5089 | Remote Code Execution in AT&T |
RCE
SSTI
Components with known vulnerabilities |
AT&T |
Corben Leo (@hacker_) |
Bug Bounty | 2017-03-10 | 2023-06-13 |
5088 | Airbnb – Ruby on Rails String Interpolation led to Remote Code Execution |
RCE |
Airbnb |
Brett Buerhaus (@bbuerhaus) |
Bug Bounty | 2017-03-13 | 2023-06-13 |
5073 | Pivoting from blind SSRF to RCE with HashiCorp Consul |
Blind XSS
RCE |
NA |
Peter Adkins (@darkarnium) |
Bug Bounty | 2017-05-29 | 2023-06-13 |
5063 | How I got 5500$ from Yahoo for RCE |
RCE |
Yahoo! / Verizon Media |
Th3G3nt3lman (@Th3G3nt3lman) |
Bug Bounty | 2017-06-04 | 2023-06-13 |
5049 | CVE-2017-10711: Reflected XSS vulnerability in SimpleRisk – Open Source Risk Management System |
Reflected XSS |
SimpleRisk |
Mohamed A. Baset |
Bug Bounty | 2017-06-28 | 2023-06-13 |
5022 | May the Shells be with You - A Star Wars RCE Adventure! |
RCE |
NA |
Andy Gill (@ZephrFish) |
Bug Bounty | 2017-07-22 | 2023-06-13 |
5015 | How I Chained 4 vulnerabilities on GitHub Enterprise, From SSRF Execution Chain to RCE! |
SSRF
RCE
CRLF injection
Insecure deserialization |
GitHub |
Orange Tsai (@orange_8361) |
Bug Bounty | 2017-07-28 | 2023-06-13 |
5002 | Secure Your Jenkins Instance Or Hackers Will Force You To! (Snapchat’s $5,000 Vulnerability) |
RCE
LFI
Exposed Jenkins instance |
Snapchat |
Ben Sadeghipour (@nahamsec) |
Bug Bounty | 2017-08-22 | 2023-06-13 |
4999 | Upgrade from LFI to RCE via PHP Sessions |
LFI
RCE |
NA |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2017-08-28 | 2023-06-13 |
4998 | Bypassing Rate Limit Protection by spoofing originating IP |
Bruteforce |
NA |
Arbaz Hussain (@ArbazKiraak) |
Bug Bounty | 2017-08-30 | 2023-06-13 |
4966 | How I could have mass uploaded from every Flickr account! |
Bruteforce |
Flickr |
Jazzy (@ret2got) |
Bug Bounty | 2017-10-05 | 2023-06-13 |
4962 | Exploiting Insecure Cross Origin Resource Sharing ( CORS ) | api.artsy.net |
CORS misconfiguration |
Artsy |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2017-10-10 | 2023-06-13 |
4955 | Sensitive data exposure by requesting a resource with a different content type |
Information disclosure |
NA |
Yogendra Jaiswal (@vulnh0lic) |
Bug Bounty | 2017-10-17 | 2023-06-13 |
4926 | Taking note: XSS to RCE in the Simplenote Electron client |
XSS
RCE |
Automattic |
Yasin Soliman (@SecurityYasin) |
Bug Bounty | 2017-11-22 | 2023-06-13 |
4921 | LFI to Command Execution: Deutche Telekom Bug Bounty |
LFI
RCE |
Deutche Telekom |
Daniel Maksimovic |
Bug Bounty | 2017-11-30 | 2023-06-13 |
4919 | Getting a RCE — CTF Way |
RCE |
NA |
Rojan Rijal (@uraniumhacker) |
Bug Bounty | 2017-12-05 | 2023-06-13 |
4912 | LFI to 10 servers pwn |
LFI
RCE |
NA |
Nirmal Dahal (@TheNittam) |
Bug Bounty | 2017-12-19 | 2023-06-13 |
4911 | Unrestricted File Upload to RCE | Bug Bounty POC |
RCE |
Meta / Facebook |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2017-12-19 | 2023-06-13 |
4899 | RCE Vulnerabilite in Yahoo Subdomain! ( Yahoo! RCE via Spring Engine SSTI ) By tghawkins |
RCE |
Yahoo! / Verizon Media |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2018-01-05 | 2023-06-13 |
4887 | Internshala Bug in Internshala Student Partner |
Bruteforce |
Internshala |
Circle Ninja (@circleninja) |
Bug Bounty | 2018-01-20 | 2023-06-13 |
4882 | No RCE? Then SSH to the box! |
LFI
Path traversal
RCE |
NA |
Jasmin Laundry (@JR0ch17) |
Bug Bounty | 2018-01-25 | 2023-06-13 |
4864 | I figured out a way to hack any of Facebook’s 2 billion accounts, and they paid me a $15,000 bounty for it |
Bruteforce
Account takeover |
Meta / Facebook |
Anand Prakash (@anandpraka_sh) |
Bug Bounty | 2018-02-09 | 2023-06-13 |
4853 | [RCE] Remote Code Execution in Wordpress iOS Application (version 9.3) |
RCE
iOS |
WordPress |
Evan Ricafort (@evanricafort) |
Bug Bounty | 2018-02-21 | 2023-06-13 |
4847 | #BugBounty — API keys leakage, Source code disclosure in India’s largest e-commerce health care company. |
Path traversal |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-02-25 | 2023-06-13 |
4846 | How i Hacked into a bugcrowd. public program |
RCE |
NA |
Vishnuraj |
Bug Bounty | 2018-02-25 | 2023-06-13 |