878 | How I Get 5x Swag From Sony |
DOM XSS
Directory listing
Default credentials
Information disclosure |
Sony |
Naeem Ahmed Sayed (@0xNaeem) |
Bug Bounty | 2022-11-02 | 2023-06-13 |
877 | How 403 Forbidden Bypass got me NOKIA Hall Of Fame (HOF) |
403 bypass |
Nokia |
Jaydeepsinh Thakor (@thakor_jd_) |
Bug Bounty | 2022-11-02 | 2023-06-13 |
876 | Improper Access Control — My Third Finding on Hackerone! |
HTML injection
Broken Access Control |
NA |
mehedishakeel (@mehedishakeel) |
Bug Bounty | 2022-11-02 | 2023-06-13 |
875 | Fuzzing For Hidden Params |
SQL injection |
NA |
calfcrusher |
Bug Bounty | 2022-11-02 | 2023-06-13 |
874 | Chaining Multiple Vulnerabilities Leads to Remote Code Execution (RCE) on One of the Payment Service Companies. |
Exposed registration page
Exposed Jenkins instance
Weak credentials
RCE |
NA |
Rohit Soni (@streetofhacker) |
Bug Bounty | 2022-11-02 | 2023-06-13 |
873 | Gregor Samsa: Exploiting Java%27s XML Signature Verification |
Integer truncation
RCE
SAML |
OpenJDK
Apache Commons BCEL |
Felix Wilhelm (@_fel1x) |
Bug Bounty | 2022-11-02 | 2023-06-13 |
872 | How I could have been the administrator for all Dutch companies and create invoices. And still can be… |
Logic flaw |
Dutch Government |
bob van der staak |
Bug Bounty | 2022-11-03 | 2023-06-13 |
871 | Get Blind XSS within 5 Minutes — $100 |
Blind XSS |
NA |
Narayanan M |
Bug Bounty | 2022-11-03 | 2023-06-13 |
870 | The power of adaptability through experience. |
Lateral movement
Active Directory Privilege Escalation |
NA |
Mike Saunders (@hardwaterhacker) |
Bug Bounty | 2022-11-03 | 2023-06-13 |
869 | Invitation Hijacking |
Authorization flaw
Privilege escalation |
NA |
vFlexo (@vflexo) |
Bug Bounty | 2022-11-03 | 2023-06-13 |
868 | Case of Admin Bypass for RCE, XSS, and Information Disclosure |
RCE
Unrestricted file upload
Stored XSS
Information disclosure |
NA |
Sam Paredes (@caffeinevulns) |
Bug Bounty | 2022-11-03 | 2023-06-13 |
867 | How I hacked into a Cambridge’s server and got appreciation letter. |
Unrestricted file upload
RCE |
Cambridge |
Prathamrajgor |
Bug Bounty | 2022-11-04 | 2023-06-13 |
866 | CSRF Leads to Delete User Account |
CSRF |
NA |
Omarbakrey |
Bug Bounty | 2022-11-04 | 2023-06-13 |
865 | Practical Client Side Path Traversal Attacks |
Path traversal
Client-side Path Traversal
Open redirect
CSS injection |
Acronis |
Medi (@medi_0ne) |
Bug Bounty | 2022-11-04 | 2023-06-13 |
864 | PENTEST TALES: EXIF Data Manipulation |
Unrestricted file upload
Stored XSS |
NA |
Armand Jasharaj |
Bug Bounty | 2022-11-05 | 2023-06-13 |
863 | Directory traversal in PDF viewing application. Leading to full database takeover |
Path traversal |
NA |
Tom Wrinn |
Bug Bounty | 2022-11-05 | 2023-06-13 |
862 | Story of a $1k bounty — SSRF to leaking access token and other sensitive information |
SSRF |
NA |
Faique (@imfaiqu3) |
Bug Bounty | 2022-11-05 | 2023-06-13 |
861 | CVE-2022-26730 | ColorSync | Hoyt LLC |
MacOS
Memory corruption
RCE |
Apple |
David Hoyt (@h02332) |
Bug Bounty | 2022-11-05 | 2023-06-13 |
860 | Exploit Feature To Get High Bug impact |
Logic flaw |
NA |
Mohamed Anani (@0xm5awy) |
Bug Bounty | 2022-11-05 | 2023-06-13 |
859 | IDOR on Unsubscribe emails to $200 bounty. |
IDOR |
NA |
shbugger1 |
Bug Bounty | 2022-11-06 | 2023-06-13 |
858 | Stormshield SNS cleartext password leak |
Use of GET request Method With sensitive query strings |
Stormshield |
Mehdi Alouache |
Bug Bounty | 2022-11-07 | 2023-06-13 |
857 | How we hacked’ Telenet’s cybersecurity quiz |
Logic flaw |
Telenet |
Mickey De Baets |
Bug Bounty | 2022-11-07 | 2023-06-13 |
856 | Exploring ZIP Mark-of-the-Web Bypass Vulnerability (CVE-2022-41049) |
Local Privilege Escalation
Windows |
Microsoft |
Kuba Gretzky (@mrgretzky) |
Bug Bounty | 2022-11-08 | 2023-06-13 |
855 | Comodo: From .Git to Takeover |
.git folder disclosure |
Comodo |
Maor Dayan (@mord1234) |
Bug Bounty | 2022-11-08 | 2023-06-13 |
854 | Compromising Plesk Via Its REST API |
CORS misconfiguration
CSRF |
Plesk |
Adrian Tiron (@Adrian__T) |
Bug Bounty | 2022-11-08 | 2023-06-13 |