4390 | How I Was Able To Takeover All User Account And Admin Panel |
IDOR
Account takeover |
NA |
Dipak kumar Das (@d1pakdas) |
Bug Bounty | 2018-12-28 | 2023-06-13 |
4388 | Abusing ACL Permissions to Overwrite other User’s Uploaded Files/Videos on s3 Bucket |
Unrestricted file upload
Authorization flaw |
NA |
Armaan Pathan (@armaancrockroax) |
Bug Bounty | 2018-12-30 | 2023-06-13 |
4385 | Tale of a Misconfiguration in Password Reset |
Password reset |
NA |
Shuaib Oladigbolu (@_sawzeeyy) |
Bug Bounty | 2018-12-30 | 2023-06-13 |
4384 | A Curious Case From Little To Complete Email Verification Bypass |
Email verification bypass
Authorization flaw |
NA |
Megaman (@N0_M3ga_Hacks) |
Bug Bounty | 2019-01-01 | 2023-06-13 |
4381 | A Tricky Open Redirect |
Open redirect |
NA |
Anas Mahmood (@AnasIsHere) |
Bug Bounty | 2019-01-03 | 2023-06-13 |
4380 | Yes I can see your OTP |
IDOR |
NA |
Vulnerables |
Bug Bounty | 2019-01-03 | 2023-06-13 |
4379 | Stealing Side-Channel Attack Tokens in Facebook Account Switcher |
Token leak |
Meta / Facebook |
Max Pasqua |
Bug Bounty | 2019-01-04 | 2023-06-13 |
4372 | When Cookie Hijacking + HTML Injection become dangerous |
Cookie hijacking
HTML injection |
NA |
Daniel V. (@d4niel_v) |
Bug Bounty | 2019-01-07 | 2023-06-13 |
4367 | Turning Self XSS to good XSS via access control |
Stored XSS
Self-XSS |
NA |
Yusuf Yazir (@Hacklad) |
Bug Bounty | 2019-01-13 | 2023-06-13 |
4365 | Abusing MySQL clients to get LFI from the server/client |
LFI |
NA |
Jarkko Vesiluoma (@jvesiluoma) |
Bug Bounty | 2019-01-15 | 2023-06-13 |
4364 | #BugBounty How I Hack Billion $ Company |
Directory listing |
NA |
Sadiq West |
Bug Bounty | 2019-01-15 | 2023-06-13 |
4362 | Command Injection PoC |
OS command injection |
NA |
NoGe (@p4c3n0g3) |
Bug Bounty | 2019-01-15 | 2023-06-13 |
4361 | Bypass Content Security Policy framing restriction rule - OLX |
CSP bypass |
OLX |
Taha Ibrahim Draidia |
Bug Bounty | 2019-01-17 | 2023-06-13 |
4360 | XSS Through SWF file! |
Flash XSS |
NA |
Friendly (@SkeletorKeys) |
Bug Bounty | 2019-01-18 | 2023-06-13 |
4359 | Oauth Misconfiguration lead to complete account takeover |
CSRF
OAuth
Account takeover |
NA |
Jackson kv (@Jacksonkv22) |
Bug Bounty | 2019-01-20 | 2023-06-13 |
4358 | A Simple CORS Misconfig Leaked Private Post Of Twitter, Facebook & Instagram |
CORS misconfiguration |
NA |
Rohan aggarwal (@nahoragg) |
Bug Bounty | 2019-01-20 | 2023-06-13 |
4338 | Misconfiguration-Whatsapp Messenger |
Logic flaw |
Meta / Facebook |
Pratheesh P Narayanan |
Bug Bounty | 2019-01-26 | 2023-06-13 |
4337 | Chaining Tricky OAuth Exploitation To Stored XSS |
Stored XSS
OAuth |
NA |
Rohan aggarwal (@nahoragg) |
Bug Bounty | 2019-01-27 | 2023-06-13 |
4336 | A short tale of Account verification bypass |
Email verification bypass
Authorization flaw |
NA |
Satyendra Kumar |
Bug Bounty | 2019-01-27 | 2023-06-13 |
4335 | Hijacking accounts by retrieving JWT tokens via unvalidated redirects |
Open redirect
Token leak |
NA |
Shawar Khan (@ShawarkOFFICIAL) |
Bug Bounty | 2019-01-27 | 2023-06-13 |
4332 | Guest blog: Eray Mitrani - Hacking isn’t an exact science |
Authorization flaw |
NA |
Eray Mitrani (@ErayMitrani) |
Bug Bounty | 2019-01-29 | 2023-06-13 |
4326 | How I was able to Extract Information of Other Users- Exploiting IDOR |
IDOR |
Knowyourmeds.com |
Rupika Luhach (@Rup_Ki_Rani) |
Bug Bounty | 2019-02-02 | 2023-06-13 |
4323 | Detecting and exploiting mass-assignments in order to manipulate user columns and read private messages |
Mass assignment |
NA |
Paul (@padannewitz) |
Bug Bounty | 2019-02-05 | 2023-06-13 |
4321 | Jumping Over The Fence |
Open redirect |
NA |
Shahar Albeck |
Bug Bounty | 2019-02-05 | 2023-06-13 |
4317 | How i was able to dump SqlDB | Simple bug |
Directory listing
SQL injection
Authentication bypass |
NA |
clever idi0t |
Bug Bounty | 2019-02-07 | 2023-06-13 |