4819 | Facebook BugBounty: Intercept incoming friend requests of Victim add/accept to your facebook account |
Authorization flaw |
Meta / Facebook |
Family guy |
Bug Bounty | 2018-04-02 | 2023-06-13 |
4810 | Source Code Analysis in YSurvey — Luminate bug |
Authentication bypass
Authorization flaw
SQL injection |
Yahoo! / Verizon Media |
Rojan Rijal (@uraniumhacker) |
Bug Bounty | 2018-04-10 | 2023-06-13 |
4791 | #BugBounty — "Journey from LFI to RCE!!!"-How I was able to get the same in one of the India’s popular property buy/sell company. |
LFI
RCE |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-04-19 | 2023-06-13 |
4780 | #BugBounty — How I was able to bypass firewall to get RCE and then went from server shell to get root user account! |
RCE |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-04-29 | 2023-06-13 |
4779 | How I found 2.9 RCE at Yahoo! Bug Bounty program |
RCE |
Yahoo! / Verizon Media |
Kedrisec (@kedrisec) |
Bug Bounty | 2018-04-30 | 2023-06-13 |
4760 | $36k Google App Engine RCE |
RCE |
Google |
Ezequiel Pereira (@epereiralopez) |
Bug Bounty | 2018-05-20 | 2023-06-13 |
4756 | RCE by uploading a web.config |
RCE |
NA |
003random (@rub003) |
Bug Bounty | 2018-05-22 | 2023-06-13 |
4750 | How I got hall of fame in two fortune 500 companies — An RCE story… |
RCE |
NA |
Alfie (@emenalf) |
Bug Bounty | 2018-05-29 | 2023-06-13 |
4744 | How I Earned $750 Bounty Reward From AT&T bug Bounty -Adesh Kolte |
RCE
Clickjacking
XSS
Same Origin Method Execution |
AT&T |
Adesh Nandkishor kolte (@AdeshKolte) |
Bug Bounty | 2018-06-01 | 2023-06-13 |
4732 | [PayPal BBP] I could’ve deleted All SMC messages. Using Brute-Force technique. |
CSRF |
Paypal |
Ayoub Ait Elmokhtar (@aessadek) |
Bug Bounty | 2018-06-10 | 2023-06-13 |
4730 | Server-Side Spreadsheet Injection – Formula Injection to Remote Code Execution |
CSV injection
Server side spreadsheet injection
Formula injection
RCE |
Google |
Jake Miller |
Bug Bounty | 2018-06-11 | 2023-06-13 |
4721 | [Responsible disclosure] How I could have booked movie tickets through other user accounts |
Password reset
Account takeover
Bruteforce
OTP bypass |
AGS Cinemas |
Bharathvaj Ganesan |
Bug Bounty | 2018-06-18 | 2023-06-13 |
4720 | Manage Engine OpManager Multiple Authenticated RCE Vulnerabilities |
RCE
Path traversal
Unrestricted file upload
Information disclosure
Arbitrary file write |
Zoho (ManageEngine) |
Denis Andzakovic |
Bug Bounty | 2018-06-18 | 2023-06-13 |
4707 | Unauthenticated Command Injection Vulnerability in VMware NSX SD-WAN by VeloCloud |
OS command injection
RCE |
VMware |
Brian Sullivan |
Bug Bounty | 2018-06-29 | 2023-06-13 |
4703 | Latex to RCE, Private Bug Bounty Program |
RCE |
NA |
Yashar Shahinzadeh (@YShahinzadeh) |
Bug Bounty | 2018-07-06 | 2023-06-13 |
4693 | Attacking PostgreSQL Database |
Bruteforce
Weak credentials |
NA |
Vishnuraj |
Bug Bounty | 2018-07-16 | 2023-06-13 |
4685 | RCE on Yahoo Luminate |
RCE |
Yahoo! / Verizon Media |
Rojan Rijal (@uraniumhacker) |
Bug Bounty | 2018-07-19 | 2023-06-13 |
4682 | RCE due to ShowExceptions |
RCE
Information disclosure
Debugging enabled |
NA |
Harsh Jaiswal (@rootxharsh) |
Bug Bounty | 2018-07-20 | 2023-06-13 |
4677 | Vulnerability in Hangouts Chat a.k.a. how Electron makes open redirect great again |
Open redirect
RCE |
Google |
Michał Bentkowski (@SecurityMB) |
Bug Bounty | 2018-07-24 | 2023-06-13 |
4667 | How I could access your internal servers, steal and modify your image repository |
RCE |
NA |
thehackerish (@thehackerish) |
Bug Bounty | 2018-07-31 | 2023-06-13 |
4639 | How I Chained 4 Bugs(Features?) into RCE on Amazon Collaboration System |
RCE |
Amazon |
Orange Tsai (@orange_8361) |
Bug Bounty | 2018-08-11 | 2023-06-13 |
4625 | Remote Code Execution on a Facebook server |
RCE |
Meta / Facebook |
Daniel Le Gall (@Blaklis_) |
Bug Bounty | 2018-08-24 | 2023-06-13 |
4623 | Traversing the Path to RCE |
Path traversal
RCE |
NA |
hawkinsecurity |
Bug Bounty | 2018-08-27 | 2023-06-13 |
4608 | How I could download the source code of an Indian e-commerce website!! |
File disclosure
Source code disclosure |
NA |
Minali Arora (@AroraMinali) |
Bug Bounty | 2018-09-05 | 2023-06-13 |
4606 | Simple Login Brute Force / Current Password Requirement Bypass |
IDOR
Account takeover
Bruteforce |
NA |
Mandeep Jadon (@1337tr0lls) |
Bug Bounty | 2018-09-07 | 2023-06-13 |