4280 | Chain of hacks leading to Database Compromise! |
LFI
SSRF |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2019-02-23 | 2023-06-13 |
4180 | The journey of Web Cache + Firewall Bypass to SSRF to AWS credentials compromise! |
LFI
SSRF
WAF bypass
Cloudflare bypass |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2019-04-25 | 2023-06-13 |
4145 | WRITE UP – GOOGLE BUG BOUNTY: LFI ON PRODUCTION SERVERS in “springboard.google.com” – $13,337 USD |
LFI |
Google |
Omar Espino (@omespino) |
Bug Bounty | 2019-05-21 | 2023-06-13 |
4143 | Local File Inclusion in peering.google.com |
LFI |
Google |
Jafar Abo Nada (@Jafar_Abo_Nada) |
Bug Bounty | 2019-05-21 | 2023-06-13 |
4103 | Bug Bounty - Information Disclosure through error message + WAF Bypass led to Local File Inclusion |
WAF bypass
LFI
Information disclosure |
NA |
Λявєη (@spenkkkkk) |
Bug Bounty | 2019-06-15 | 2023-06-13 |
4065 | How I escalated RFI into LFI |
RFI
LFI |
NA |
Hassan Khan Yusufzai (@Splint3r7) |
Bug Bounty | 2019-07-01 | 2023-06-13 |
3948 | My First LFI |
LFI |
NA |
Tirtha Mandal (@tirtha_mandal) |
Bug Bounty | 2019-08-31 | 2023-06-13 |
3916 | Client, not client! |
LFI |
NA |
Tung Pun |
Bug Bounty | 2019-09-15 | 2023-06-13 |
3552 | How i Unlocked the blocked accounts? |
Password reset
HTTP parameter pollution
IDOR |
NA |
Maria Zulfiqar |
Bug Bounty | 2020-04-11 | 2023-06-13 |
3419 | Local file read via XSS using PDF generate functionality |
XSS
LFI |
NA |
Sanjay Singh Jhala (@lordjerry0x01) |
Bug Bounty | 2020-06-05 | 2023-06-13 |
3315 | Don’t stop at one bug $$$$ |
Open redirect
XSS
LFI |
NA |
Dheeraj Madhukar (@Dheerajmadhukar) |
Bug Bounty | 2020-07-10 | 2023-06-13 |
3195 | How I was able to find easy P1 just by doing Recon |
LFI |
NA |
Kirtan Patel (@kirtanpatel9111) |
Bug Bounty | 2020-08-22 | 2023-06-13 |
3194 | $$ Bounties for Unauthenticated file read in Cisco ASA CVE-2020–3452 |
LFI |
NA |
Supun Halangoda (@halangoda_supun) |
Bug Bounty | 2020-08-23 | 2023-06-13 |
3163 | How I hacked redbus [An online bus-ticketing application] |
LFI
SSRF |
redBus |
Sangeetha Rajesh S (@rajesh_sangi12) |
Bug Bounty | 2020-09-12 | 2023-06-13 |
3118 | Leveraging LFI to RCE in a website with +20000 users |
LFI
RCE |
NA |
Kleiton Kurti (@kleiton0x7e) |
Bug Bounty | 2020-10-04 | 2023-06-13 |
3102 | Leveraging XSS to Read Internal Files |
XSS
LFI |
NA |
Aditya Dixit (@zombie007o) |
Bug Bounty | 2020-10-09 | 2023-06-13 |
3004 | SD-PWN Part 4 — VMware VeloCloud — The Last Takeover |
RCE
Authentication bypass
Default credentials
SQL injection
Path traversal
LFI |
VMware |
Realmode Labs (@RealmodeLabs) |
Bug Bounty | 2020-11-26 | 2023-06-13 |
2992 | SSTI to Local File Read |
SSTI
LFI |
NA |
Demon (@R29k_) |
Bug Bounty | 2020-12-02 | 2023-06-13 |
2984 | RCE via LFI Log Poisoning - The Death Potion |
RCE
LFI
Log poisoning |
NA |
Jerry Shah (@Jerry) |
Bug Bounty | 2020-12-06 | 2023-06-13 |
2971 | How i got my First Bug Bounty in Intersting Target (LFI to SXSS) |
LFI
Stored XSS |
NA |
Ph.Hitachi |
Bug Bounty | 2020-12-11 | 2023-06-13 |
2685 | PHP fopen() function to local file inclusion |
LFI |
NA |
أنس روبي (@xhzeem) |
Bug Bounty | 2021-03-28 | 2023-06-13 |
2646 | Bug Bounty - Information Disclosure through error message + WAF Bypass led to Local File Inclusion |
LFI
Information disclosure |
NA |
Arben Shala (@arbennsh) |
Bug Bounty | 2021-04-13 | 2023-06-13 |
2563 | CVE-2020-35580 |
LFI |
NA |
hateshape (@hateshaped) |
Bug Bounty | 2021-05-11 | 2023-06-13 |
2506 | Bypassing LFI (Local File Inclusion) |
LFI |
NA |
Abhishek (@abhishake21) |
Bug Bounty | 2021-06-03 | 2023-06-13 |
2444 | Escalating XSS to Arbitrary File Read |
XSS
LFI |
NA |
Pethuraj (@Pethuraj) |
Bug Bounty | 2021-06-27 | 2023-06-13 |