4505 | IDOR in JWT and the shortest token you will ever see {}.{“uid”: “1234567890”} |
IDOR |
NA |
Plenum (@plenumlab) |
Bug Bounty | 2018-10-30 | 2023-06-13 |
4503 | It’s all in the detail: Email leak & Account takeover thanks to WayBackMachine & extensive knowledge about the program |
Information disclosure
Authentication bypass
Account takeover |
NA |
Zseano (@zseano) |
Bug Bounty | 2018-10-30 | 2023-06-13 |
4501 | Stored XSS in Bug Bounty |
Stored XSS |
NA |
KatsuragiCSL (@ZuuitterE) |
Bug Bounty | 2018-11-01 | 2023-06-13 |
4500 | P1 Like a Boss | Information Disclosure via Github leads to Employee Account Takeover | Bug Bounty POC |
Information disclosure |
NA |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2018-11-01 | 2023-06-13 |
4499 | Finding hidden gems vol. 3: quick win with .sh file |
Information disclosure |
NA |
Mateusz Olejarka (@molejarka) |
Bug Bounty | 2018-11-01 | 2023-06-13 |
4498 | CVE-2018-11759 – Apache mod_jk access control bypass |
Path traversal |
Apache HTTP Server |
Raphaël Arrouas |
Bug Bounty | 2018-11-01 | 2023-06-13 |
4495 | Full Account Takeover via Referer Header (OAuth token Steal, Open Redirect Vulnerability Chaining) |
Open redirect
Token leak
Account takeover |
NA |
Muhammad Asim Shahzad (@protector47) |
Bug Bounty | 2018-11-03 | 2023-06-13 |
4494 | Unauthenticated RSFTP to Command Injection |
Path traversal
RCE |
NA |
Nicodemo Gawronski |
Bug Bounty | 2018-11-03 | 2023-06-13 |
4493 | Duplicate but still cool |
IDOR
Account takeover |
NA |
Plenum (@plenumlab) |
Bug Bounty | 2018-11-05 | 2023-06-13 |
4485 | CVE-2018-9539: Use-after-free vulnerability in privileged Android service |
Memory corruption
Use-After-Free |
Google |
Tamir Zahavi-Brunner (@tamir_zb) |
Bug Bounty | 2018-11-09 | 2023-06-13 |
4482 | Chain exploitation of XSS |
DOM XSS
Clickjacking
CSRF |
NA |
Mikhail Klyuchnikov (@__Mn1__) |
Bug Bounty | 2018-11-12 | 2023-06-13 |
4480 | [DOM based XSS] Or why you should not rely on Cloudflare too much |
DOM XSS |
NA |
KatsuragiCSL (@ZuuitterE) |
Bug Bounty | 2018-11-13 | 2023-06-13 |
4479 | OOB XXE in PrizmDoc (CVE-2018–15805) |
OOB XXE |
PrizmDoc |
Nik srivastava |
Bug Bounty | 2018-11-13 | 2023-06-13 |
4478 | Spoof All Domains Containing %27d%27 in Apple Products [CVE-2018-4277] |
Browser hacking |
Apple |
Tencent%27s Xuanwu Lab |
Bug Bounty | 2018-11-13 | 2023-06-13 |
4470 | [POC] Cross-Site Scripting on Garuda Indonesia Website |
XSS |
Garuda Indonesia |
Arif-ITSEC111 |
Bug Bounty | 2018-11-16 | 2023-06-13 |
4469 | XSS in hidden input fields |
XSS |
NA |
Gareth Heyes (@garethheyes) |
Bug Bounty | 2018-11-16 | 2023-06-13 |
4468 | Microsoft BingPlaces Business - (url) Redirect Vulnerability |
Open redirect |
Microsoft |
Benjamin K.M. |
Bug Bounty | 2018-11-16 | 2023-06-13 |
4464 | From Security Misconfiguration to Gaining Access of SMTP server |
File disclosure |
NA |
Daniel V. (@d4niel_v) |
Bug Bounty | 2018-11-18 | 2023-06-13 |
4462 | Youtube - Open redirection |
Open redirect |
Google |
Barak Tawily (@quitten11) |
Bug Bounty | 2018-11-19 | 2023-06-13 |
4461 | XS-Searching Google’s bug tracker to find out vulnerable source code |
XS-Search
Information disclosure |
Google |
Luan Herrera (@lbherrera_) |
Bug Bounty | 2018-11-19 | 2023-06-13 |
4457 | Exploiting SSRF like a Boss — Escalation of an SSRF to Local File Read! |
SSRF
LFI |
NA |
Zain Sabahat (@Zain_Sabahat) |
Bug Bounty | 2018-11-22 | 2023-06-13 |
4455 | Stored XSS Vulnerability in Jotform and H1C Private Site |
Stored XSS |
NA |
Anas Mahmood (@AnasIsHere) |
Bug Bounty | 2018-11-23 | 2023-06-13 |
4448 | Instagram Multi-factor authentication Bypass |
MFA bypass |
Meta / Facebook |
Vishnuraj |
Bug Bounty | 2018-11-27 | 2023-06-13 |
4447 | Pwning eBay - How I Dumped eBay Japan%27s Website Source Code |
.git folder disclosure
Source code disclosure |
Ebay |
David (@slashcrypto) |
Bug Bounty | 2018-11-28 | 2023-06-13 |
4445 | Broken Authentication — Bug Bounty |
Session management issue |
NA |
Vulnerables |
Bug Bounty | 2018-11-28 | 2023-06-13 |