4951 | Abusing new Claps feature in Medium |
IDOR |
Medium |
Sai Krishna Kothapalli (@kmskrishna) |
Bug Bounty | 2017-10-29 | 2023-06-13 |
4937 | How I Pwned a company using IDOR & Blind XSS |
IDOR
Blind XSS |
NA |
Osama Ansari (@AnsariOsama10) |
Bug Bounty | 2017-11-15 | 2023-06-13 |
4924 | Image removal vulnerability in Facebook polling feature |
IDOR |
Meta / Facebook |
Pouya Darabi (@Pouyadarabi) |
Bug Bounty | 2017-11-25 | 2023-06-13 |
4904 | Abusing internal API to achieve IDOR in New Relic |
IDOR |
New Relic |
Jon Bottarini (@jon_bottarini) |
Bug Bounty | 2018-01-02 | 2023-06-13 |
4900 | Hunting Insecure Direct Object Reference Vulnerabilities for Fun and Profit (PART-1) |
IDOR |
NA |
Mohammed Abdul Raheem (@mohdaltaf163) |
Bug Bounty | 2018-01-04 | 2023-06-13 |
4898 | #BugBounty — How I was able to read chat of users in an Online travel portal |
IDOR |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-01-10 | 2023-06-13 |
4876 | How I was able to Download Any file from Web server! |
XSS
IDOR |
NA |
hammadhassan924 |
Bug Bounty | 2018-01-27 | 2023-06-13 |
4872 | Hunting Insecure Direct Object Reference Vulnerabilities for Fun and Profit (PART-1) |
IDOR |
NA |
Mohammed Abdul Raheem (@mohdaltaf163) |
Bug Bounty | 2018-02-03 | 2023-06-13 |
4869 | How I found IDOR on Twitter’s Acquisition – Mopub.com |
IDOR |
Twitter |
Jay Jani (@JayJani007) |
Bug Bounty | 2018-02-05 | 2023-06-13 |
4865 | Taking over Facebook accounts using Free Basics partner portal |
Information disclosure
IDOR |
Meta / Facebook |
Josip Franjkovic (@josipfranjkovic) |
Bug Bounty | 2018-02-07 | 2023-06-13 |
4851 | Modifying any Ad Space and Placement |
IDOR |
Meta / Facebook |
Joshua Regio |
Bug Bounty | 2018-02-22 | 2023-06-13 |
4848 | How I was able to delete any image in Facebook community question forum |
IDOR |
Meta / Facebook |
Sarmad Hassan (@JubaBaghdad) |
Bug Bounty | 2018-02-24 | 2023-06-13 |
4838 | Getting any Facebook user%27s friend list and partial payment card details |
Information disclosure
IDOR |
Meta / Facebook |
Josip Franjkovic (@josipfranjkovic) |
Bug Bounty | 2018-03-09 | 2023-06-13 |
4829 | #BugBounty — Rewarded by securing vulnerabilities in Bookmyshow (India’s largest online movie & event booking portal) |
Host header injection
IDOR |
BookMyShow |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-03-25 | 2023-06-13 |
4816 | #BugBounty — ” Your details are saved into my account”-User info disclosure Vulnerability in Practo (India’s biggest healthcare app) |
IDOR |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-04-05 | 2023-06-13 |
4805 | How I hacked companies related to the crypto currency and earned $60,000 |
Authorization flaw
CSRF
IDOR
Stored XSS
HTML injection |
okex.com
livecoin.net |
Max (@0xw2w) |
Bug Bounty | 2018-04-14 | 2023-06-13 |
4800 | Spoof an user to create a description of a group in Flickr |
IDOR |
Flickr |
Samuel (@saamux) |
Bug Bounty | 2018-04-16 | 2023-06-13 |
4797 | IDOR (at Private Bug Bounty Program) that could Leads to Personal Data Leaks |
IDOR |
NA |
YoKo Kho (@YokoAcc) |
Bug Bounty | 2018-04-17 | 2023-06-13 |
4796 | How I Get the Name of the Hotel (and other Data) that you ever Stay - Personal Data Leaks: Private Bug Bounty Program |
IDOR |
NA |
YoKo Kho (@YokoAcc) |
Bug Bounty | 2018-04-18 | 2023-06-13 |
4795 | Ribose — IDOR with Simple CSRF Bypass — Unrestricted Changes and Deletion to other Photo Profile |
IDOR |
Ribose |
YoKo Kho (@YokoAcc) |
Bug Bounty | 2018-04-18 | 2023-06-13 |
4782 | Bypassing the Confirmation Email for Newsletter (bof.nl) |
Authorization flaw
IDOR |
Bits of Freedom |
Mohammed Israil (@mdisrail2468) |
Bug Bounty | 2018-04-26 | 2023-06-13 |
4775 | Disclose Private Video Thumbnail from Facebook WorkPlace |
IDOR |
Meta / Facebook |
Sarmad Hassan (@JubaBaghdad) |
Bug Bounty | 2018-05-03 | 2023-06-13 |
4763 | How i HACKED admin account via password reset IDOR function of one private currency exchanger site |
IDOR
Account takeover
Password reset |
NA |
Aayush Pokhrel (@aayushpok) |
Bug Bounty | 2018-05-19 | 2023-06-13 |
4755 | #BugBounty — "How I was able to hack any user account via password reset?" |
IDOR
Account takeover
Password reset |
NA |
Bikash Gupta (@BgxDoc) |
Bug Bounty | 2018-05-23 | 2023-06-13 |
4754 | How I was able to see any private album passwrod in Picturepush — IDOR |
IDOR |
PicturePush |
Murtada Kamil |
Bug Bounty | 2018-05-23 | 2023-06-13 |