4677 | Vulnerability in Hangouts Chat a.k.a. how Electron makes open redirect great again |
Open redirect
RCE |
Google |
Michał Bentkowski (@SecurityMB) |
Bug Bounty | 2018-07-24 | 2023-06-13 |
4599 | How I find Open-Redirect Vulnerability in redacted.com (One of the top online payment processing service website) |
Open redirect |
NA |
Muhammad Asim Shahzad (@protector47) |
Bug Bounty | 2018-09-09 | 2023-06-13 |
4597 | Making the Facebook app more secure - $8500 bounty |
Open redirect |
Meta / Facebook |
Ashley King (@AshleyKingUK) |
Bug Bounty | 2018-09-09 | 2023-06-13 |
4590 | Open-Redirect Vulnerability in udacity.com |
Open redirect |
Udacity |
Anil Tom (mr_4nk) |
Bug Bounty | 2018-09-11 | 2023-06-13 |
4562 | Just another tale of severe bugs on a private program. |
Open redirect
SSRF
IDOR
Logic flaw |
NA |
Siva Krishna Samireddi (@le4rner) |
Bug Bounty | 2018-09-28 | 2023-06-13 |
4561 | IDOR, Content Spoofing and Url Redirection via unsubscribe email in Confluent |
IDOR
Content spoofing
Open redirect |
Confluent |
Divyanshu Shukla (@justm0rph3u5) |
Bug Bounty | 2018-09-28 | 2023-06-13 |
4517 | Facebook hidden redirection vulnerability |
Open redirect |
Meta / Facebook |
Ege Ken |
Bug Bounty | 2018-10-24 | 2023-06-13 |
4495 | Full Account Takeover via Referer Header (OAuth token Steal, Open Redirect Vulnerability Chaining) |
Open redirect
Token leak
Account takeover |
NA |
Muhammad Asim Shahzad (@protector47) |
Bug Bounty | 2018-11-03 | 2023-06-13 |
4468 | Microsoft BingPlaces Business - (url) Redirect Vulnerability |
Open redirect |
Microsoft |
Benjamin K.M. |
Bug Bounty | 2018-11-16 | 2023-06-13 |
4462 | Youtube - Open redirection |
Open redirect |
Google |
Barak Tawily (@quitten11) |
Bug Bounty | 2018-11-19 | 2023-06-13 |
4454 | My Journey To The Google Hall Of Fame |
Open redirect
XSS |
Google |
Abartan Dhakal (@imhaxormad) |
Bug Bounty | 2018-11-25 | 2023-06-13 |
4418 | [Open redirect] Developers are lazy(or maybe busy) |
Open redirect |
NA |
KatsuragiCSL (@ZuuitterE) |
Bug Bounty | 2018-12-12 | 2023-06-13 |
4381 | A Tricky Open Redirect |
Open redirect |
NA |
Anas Mahmood (@AnasIsHere) |
Bug Bounty | 2019-01-03 | 2023-06-13 |
4375 | How I hacked Altervista.org |
Open redirect |
Altervista |
Jacopo Tediosi (@jacopotediosi) |
Bug Bounty | 2019-01-05 | 2023-06-13 |
4335 | Hijacking accounts by retrieving JWT tokens via unvalidated redirects |
Open redirect
Token leak |
NA |
Shawar Khan (@ShawarkOFFICIAL) |
Bug Bounty | 2019-01-27 | 2023-06-13 |
4321 | Jumping Over The Fence |
Open redirect |
NA |
Shahar Albeck |
Bug Bounty | 2019-02-05 | 2023-06-13 |
4300 | Open Redirect in SLACK |
Open redirect |
Slack |
Mukhammad Akbar (@abaykandotcom) |
Bug Bounty | 2019-02-16 | 2023-06-13 |
4207 | Account Takeover by chaining two vulnerabilities. |
CSRF
Open redirect
Account takeover |
NA |
Sheraz Khalid |
Bug Bounty | 2019-04-10 | 2023-06-13 |
4153 | You do not need to run 80 reconnaissance tools to get access to user accounts |
Open redirect |
NA |
Stefano Vettorazzi (@stefanohablando) |
Bug Bounty | 2019-05-15 | 2023-06-13 |
4146 | Open-redirect to Account Takeover. |
Open redirect
Account takeover |
NA |
Rishabh (@____cypher____) |
Bug Bounty | 2019-05-19 | 2023-06-13 |
4144 | Leaking OpenID tokens with “ — the bug right infront of you |
OpenID Connect
Open redirect
Token leak |
NA |
Zseano (@zseano) |
Bug Bounty | 2019-05-21 | 2023-06-13 |
4073 | 1-Click Account Takeover in Virgool.io — a Nice Case Study |
Account takeover
Open redirect |
NA |
Yashar Shahinzadeh (@YShahinzadeh) |
Bug Bounty | 2019-06-27 | 2023-06-13 |
4052 | OAuth authentication bypass on Airbnb acquisition using 1-char Open Redirect |
Open redirect
Token leak
Account takeover |
Airbnb |
Evgeniy Yakovchuk (@h1_sp1d3r) |
Bug Bounty | 2019-07-10 | 2023-06-13 |
4027 | Microsoft ID Open Redirect |
Open redirect |
Microsoft |
Burninator Sec |
Bug Bounty | 2019-07-19 | 2023-06-13 |
3995 | From Sub domain Takeover to Open-Redirect |
Subdomain takeover
Open redirect |
NA |
Anil Tom (mr_4nk) |
Bug Bounty | 2019-08-02 | 2023-06-13 |