4737 | Zero to Account Takeover: How I Impersonated’ Someone Else Using Auth0 |
Logic flaw |
Auth0 |
Daniel Svartman |
Bug Bounty | 2018-06-05 | 2023-06-13 |
4729 | Full account Takeover via reset password function |
IDOR
Account takeover
Password reset |
NA |
Khaled Hassan |
Bug Bounty | 2018-06-12 | 2023-06-13 |
4721 | [Responsible disclosure] How I could have booked movie tickets through other user accounts |
Password reset
Account takeover
Bruteforce
OTP bypass |
AGS Cinemas |
Bharathvaj Ganesan |
Bug Bounty | 2018-06-18 | 2023-06-13 |
4712 | Account Take over via reset password |
Password reset
Account takeover |
NA |
Yasser Gersy (@yassergersy) |
Bug Bounty | 2018-06-25 | 2023-06-13 |
4710 | How re-signing up for an account lead to account takeover |
Logic flaw
Account takeover |
NA |
Zseano (@zseano) |
Bug Bounty | 2018-06-26 | 2023-06-13 |
4705 | Chaining Multiple Vulnerabilities to Gain Admin Access |
IDOR
Account takeover |
NA |
Ben Sadeghipour (@nahamsec) |
Bug Bounty | 2018-07-02 | 2023-06-13 |
4699 | #BugBounty - Compromising User Account- "How I was able to compromise user account via HTTP Parameter Pollution(HPP)" |
HTTP parameter pollution
Password reset
Account takeover |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-07-07 | 2023-06-13 |
4690 | Hacking thousands of companies through their helpdesk |
Account takeover
DoS
Logic flaw |
NA |
Khaled Hassan |
Bug Bounty | 2018-07-17 | 2023-06-13 |
4651 | From data leak to account takeover |
Account takeover
Information disclosure
Password reset |
NA |
Antony Garand (@AntoGarand) |
Bug Bounty | 2018-08-07 | 2023-06-13 |
4649 | My First Critical Report |
Password reset
Account takeover |
NA |
Miguel Corral (@mcorral74) |
Bug Bounty | 2018-08-08 | 2023-06-13 |
4634 | IDOR leads to account takeover |
IDOR |
NA |
s0cket7 (@s0cket7) |
Bug Bounty | 2018-08-16 | 2023-06-13 |
4606 | Simple Login Brute Force / Current Password Requirement Bypass |
IDOR
Account takeover
Bruteforce |
NA |
Mandeep Jadon (@1337tr0lls) |
Bug Bounty | 2018-09-07 | 2023-06-13 |
4584 | IDOR User Account Takeover By Connecting My Facebook Account with victims Account |
IDOR |
Meta / Facebook |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2018-09-16 | 2023-06-13 |
4583 | User Account takeover in India’s largest digital business company |
Account takeover
OTP bypass |
NA |
Minali Arora (@AroraMinali) |
Bug Bounty | 2018-09-16 | 2023-06-13 |
4572 | R-XSS -> CSRF bypass to account takeover/ |
Reflected XSS
CSRF |
NA |
Nirmal Dahal (@TheNittam) |
Bug Bounty | 2018-09-21 | 2023-06-13 |
4522 | A possibility of Account Takeover in Medium |
Account takeover
Logic flaw |
Medium |
Prashant Kumar (@notsoshant) |
Bug Bounty | 2018-10-20 | 2023-06-13 |
4513 | CSRF account takeover Explained Automated/Manual — Bug Bounty |
CSRF
Account takeover |
OpenMenu |
Vulnerables |
Bug Bounty | 2018-10-26 | 2023-06-13 |
4503 | It’s all in the detail: Email leak & Account takeover thanks to WayBackMachine & extensive knowledge about the program |
Information disclosure
Authentication bypass
Account takeover |
NA |
Zseano (@zseano) |
Bug Bounty | 2018-10-30 | 2023-06-13 |
4500 | P1 Like a Boss | Information Disclosure via Github leads to Employee Account Takeover | Bug Bounty POC |
Information disclosure |
NA |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2018-11-01 | 2023-06-13 |
4495 | Full Account Takeover via Referer Header (OAuth token Steal, Open Redirect Vulnerability Chaining) |
Open redirect
Token leak
Account takeover |
NA |
Muhammad Asim Shahzad (@protector47) |
Bug Bounty | 2018-11-03 | 2023-06-13 |
4493 | Duplicate but still cool |
IDOR
Account takeover |
NA |
Plenum (@plenumlab) |
Bug Bounty | 2018-11-05 | 2023-06-13 |
4471 | HackenProof Customer Story: Uklon |
XSS
IDOR
Blind XSS
Account takeover |
Uklon |
HackenProof (@hackenproof) |
Bug Bounty | 2018-11-16 | 2023-06-13 |
4441 | Love Story Of A Account Takeover (Chaining Host Header Injection To Takeover Someones Account) |
Host header injection |
NA |
Logical Bimboo |
Bug Bounty | 2018-11-30 | 2023-06-13 |
4425 | Token Brute-Force to Account Take-over to Privilege Escalation to Organization Take-Over |
Account takeover
Privilege escalation
Bruteforce |
NA |
Plenum (@plenumlab) |
Bug Bounty | 2018-12-10 | 2023-06-13 |
4422 | Microsoft Account Takeover Vulnerability Affecting 400 Million Users |
Subdomain takeover
OAuth |
Meta / Facebook |
Aviva Zacks |
Bug Bounty | 2018-12-11 | 2023-06-13 |