3591 | Remote Image Upload Leads to RCE (Inject Malicious Code to PHP-GD Image) |
Unrestricted file upload
RCE |
NA |
Muhammad R. Maulana |
Bug Bounty | 2020-03-21 | 2023-06-13 |
3584 | Exploitation of the CVE-2018-15961 – Unrestricted File Upload in Adobe ColdFusion |
Unrestricted file upload |
NA |
Supras (@LdrTom) |
Bug Bounty | 2020-03-26 | 2023-06-13 |
3555 | Unrestricted CV File Upload |
Unrestricted file upload |
NA |
vict0ni (@vict0ni) |
Bug Bounty | 2020-04-07 | 2023-06-13 |
3540 | CSRF to RCE bug chain in Prestashop v1.7.6.4 and below |
RCE
CSRF
Stored XSS
Unrestricted file upload |
PrestaShop |
Sivanesh Ashok (@sivaneshashok) |
Bug Bounty | 2020-04-18 | 2023-06-13 |
3476 | Stored XSS Leads to Plaintext Password Disclosure |
Stored XSS
Information disclosure
Unrestricted file upload |
NA |
bad5ect0r (@bad5ect0r) |
Bug Bounty | 2020-05-17 | 2023-06-13 |
3410 | The Accidental RCE |
Unrestricted file upload |
NA |
Mr. Beast (@__mr_beast__) |
Bug Bounty | 2020-06-09 | 2023-06-13 |
3404 | Guest Blog: From File Upload to RCE |
Unrestricted file upload
RCE |
NA |
Lukasz Wierzbicki (@v13rs8a) |
Bug Bounty | 2020-06-10 | 2023-06-13 |
3362 | Bypassing file upload filter by source code review in Bolt CMS |
RCE
Unrestricted file upload
Path traversal
Security code review |
Bolt CMS |
Sivanesh Ashok (@sivaneshashok) |
Bug Bounty | 2020-06-27 | 2023-06-13 |
3331 | RCE via image upload functionality |
Unrestricted file upload
RCE |
NA |
Adwaith KS |
Bug Bounty | 2020-07-05 | 2023-06-13 |
3269 | XSS, RCE & HTML File Upload in same endpoint |
XSS
RCE
Unrestricted file upload |
NA |
Tarikul Islam (@sa1tama0) |
Bug Bounty | 2020-07-29 | 2023-06-13 |
3143 | Unauthenticated File upload Vulnerability on Synology Sub-domain |
Unrestricted file upload |
Synology |
Touhid Shaikh |
Bug Bounty | 2020-09-20 | 2023-06-13 |
2905 | Unrestricted File Upload |
Unrestricted file upload |
NA |
Binamra Pandey |
Bug Bounty | 2021-01-12 | 2023-06-13 |
2885 | How I was rewarded a $1000 bounty after abusing File Upload functionality to Stored XSS Vulnerability leading to credential theft of a vistor in a website. |
Unrestricted file upload
Stored XSS |
NA |
Kunal Khubchandani (@iamkun4l) |
Bug Bounty | 2021-01-18 | 2023-06-13 |
2755 | Bragging Rights: Killing File Uploads softly |
Unrestricted file upload
Stored XSS |
NA |
Manas Harsh (@ManasH4rsh) |
Bug Bounty | 2021-02-28 | 2023-06-13 |
2721 | Finding keys under the door |
Stored XSS
Unrestricted file upload |
Paytm |
Naveen Prakaasham K S V |
Bug Bounty | 2021-03-12 | 2023-06-13 |
2666 | RCE on Starbucks Singapore and more for $5600 |
RCE
Unrestricted file upload |
Starbucks |
Kamil Onur Özkaleli (@ko2sec) |
Bug Bounty | 2021-04-04 | 2023-06-13 |
2630 | Exploiting Unrestricted File Upload to achieve Remote Code Execution on a bug bounty program |
Unrestricted file upload
RCE |
NA |
Jadek Mark (@mase289) |
Bug Bounty | 2021-04-18 | 2023-06-13 |
2464 | Exploiting File Upload Functionality in Unique Way. |
Unrestricted file upload |
NA |
Rohit Soni (@streetofhacker) |
Bug Bounty | 2021-06-19 | 2023-06-13 |
2363 | From Hobby to Hacking |
Unrestricted file upload
RCE
Missing authentication |
NA |
Muhammad Syahrul Haniawan (@b0x_in) |
Bug Bounty | 2021-07-31 | 2023-06-13 |
2252 | Bypassed! and uploaded a sweet reverse shell |
Unrestricted file upload |
NA |
Ajay Sharma (@security_donut) |
Bug Bounty | 2021-09-05 | 2023-06-13 |
2142 | Independently Secure, Together Not So Much – A Story Of 2 WP Plugins |
RCE
Race condition
Unrestricted file upload
Security code review |
NA |
Adrian Tiron (@Adrian__T) |
Bug Bounty | 2021-10-17 | 2023-06-13 |
2089 | Unrestricted File Upload Leads to SSRF and RCE |
ImageTragick
Unrestricted file upload
SSRF
RCE |
NA |
Muhammad Adel (@ItsFadinG_) |
Bug Bounty | 2021-11-11 | 2023-06-13 |
2009 | File Upload to RCE |
Unrestricted file upload |
NA |
Ahmed Magdy (@8Ahmed88Magdy8) |
Bug Bounty | 2021-12-09 | 2023-06-13 |
1988 | Stored XSS by bypassing signature |
XSS
Unrestricted file upload |
NA |
Abdulrahman Makki (@AMakki1337) |
Bug Bounty | 2021-12-20 | 2023-06-13 |
1969 | XSS via file upload |
XSS
Unrestricted file upload |
NA |
Jay Sharma |
Bug Bounty | 2021-12-27 | 2023-06-13 |