4737 | Zero to Account Takeover: How I Impersonated’ Someone Else Using Auth0 |
Logic flaw |
Auth0 |
Daniel Svartman |
Bug Bounty | 2018-06-05 | 2023-06-13 |
4736 | #BugBounty —" Database hacked of India’s Popular Sports company"-Bypassing Host Header to SQL injection to dumping Database — An unusual case of SQL injection. |
SQL injection |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-06-06 | 2023-06-13 |
4735 | How I found XSS via SSRF vulnerability -Adesh Kolte |
SSRF
XSS |
CERT-EU
Motorola
Stanford |
Adesh Nandkishor kolte (@AdeshKolte) |
Bug Bounty | 2018-06-07 | 2023-06-13 |
4734 | How I was able to list some internal information from PayPal #BugBounty |
Expression Language Injection (JSTL)
Information disclosure |
Paypal |
Adrien Jeanneau (@adrien_jeanneau) |
Bug Bounty | 2018-06-07 | 2023-06-13 |
4733 | Steam, Fire, and Paste – A Story of UXSS via DOM-XSS & Clickjacking in Steam Inventory Helper |
DOM XSS
Universal XSS
Clickjacking
Browser extension hacking |
NA |
Matthew Bryant (@IAmMandatory) |
Bug Bounty | 2018-06-08 | 2023-06-13 |
4732 | [PayPal BBP] I could’ve deleted All SMC messages. Using Brute-Force technique. |
CSRF |
Paypal |
Ayoub Ait Elmokhtar (@aessadek) |
Bug Bounty | 2018-06-10 | 2023-06-13 |
4731 | How I Found CVE-2018-8819: Out-of-Band (OOB) XXE in WebCTRL |
XXE |
NA |
Darrell Damstedt |
Bug Bounty | 2018-06-11 | 2023-06-13 |
4730 | Server-Side Spreadsheet Injection – Formula Injection to Remote Code Execution |
CSV injection
Server side spreadsheet injection
Formula injection
RCE |
Google |
Jake Miller |
Bug Bounty | 2018-06-11 | 2023-06-13 |
4729 | Full account Takeover via reset password function |
IDOR
Account takeover
Password reset |
NA |
Khaled Hassan |
Bug Bounty | 2018-06-12 | 2023-06-13 |
4728 | Unvalidated Open Redirect Bol.com |
Open redirect |
Bol.com |
Jonathan Bouman (@JonathanBouman) |
Bug Bounty | 2018-06-12 | 2023-06-13 |
4727 | Vulnerability Netflix (cross-site-scripting) XSS |
Reflected XSS |
Netflix |
Bada Diaz (@bada77) |
Bug Bounty | 2018-06-13 | 2023-06-13 |
4726 | How I got paid premium plan for free on many popular websites |
Logic flaw |
NA |
Khaled Hassan |
Bug Bounty | 2018-06-13 | 2023-06-13 |
4725 | The 2.5 BTC Stored XSS |
Stored XSS |
NA |
Khaled Hassan |
Bug Bounty | 2018-06-13 | 2023-06-13 |
4724 | Reflected XSS in 360totalsecurity |
Reflected XSS |
360totalsecurity |
Taha Smily (@tahakhantaha) |
Bug Bounty | 2018-06-14 | 2023-06-13 |
4723 | Reflected Client XSS at Amazon.com |
Reflected XSS |
Amazon |
Jonathan Bouman (@JonathanBouman) |
Bug Bounty | 2018-06-15 | 2023-06-13 |
4722 | How i found blind XSS in Apple |
Blind XSS |
Apple |
Taha Smily (@tahakhantaha) |
Bug Bounty | 2018-06-18 | 2023-06-13 |
4721 | [Responsible disclosure] How I could have booked movie tickets through other user accounts |
Password reset
Account takeover
Bruteforce
OTP bypass |
AGS Cinemas |
Bharathvaj Ganesan |
Bug Bounty | 2018-06-18 | 2023-06-13 |
4720 | Manage Engine OpManager Multiple Authenticated RCE Vulnerabilities |
RCE
Path traversal
Unrestricted file upload
Information disclosure
Arbitrary file write |
Zoho (ManageEngine) |
Denis Andzakovic |
Bug Bounty | 2018-06-18 | 2023-06-13 |
4719 | I discovered a browser bug |
Browser hacking |
Mozilla
Microsoft |
Jake Archibald (@jaffathecake) |
Bug Bounty | 2018-06-20 | 2023-06-13 |
4718 | Setting arbitrary request headers in Chromium via CRLF injection |
CRLF injection |
Google |
Michał Bentkowski (@SecurityMB) |
Bug Bounty | 2018-06-20 | 2023-06-13 |
4717 | Using a GitHub app to escalate to an organization owner for a $10,000 bounty |
Authorization flaw
IDOR |
GitHub |
Tanner Emek (@itscachemoney) |
Bug Bounty | 2018-06-20 | 2023-06-13 |
4716 | XSS in Google Colaboratory + CSP bypass |
XSS
CSP bypass |
Google |
Michał Bentkowski (@SecurityMB) |
Bug Bounty | 2018-06-21 | 2023-06-13 |
4715 | How I hacked Apple.com (Unrestricted File Upload) |
Unrestricted file upload |
Apple |
Jonathan Bouman (@JonathanBouman) |
Bug Bounty | 2018-06-22 | 2023-06-13 |
4714 | Fastest Fix on Open Bug Bounty Platform |
Reflected XSS
CSRF |
Kevag Telekom GmbH |
Wen Bin KONG (@kongwenbin) |
Bug Bounty | 2018-06-24 | 2023-06-13 |
4713 | How I got access to local AWS info via Jira |
SSRF |
NA |
Coen Goedegebure (@CoenHimself) |
Bug Bounty | 2018-06-24 | 2023-06-13 |