4610 | Facebook Bug Bounty! {Permission Bug} |
Authorization flaw
Logic flaw |
Meta / Facebook |
Ali Tütüncü (@alicanact60) |
Bug Bounty | 2018-09-05 | 2023-06-13 |
4609 | P1 Vulnerability in 60 seconds |
Information disclosure
File disclosure |
NA |
Wh11teW0lf (@wh11tew0lf) |
Bug Bounty | 2018-09-05 | 2023-06-13 |
4608 | How I could download the source code of an Indian e-commerce website!! |
File disclosure
Source code disclosure |
NA |
Minali Arora (@AroraMinali) |
Bug Bounty | 2018-09-05 | 2023-06-13 |
4607 | #BugBounty — How Naaptol (India’s popular home shopping company) Kept their Millions of User Data at Risk! |
IDOR |
Naaptol |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-09-07 | 2023-06-13 |
4606 | Simple Login Brute Force / Current Password Requirement Bypass |
IDOR
Account takeover
Bruteforce |
NA |
Mandeep Jadon (@1337tr0lls) |
Bug Bounty | 2018-09-07 | 2023-06-13 |
4605 | Write-up - Love story, from closed as informative to $3,500 USD, XSS stored in Yahoo! iOS MaiL app |
Stored XSS |
Yahoo! / Verizon Media |
Omar Espino (@omespino) |
Bug Bounty | 2018-09-07 | 2023-06-13 |
4604 | RCE Unsecure Jenkins Instance | Bug Bounty POC |
RCE
Exposed Jenkins instance |
NA |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2018-09-07 | 2023-06-13 |
4603 | Bypassing Hotstar Premium with DOM manipulation and some JavaScript |
Logic flaw
Payment bypass |
Hotstar |
OpSecX (@OpSecX) |
Bug Bounty | 2018-09-07 | 2023-06-13 |
4602 | SQL Injection Vulnerability bootcamp.nutanix.com | Bug Bounty POC |
SQL injection |
Nutanix |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2018-09-08 | 2023-06-13 |
4601 | Reflected XSS in Google Code Jam |
Reflected XSS |
Google |
Thomas Orlita (@ThomasOrlita) |
Bug Bounty | 2018-09-08 | 2023-06-13 |
4600 | Stored XSS Vulnerability in Tumblr |
Stored XSS |
Automattic |
Anas Mahmood (@AnasIsHere) |
Bug Bounty | 2018-09-08 | 2023-06-13 |
4599 | How I find Open-Redirect Vulnerability in redacted.com (One of the top online payment processing service website) |
Open redirect |
NA |
Muhammad Asim Shahzad (@protector47) |
Bug Bounty | 2018-09-09 | 2023-06-13 |
4598 | ZOL Zimbabwe Authentication Bypass to XSS & SQLi Vulnerability – Bug Bounty POC |
XSS
SQL injection |
ZOL Zimbabwe |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2018-09-09 | 2023-06-13 |
4597 | Making the Facebook app more secure - $8500 bounty |
Open redirect |
Meta / Facebook |
Ashley King (@AshleyKingUK) |
Bug Bounty | 2018-09-09 | 2023-06-13 |
4596 | Stored XSS Vulnerability in H1C Private site |
Stored XSS |
NA |
Anas Mahmood (@AnasIsHere) |
Bug Bounty | 2018-09-09 | 2023-06-13 |
4595 | Apple Safari & Microsoft Edge Browser Address Bar Spoofing - Writeup |
Address Bar Spoofing |
Microsoft
Apple |
Rafay Baloch (@rafaybaloch) |
Bug Bounty | 2018-09-10 | 2023-06-13 |
4594 | Authentication Bypass Using SQL Injection AutoTrader Webmail – Bug Bounty POC |
SQL injection |
AutoTrader |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2018-09-10 | 2023-06-13 |
4593 | How to do 55.000+ Subdomain Takeover in a Blink of an Eye |
Subdomain takeover |
Shopify |
BuckHacker (@thebuckhacker) |
Bug Bounty | 2018-09-10 | 2023-06-13 |
4592 | XXE at Bol.com |
XXE |
Bol.com |
Jonathan Bouman (@JonathanBouman) |
Bug Bounty | 2018-09-11 | 2023-06-13 |
4591 | Hacking a Crypto Debit Card Service |
SQL injection |
Plutus |
Muhammad Abdullah |
Bug Bounty | 2018-09-11 | 2023-06-13 |
4590 | Open-Redirect Vulnerability in udacity.com |
Open redirect |
Udacity |
Anil Tom (mr_4nk) |
Bug Bounty | 2018-09-11 | 2023-06-13 |
4589 | Reflected DOM XSS and CLICKJACKING on https://silvergoldbull.de/bt.html |
DOM XSS
Clickjacking |
Silver Gold Bull |
Daniel Maksimovic |
Bug Bounty | 2018-09-13 | 2023-06-13 |
4588 | Subdomain Takeover worth 200$ |
Subdomain takeover |
Netlify |
Ali Razzaq (@AliRazzaq_) |
Bug Bounty | 2018-09-14 | 2023-06-13 |
4587 | Hacking your own antivirus for fun and profit (Safe browsing gone wrong) |
Reflected XSS |
Bullguard |
Martin Thirup Christensen (@Mthirup) |
Bug Bounty | 2018-09-14 | 2023-06-13 |
4586 | How I hijacked your account when you opened my cat picture |
Logout CSRF |
NA |
Matti Bijnens (@MattiBijnens) |
Bug Bounty | 2018-09-14 | 2023-06-13 |