5031 | Stealing Access Token of One-drive Integration By Chaining CSRF Vulnerability |
OAuth
CSRF |
NA |
Arbaz Hussain (@ArbazKiraak) |
Bug Bounty | 2017-07-18 | 2023-06-13 |
5028 | That Escalated Quickly : From partial CSRF to reflected XSS to complete CSRF to Stored XSS |
CSRF
Reflected XSS
Stored XSS |
NA |
Mandeep Jadon (@1337tr0lls) |
Bug Bounty | 2017-07-19 | 2023-06-13 |
5006 | Chain the vulnerabilities and take your report impact on the moon (CSRF to HTML INJECTION which results OPEN REDIRECT and could steal USER CREDENTIALS) |
CSRF
HTML injection |
Legal Robot |
Armaan Pathan (@armaancrockroax) |
Bug Bounty | 2017-08-12 | 2023-06-13 |
4995 | Luminate Store Basics defacement and potential takeover |
CSRF
Session management issue |
Yahoo! / Verizon Media |
Rojan Rijal (@uraniumhacker) |
Bug Bounty | 2017-08-30 | 2023-06-13 |
4960 | Leaking Amazon.com CSRF Tokens Using Service Worker API |
CSRF |
Amazon |
Abdullah Hussam (@Abdulahhusam) |
Bug Bounty | 2017-10-11 | 2023-06-13 |
4935 | Bypassing Crossdomain Policy and Hit Hundreds of Top Alexa Sites |
CSRF |
NA |
Ak1T4 (@akita_zen) |
Bug Bounty | 2017-11-16 | 2023-06-13 |
4930 | Account Take Over Vulnerability in Google acquisition [Famebit] |
CSRF |
Google |
Hassan Khan Yusufzai |
Bug Bounty | 2017-11-17 | 2023-06-13 |
4896 | #BugBounty — How I was able to delete anyone’s account in an Online Car Rental Company |
CSRF
Parameter tampering |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-01-14 | 2023-06-13 |
4895 | Hacking Facebook accounts using CSRF in Oculus-Facebook integration |
CSRF |
Meta / Facebook |
Josip Franjkovic (@josipfranjkovic) |
Bug Bounty | 2018-01-15 | 2023-06-13 |
4891 | $1800 in less than an hour. |
CSRF
XSS |
Indeed |
yappare (@yappare) |
Bug Bounty | 2018-01-17 | 2023-06-13 |
4878 | JSON CSRF attack on a Social Networking Site[Hackerone Platform] |
CSRF |
Badoo |
Sahil Tikoo (@viperbluff) |
Bug Bounty | 2018-01-26 | 2023-06-13 |
4832 | Leaking WordPress CSRF Tokens for Fun, $1337 bounty, and CVE-2017-5489 |
CSRF |
WordPress |
Abdullah Hussam (@Abdulahhusam) |
Bug Bounty | 2018-03-15 | 2023-06-13 |
4823 | How I hacked one cryptocurrency service |
Blind XSS
Reflected XSS
CSRF |
PayKassa |
Valeriy Shevchenko (@Krevetk0Valeriy) |
Bug Bounty | 2018-03-31 | 2023-06-13 |
4805 | How I hacked companies related to the crypto currency and earned $60,000 |
Authorization flaw
CSRF
IDOR
Stored XSS
HTML injection |
okex.com
livecoin.net |
Max (@0xw2w) |
Bug Bounty | 2018-04-14 | 2023-06-13 |
4795 | Ribose — IDOR with Simple CSRF Bypass — Unrestricted Changes and Deletion to other Photo Profile |
IDOR |
Ribose |
YoKo Kho (@YokoAcc) |
Bug Bounty | 2018-04-18 | 2023-06-13 |
4761 | Fastest Fix on Open Bug Bounty Platform |
XSS
CSRF |
Kevag Telekom GmbH |
Wen Bin KONG (@kongwenbin) |
Bug Bounty | 2018-05-19 | 2023-06-13 |
4759 | Self-XSS + CSRF to Stored XSS |
Self-XSS
CSRF
Stored XSS |
NA |
Renwa (@RenwaX23) |
Bug Bounty | 2018-05-20 | 2023-06-13 |
4732 | [PayPal BBP] I could’ve deleted All SMC messages. Using Brute-Force technique. |
CSRF |
Paypal |
Ayoub Ait Elmokhtar (@aessadek) |
Bug Bounty | 2018-06-10 | 2023-06-13 |
4714 | Fastest Fix on Open Bug Bounty Platform |
Reflected XSS
CSRF |
Kevag Telekom GmbH |
Wen Bin KONG (@kongwenbin) |
Bug Bounty | 2018-06-24 | 2023-06-13 |
4686 | How I was able to delete 13k+ Microsoft Translator projects |
CSRF
IDOR |
Microsoft |
Haider Mahmood (@haiderinfosec) |
Bug Bounty | 2018-07-19 | 2023-06-13 |
4612 | Send request to Martians. Earthlings are already your friends. |
CSRF |
Google |
Sagar VD |
Bug Bounty | 2018-09-01 | 2023-06-13 |
4586 | How I hijacked your account when you opened my cat picture |
Logout CSRF |
NA |
Matti Bijnens (@MattiBijnens) |
Bug Bounty | 2018-09-14 | 2023-06-13 |
4572 | R-XSS -> CSRF bypass to account takeover/ |
Reflected XSS
CSRF |
NA |
Nirmal Dahal (@TheNittam) |
Bug Bounty | 2018-09-21 | 2023-06-13 |
4557 | Collecting Shells by the Sea of NAS Vulnerabilities |
OS command injection
XSS
CSRF |
Lenovo |
Rick Ramgattie (@RRamgattie) |
Bug Bounty | 2018-10-01 | 2023-06-13 |
4550 | An interesting Google vulnerability that got me 3133.7 reward. |
CSRF |
Google |
Ebrahem Hegazy (@Zigoo0) |
Bug Bounty | 2018-10-04 | 2023-06-13 |