5019 | Rolling around and Bypassing Facebook’s Linkshim protection on iOS |
Open redirect |
Meta / Facebook |
Seif Elsallamy (@seifelsallamy) |
Bug Bounty | 2017-07-26 | 2023-06-13 |
5018 | Disabling New Emails From Facebook Without Email Owner Interaction |
Logic flaw
Authorization flaw |
Meta / Facebook |
Zahid Ali |
Bug Bounty | 2017-07-26 | 2023-06-13 |
5017 | How we invented the Tesla DOM DOOM XSS |
DOM XSS |
Tesla |
Detectify Labs |
Bug Bounty | 2017-07-27 | 2023-06-13 |
5016 | Cracking the lens: targeting HTTP%27s hidden attack-surface |
Reflected XSS
SSRF |
Yahoo! / Verizon Media
BT
New Relic |
James Kettle (@albinowax) |
Bug Bounty | 2017-07-27 | 2023-06-13 |
5015 | How I Chained 4 vulnerabilities on GitHub Enterprise, From SSRF Execution Chain to RCE! |
SSRF
RCE
CRLF injection
Insecure deserialization |
GitHub |
Orange Tsai (@orange_8361) |
Bug Bounty | 2017-07-28 | 2023-06-13 |
5014 | Referer Based XSS |
XSS |
NA |
Arbaz Hussain (@ArbazKiraak) |
Bug Bounty | 2017-07-30 | 2023-06-13 |
5013 | How i found massive information disclosure of 1500 famous people |
Information disclosure |
NA |
Valeriy Shevchenko (@Krevetk0Valeriy) |
Bug Bounty | 2017-07-31 | 2023-06-13 |
5012 | Business Logic Vulnerabilities Series: How I became invisible and immune to blocking on Instagram! |
Logic flaw |
Meta / Facebook |
Ali Kabeel |
Bug Bounty | 2017-07-31 | 2023-06-13 |
5011 | XSS Because of wrong Content-type Header |
XSS |
Internshala |
Noman Shaikh (@nomanali181) |
Bug Bounty | 2017-08-04 | 2023-06-13 |
5010 | How to confirm a Google user’s specific email address (Bug Bounty Submission) |
Logic flaw |
Google |
Tom Anthony (@TomAnthonySEO) |
Bug Bounty | 2017-08-09 | 2023-06-13 |
5009 | $10k host header |
Authorization flaw |
Google |
Ezequiel Pereira (@epereiralopez) |
Bug Bounty | 2017-08-10 | 2023-06-13 |
5008 | Getting access to 25k employees details |
Exposed registration page |
NA |
Sahil Ahamad (@ehsahil) |
Bug Bounty | 2017-08-11 | 2023-06-13 |
5007 | Insecure Direct Object Reference In Facebook Events |
IDOR |
Meta / Facebook |
Armaan Pathan (@armaancrockroax) |
Bug Bounty | 2017-08-11 | 2023-06-13 |
5006 | Chain the vulnerabilities and take your report impact on the moon (CSRF to HTML INJECTION which results OPEN REDIRECT and could steal USER CREDENTIALS) |
CSRF
HTML injection |
Legal Robot |
Armaan Pathan (@armaancrockroax) |
Bug Bounty | 2017-08-12 | 2023-06-13 |
5005 | Reflected XSS on www.yahoo.com |
Reflected XSS |
Yahoo! / Verizon Media |
Samuel (@saamux) |
Bug Bounty | 2017-08-12 | 2023-06-13 |
5004 | Accidentally typo to bypass administration access |
Authentication bypass |
NA |
yappare (@yappare) |
Bug Bounty | 2017-08-13 | 2023-06-13 |
5003 | Password Not Provided - Compromising Any Flurry User%27s Account [Yahoo Bug Bounty] |
Authentication flaw
Account takeover |
Yahoo! / Verizon Media |
Jack Cable (@jackhcable) |
Bug Bounty | 2017-08-15 | 2023-06-13 |
5002 | Secure Your Jenkins Instance Or Hackers Will Force You To! (Snapchat’s $5,000 Vulnerability) |
RCE
LFI
Exposed Jenkins instance |
Snapchat |
Ben Sadeghipour (@nahamsec) |
Bug Bounty | 2017-08-22 | 2023-06-13 |
5000 | Pre-domain wildcard CORS Exploitation |
CORS misconfiguration |
NA |
Arbaz Hussain (@ArbazKiraak) |
Bug Bounty | 2017-08-26 | 2023-06-13 |
4999 | Upgrade from LFI to RCE via PHP Sessions |
LFI
RCE |
NA |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2017-08-28 | 2023-06-13 |
4998 | Bypassing Rate Limit Protection by spoofing originating IP |
Bruteforce |
NA |
Arbaz Hussain (@ArbazKiraak) |
Bug Bounty | 2017-08-30 | 2023-06-13 |
4997 | Improper Storage of Private Project’s Files |
IDOR |
NA |
Arbaz Hussain (@ArbazKiraak) |
Bug Bounty | 2017-08-30 | 2023-06-13 |
4996 | Developer Luminate IDOR |
IDOR |
Yahoo! / Verizon Media |
Rojan Rijal (@uraniumhacker) |
Bug Bounty | 2017-08-30 | 2023-06-13 |
4995 | Luminate Store Basics defacement and potential takeover |
CSRF
Session management issue |
Yahoo! / Verizon Media |
Rojan Rijal (@uraniumhacker) |
Bug Bounty | 2017-08-30 | 2023-06-13 |
4994 | Uber XSS via Cookie |
XSS |
Uber |
Chaobin Zhang |
Bug Bounty | 2017-08-30 | 2023-06-13 |