4813 | Reflected XSS on www.zomato.com By Mustafa Hasan |
Reflected XSS |
Zomato |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2018-04-07 | 2023-06-13 |
4812 | Stealing HttpOnly Cookie via XSS |
XSS |
NA |
Yasser Gersy (@yassergersy) |
Bug Bounty | 2018-04-08 | 2023-06-13 |
4811 | Piercing the veil: Server Side Request Forgery to NIPRNet access |
SSRF |
U.S. Dept Of Defense |
Alyssa Herrera (@Alyssa_Herrera_) |
Bug Bounty | 2018-04-09 | 2023-06-13 |
4810 | Source Code Analysis in YSurvey — Luminate bug |
Authentication bypass
Authorization flaw
SQL injection |
Yahoo! / Verizon Media |
Rojan Rijal (@uraniumhacker) |
Bug Bounty | 2018-04-10 | 2023-06-13 |
4809 | How I broke into Google Issue Tracker |
Logic flaw
Authorization flaw |
Google |
Abhishek Bundela (@abhibundela) |
Bug Bounty | 2018-04-10 | 2023-06-13 |
4808 | Please email me your password |
Blind XSS
Blind SQL injection
SMTP injection
Account takeover |
NA |
Jasmin Laundry (@JR0ch17) |
Bug Bounty | 2018-04-11 | 2023-06-13 |
4807 | Hijacking User’s Private Information access_token from Microsoft Office360 facebook App |
Logic flaw |
Microsoft |
Mohamed A. Baset |
Bug Bounty | 2018-04-13 | 2023-06-13 |
4806 | How I bypassed Ebay process on redirect |
Open redirect |
Ebay |
Mohamed Sayed (@FlEx0Geek) |
Bug Bounty | 2018-04-13 | 2023-06-13 |
4805 | How I hacked companies related to the crypto currency and earned $60,000 |
Authorization flaw
CSRF
IDOR
Stored XSS
HTML injection |
okex.com
livecoin.net |
Max (@0xw2w) |
Bug Bounty | 2018-04-14 | 2023-06-13 |
4804 | Bypass CSP by Abusing XSS Filter in Edge |
CSP bypass |
Microsoft |
Xiaoyin Liu (@general_nfs) |
Bug Bounty | 2018-04-15 | 2023-06-13 |
4803 | #SecurityBreach — "How I was able to book hotel room for 1.50₹!" |
CORS misconfiguration |
NA |
Hariom Vashisth |
Bug Bounty | 2018-04-15 | 2023-06-13 |
4802 | $5k Service dependencies |
Logic flaw |
Google |
Ezequiel Pereira (@epereiralopez) |
Bug Bounty | 2018-04-16 | 2023-06-13 |
4801 | Bypassing Captcha Like a Boss |
Captcha bypass |
NA |
Ak1T4 (@akita_zen) |
Bug Bounty | 2018-04-16 | 2023-06-13 |
4800 | Spoof an user to create a description of a group in Flickr |
IDOR |
Flickr |
Samuel (@saamux) |
Bug Bounty | 2018-04-16 | 2023-06-13 |
4799 | From an error message to DB disclosure |
Hardcoded credentials |
NA |
Yumi |
Bug Bounty | 2018-04-17 | 2023-06-13 |
4798 | How I got stored XSS using file upload |
Stored XSS |
NA |
gujjuboy10x00 (@vis_hacker) |
Bug Bounty | 2018-04-17 | 2023-06-13 |
4797 | IDOR (at Private Bug Bounty Program) that could Leads to Personal Data Leaks |
IDOR |
NA |
YoKo Kho (@YokoAcc) |
Bug Bounty | 2018-04-17 | 2023-06-13 |
4796 | How I Get the Name of the Hotel (and other Data) that you ever Stay - Personal Data Leaks: Private Bug Bounty Program |
IDOR |
NA |
YoKo Kho (@YokoAcc) |
Bug Bounty | 2018-04-18 | 2023-06-13 |
4795 | Ribose — IDOR with Simple CSRF Bypass — Unrestricted Changes and Deletion to other Photo Profile |
IDOR |
Ribose |
YoKo Kho (@YokoAcc) |
Bug Bounty | 2018-04-18 | 2023-06-13 |
4794 | Whatsapp user’s IP disclosure with Link Preview feature |
Information disclosure |
Meta / Facebook |
Rahul Kankrale (@RahulKankrale) |
Bug Bounty | 2018-04-18 | 2023-06-13 |
4793 | Google Bug: Posting on groups as any user’s behalf |
Email spoofing |
Google |
ssid (@newp_th) |
Bug Bounty | 2018-04-18 | 2023-06-13 |
4792 | Bypassing the Current Password Protection at PayPal TechSupport Portal |
Authorization flaw
Account takeover |
Paypal |
YoKo Kho (@YokoAcc) |
Bug Bounty | 2018-04-19 | 2023-06-13 |
4791 | #BugBounty — "Journey from LFI to RCE!!!"-How I was able to get the same in one of the India’s popular property buy/sell company. |
LFI
RCE |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-04-19 | 2023-06-13 |
4790 | Story Of a Stored XSS Bypass |
Stored XSS |
NA |
Prial Islam Khan (@prial261) |
Bug Bounty | 2018-04-21 | 2023-06-13 |
4789 | Turning Self-XSS into non-Self Stored-XSS via Authorization Issue at “PayPal Tech-Support and Brand Central Portal |
Stored XSS |
Paypal |
YoKo Kho (@YokoAcc) |
Bug Bounty | 2018-04-21 | 2023-06-13 |