4915 | How I was able to takeover Facebook account |
Authentication bypass |
Meta / Facebook |
Ameer Hamza |
Bug Bounty | 2017-12-10 | 2023-06-13 |
4914 | Don%27t Trust the Host Header for Sending Password Reset Emails |
Password reset
Account takeover |
Mavenlink |
Jack Cable (@jackhcable) |
Bug Bounty | 2017-12-13 | 2023-06-13 |
4913 | Hacking the Hackers: Leveraging an SSRF in HackerTarget |
SSRF |
HackerTarget |
Corben Leo (@hacker_) |
Bug Bounty | 2017-12-17 | 2023-06-13 |
4912 | LFI to 10 servers pwn |
LFI
RCE |
NA |
Nirmal Dahal (@TheNittam) |
Bug Bounty | 2017-12-19 | 2023-06-13 |
4911 | Unrestricted File Upload to RCE | Bug Bounty POC |
RCE |
Meta / Facebook |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2017-12-19 | 2023-06-13 |
4910 | P4 to P2 - The story of one blind SSRF |
Blind SSRF |
NA |
Mikhail Klyuchnikov (@__Mn1__) |
Bug Bounty | 2017-12-19 | 2023-06-13 |
4909 | Account Takeover Due to Misconfigured Login with Facebook/Google |
Account takeover
Authorization flaw |
Google
Meta / Facebook |
Bhavuk Jain (@bhavukjain1) |
Bug Bounty | 2017-12-20 | 2023-06-13 |
4908 | Microsoft SharePoint%27s %27Follow%27 Feature XSS (CVE-2017–8514) -Adesh Kolte |
XSS |
Microsoft |
Adesh Nandkishor kolte (@AdeshKolte) |
Bug Bounty | 2017-12-21 | 2023-06-13 |
4907 | Jumping to the hell with 10 attempts to bypass devil%27s WAF |
XSS |
NA |
Ak1T4 (@akita_zen) |
Bug Bounty | 2017-12-27 | 2023-06-13 |
4906 | How I found SSRF on TheFacebook.com |
SSRF |
Meta / Facebook |
Thunder |
Bug Bounty | 2017-12-27 | 2023-06-13 |
4905 | Stealing $10,000 Yahoo Cookies! |
CORS misconfiguration |
Yahoo! / Verizon Media |
Tabahi (@_tabahi) |
Bug Bounty | 2017-12-30 | 2023-06-13 |
4904 | Abusing internal API to achieve IDOR in New Relic |
IDOR |
New Relic |
Jon Bottarini (@jon_bottarini) |
Bug Bounty | 2018-01-02 | 2023-06-13 |
4903 | Facebook chat / dashboard content injection |
Content injection |
Meta / Facebook |
void (@voidz0r) |
Bug Bounty | 2018-01-03 | 2023-06-13 |
4902 | Content Injection in DuoLingo’s TinyCards App for Android [CVE-2017-16905] |
Content injection |
DuoLingo |
Nightwatch Cybersecurity (@nightwatchcyber) |
Bug Bounty | 2018-01-04 | 2023-06-13 |
4901 | "F**k you Thomas" - ToyTalk bug bounty writeup |
Authentication bypass
HTML injection |
ToyTalk |
Jahmel Harris |
Bug Bounty | 2018-01-04 | 2023-06-13 |
4900 | Hunting Insecure Direct Object Reference Vulnerabilities for Fun and Profit (PART-1) |
IDOR |
NA |
Mohammed Abdul Raheem (@mohdaltaf163) |
Bug Bounty | 2018-01-04 | 2023-06-13 |
4899 | RCE Vulnerabilite in Yahoo Subdomain! ( Yahoo! RCE via Spring Engine SSTI ) By tghawkins |
RCE |
Yahoo! / Verizon Media |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2018-01-05 | 2023-06-13 |
4898 | #BugBounty — How I was able to read chat of users in an Online travel portal |
IDOR |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-01-10 | 2023-06-13 |
4897 | Chaining Bugs to Steal Yahoo Contacts! |
CORS misconfiguration
XSS |
Yahoo! / Verizon Media |
Corben Leo (@hacker_) |
Bug Bounty | 2018-01-11 | 2023-06-13 |
4896 | #BugBounty — How I was able to delete anyone’s account in an Online Car Rental Company |
CSRF
Parameter tampering |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-01-14 | 2023-06-13 |
4895 | Hacking Facebook accounts using CSRF in Oculus-Facebook integration |
CSRF |
Meta / Facebook |
Josip Franjkovic (@josipfranjkovic) |
Bug Bounty | 2018-01-15 | 2023-06-13 |
4893 | #BugBounty — AWS S3 added to my “Bucket” list! |
AWS misconfiguration |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-01-16 | 2023-06-13 |
4892 | Reflected XSS via AngularJS Template Injection |
Reflected XSS
CSTI |
Hostinger |
Taha Ibrahim Draidia |
Bug Bounty | 2018-01-17 | 2023-06-13 |
4891 | $1800 in less than an hour. |
CSRF
XSS |
Indeed |
yappare (@yappare) |
Bug Bounty | 2018-01-17 | 2023-06-13 |
4890 | My Research on Misconfigured Jenkins Servers |
Information disclosure
Missing authentication
Exposed Jenkins instance |
Google
Tesco
Pearson
News Uk |
Mikail Tunç (@emtunc) |
Bug Bounty | 2018-01-18 | 2023-06-13 |