4838 | Getting any Facebook user%27s friend list and partial payment card details |
Information disclosure
IDOR |
Meta / Facebook |
Josip Franjkovic (@josipfranjkovic) |
Bug Bounty | 2018-03-09 | 2023-06-13 |
4837 | How I hacked 74k users of a website. |
Authorization flaw |
NA |
Utkarsh Agrawal (@agrawalsmart7) |
Bug Bounty | 2018-03-11 | 2023-06-13 |
4836 | Union Based Sql injection Write up ->A private Company Site |
SQL injection |
NA |
Nur A Alam Dipu (@Dipu1A) |
Bug Bounty | 2018-03-12 | 2023-06-13 |
4835 | #BugBounty — “Let me reset your password and login into your account “-How I was able to Compromise any User Account via Reset Password Functionality |
Logic flaw
Password reset
Account takeover |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-03-14 | 2023-06-13 |
4834 | GraphQL abuse: Bypass account level permissions through parameter smuggling |
GraphQL
Privilege escalation |
New Relic |
Jon Bottarini (@jon_bottarini) |
Bug Bounty | 2018-03-14 | 2023-06-13 |
4833 | CVE-2017-13253: Buffer overflow in multiple Android DRM services |
Memory corruption
Local Privilege Escalation |
Google |
Tamir Zahavi-Brunner (@tamir_zb) |
Bug Bounty | 2018-03-15 | 2023-06-13 |
4832 | Leaking WordPress CSRF Tokens for Fun, $1337 bounty, and CVE-2017-5489 |
CSRF |
WordPress |
Abdullah Hussam (@Abdulahhusam) |
Bug Bounty | 2018-03-15 | 2023-06-13 |
4831 | Google adwords 3133.7$ Stored XSS |
Stored XSS |
Google |
Emad Shanab (@Alra3ees) |
Bug Bounty | 2018-03-21 | 2023-06-13 |
4830 | Hacking Oracle in 5 Minutes |
Directory listing |
Oracle |
Rahul R |
Bug Bounty | 2018-03-25 | 2023-06-13 |
4829 | #BugBounty — Rewarded by securing vulnerabilities in Bookmyshow (India’s largest online movie & event booking portal) |
Host header injection
IDOR |
BookMyShow |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-03-25 | 2023-06-13 |
4828 | Misconfiguration of Demographics Privacy in a Page |
Logic flaw |
Meta / Facebook |
Mark Christian Deduyo |
Bug Bounty | 2018-03-26 | 2023-06-13 |
4827 | Reflected XSS Moogaloop SWF ( Version < 6.2.x ) |
Flash XSS
Reflected XSS |
Vimeo |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2018-03-26 | 2023-06-13 |
4826 | Google bug bounty for security exploit that influences search results |
Logic flaw |
Google |
Tom Anthony (@TomAnthonySEO) |
Bug Bounty | 2018-03-27 | 2023-06-13 |
4825 | Creating Test Conversion using any App |
Parameter tampering |
Meta / Facebook |
Joshua Regio |
Bug Bounty | 2018-03-27 | 2023-06-13 |
4824 | How I Could Have Promoted Any Facebook Page For Free. |
Logic flaw |
Meta / Facebook |
Anees Khan (@AneesEthical) |
Bug Bounty | 2018-03-30 | 2023-06-13 |
4823 | How I hacked one cryptocurrency service |
Blind XSS
Reflected XSS
CSRF |
PayKassa |
Valeriy Shevchenko (@Krevetk0Valeriy) |
Bug Bounty | 2018-03-31 | 2023-06-13 |
4822 | XSS In sports.tw.campaign.yahoo.net |
Reflected XSS |
Yahoo! / Verizon Media |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2018-03-31 | 2023-06-13 |
4821 | XSS in Yahoo Subdomain |
Flash XSS |
Yahoo! / Verizon Media |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2018-03-31 | 2023-06-13 |
4820 | My Best Small Report Bounty Report in Private Program ( Django REST framework Admin Login ByPass ) |
SQL injection
Authentication bypass
Account takeover |
NA |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2018-04-01 | 2023-06-13 |
4819 | Facebook BugBounty: Intercept incoming friend requests of Victim add/accept to your facebook account |
Authorization flaw |
Meta / Facebook |
Family guy |
Bug Bounty | 2018-04-02 | 2023-06-13 |
4818 | Beyond XSS: Edge Side Include Injection |
ESI injection
SSRF
XSS |
Squid
Varnish |
Louis Dion-Marcil (@ldionmarcil) |
Bug Bounty | 2018-04-03 | 2023-06-13 |
4817 | How I caught Multiple vulnerabilities in Udemy.com, But not rewarded for serious XSS vulnerability :( |
XSS
HTML injection |
Udemy |
Satyendra Shrivastava |
Bug Bounty | 2018-04-05 | 2023-06-13 |
4816 | #BugBounty — ” Your details are saved into my account”-User info disclosure Vulnerability in Practo (India’s biggest healthcare app) |
IDOR |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-04-05 | 2023-06-13 |
4815 | Link injection on 2 Twitter Subdomain |
Hyperlink injection |
Twitter |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2018-04-05 | 2023-06-13 |
4814 | “Exploiting a Single Parameter” |
SSRF
XSS |
NA |
Hisham Mir (@Hishammir1) |
Bug Bounty | 2018-04-06 | 2023-06-13 |