins instance to Command Execution.Secure your Jenkins Instance! |
RCE
Exposed Jenkins instance |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-09-27 | 2023-06-13 |