4967 | Craft CMS – Why case matters |
Reflected XSS
Content injection |
Craft CMS |
Markus Krell (@MarkusKrell) |
Bug Bounty | 2017-10-01 | 2023-06-13 |
4966 | How I could have mass uploaded from every Flickr account! |
Bruteforce |
Flickr |
Jazzy (@ret2got) |
Bug Bounty | 2017-10-05 | 2023-06-13 |
4965 | How I Was Able To View Private Tweets Of Any Private Twitter Account |
IDOR |
Twitter |
Cj Legacion (@LegacionCj) |
Bug Bounty | 2017-10-06 | 2023-06-13 |
4963 | Subdomain Takeover Through Expired Cloudfront Distribution | live.lamborghini.co |
Subdomain takeover |
Lamborghini |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2017-10-10 | 2023-06-13 |
4962 | Exploiting Insecure Cross Origin Resource Sharing ( CORS ) | api.artsy.net |
CORS misconfiguration |
Artsy |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2017-10-10 | 2023-06-13 |
4961 | Bugcrowd’s Domain & Subdomain Takeover vulnerability! |
Subdomain takeover |
Bugcrowd |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2017-10-10 | 2023-06-13 |
4960 | Leaking Amazon.com CSRF Tokens Using Service Worker API |
CSRF |
Amazon |
Abdullah Hussam (@Abdulahhusam) |
Bug Bounty | 2017-10-11 | 2023-06-13 |
4959 | How I was Able to see someone’s all private files with a single file share link through Atom feed & Never Give Up #togetherwehitharder HackerOne |
Information disclosure |
NA |
Yogendra Jaiswal (@vulnh0lic) |
Bug Bounty | 2017-10-13 | 2023-06-13 |
4958 | DOM XSS – auth.uber.com |
DOM XSS |
Uber |
StamOne_ |
Bug Bounty | 2017-10-14 | 2023-06-13 |
4957 | Reading Internal Files using SSRF vulnerability |
SSRF |
NA |
Neeraj Sonaniya (@neeraj_sonaniya) |
Bug Bounty | 2017-10-16 | 2023-06-13 |
4956 | How I hacked all the [REDACT] Agents accounts |
Default credentials |
NA |
Neeraj Sonaniya (@neeraj_sonaniya) |
Bug Bounty | 2017-10-17 | 2023-06-13 |
4955 | Sensitive data exposure by requesting a resource with a different content type |
Information disclosure |
NA |
Yogendra Jaiswal (@vulnh0lic) |
Bug Bounty | 2017-10-17 | 2023-06-13 |
4954 | Taking over every Ad on OLX (automated), an IDOR story |
IDOR |
OLX |
Roderick Schaefer (@kciredor_) |
Bug Bounty | 2017-10-18 | 2023-06-13 |
4953 | How i found an SSRF in Yahoo! Guesthouse (Recon Wins) |
SSRF |
Yahoo! / Verizon Media |
Th3G3nt3lman (@Th3G3nt3lman) |
Bug Bounty | 2017-10-20 | 2023-06-13 |
4952 | Slack SAML authentication bypass |
Authentication bypass |
Slack |
Antonio Sanso (@asanso) |
Bug Bounty | 2017-10-26 | 2023-06-13 |
4951 | Abusing new Claps feature in Medium |
IDOR |
Medium |
Sai Krishna Kothapalli (@kmskrishna) |
Bug Bounty | 2017-10-29 | 2023-06-13 |
4950 | How I hacked Google’s bug tracking system itself for $15,600 in bounties |
Logic flaw |
Google |
Alex Birsan (@alxbrsn) |
Bug Bounty | 2017-10-30 | 2023-06-13 |
4949 | App Maker and Colaboratory: a stored Google XSS double-bill |
Stored XSS |
Google |
Yasin Soliman (@SecurityYasin) |
Bug Bounty | 2017-11-01 | 2023-06-13 |
4948 | Senstive Information Leak Lead To join any Organisation |
Information disclosure |
NA |
Shivbihari Pandey (@ninja_pandit_) |
Bug Bounty | 2017-11-04 | 2023-06-13 |
4947 | Accessing Localhost via Vhost |
vHost misconfiguration |
NA |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2017-11-04 | 2023-06-13 |
4946 | CRLF injection in blockchain.info |
CRLF injection |
Blockchain.info |
Shashank (@cyberboyIndia) |
Bug Bounty | 2017-11-05 | 2023-06-13 |
4945 | Non-persistent XSS at Microsoft -Adesh Kolte |
Reflected XSS |
Microsoft |
Adesh Nandkishor kolte (@AdeshKolte) |
Bug Bounty | 2017-11-05 | 2023-06-13 |
4944 | Multiple Intel Vulnerabilities-Adesh Kolte |
Open redirect
Directory listing |
Intel |
Adesh Nandkishor kolte (@AdeshKolte) |
Bug Bounty | 2017-11-05 | 2023-06-13 |
4943 | Get your Microsoft account hijacked by simply clicking connect button -Adesh Kolte |
Stored XSS |
Microsoft |
Adesh Nandkishor kolte (@AdeshKolte) |
Bug Bounty | 2017-11-06 | 2023-06-13 |
4942 | From SSRF to Local File Disclosure |
SSRF
Local file disclosure (LFD) |
NA |
Tung Pun |
Bug Bounty | 2017-11-08 | 2023-06-13 |