1942 | SQL Injection - The File Upload Playground |
Unrestricted file upload
SQL injection |
NA |
Jerry Shah (@Jerry) |
Bug Bounty | 2022-01-04 | 2023-06-13 |
1872 | Remote Code Execution in .tgz File Upload |
RCE
Unrestricted file upload |
NA |
Nick Berrie (@machevalia) |
Bug Bounty | 2022-01-30 | 2023-06-13 |
1809 | Advisory: Cisco RV340 Dual WAN Gigabit VPN Router (RCE over LAN) |
RCE
Unrestricted file upload
OS command injection |
Cisco |
Quentin Kaiser (@QKaiser) |
Bug Bounty | 2022-02-17 | 2023-06-13 |
1735 | Achieving Remote Code Execution via Unrestricted File Upload |
Unrestricted file upload
RCE |
NA |
Haroon Hameed (@HaroonHameed40) |
Bug Bounty | 2022-03-14 | 2023-06-13 |
1608 | Exploiting a File Upload Vulnerability — A Directory Traversal Attack |
Unrestricted file upload
Path traversal |
NA |
Kwadwo Amoako |
Bug Bounty | 2022-04-20 | 2023-06-13 |
1582 | Hacking a Bank by Finding a 0day in DotCMS |
Directory traversal
Unrestricted file upload
RCE |
NA |
Shubham Shah (@infosec_au) |
Bug Bounty | 2022-05-03 | 2023-06-13 |
1567 | How I Paid For My Holiday With Bug Bounty |
XSS
Broken Access Control
IDOR
Unrestricted file upload |
NA |
Tobydavenn |
Bug Bounty | 2022-05-08 | 2023-06-13 |
1566 | Can analyzing javascript files lead to remote code execution? |
Unrestricted file upload
RCE |
NA |
Asem Eleraky (@melotover) |
Bug Bounty | 2022-05-08 | 2023-06-13 |
1286 | How I earned 500$ by uploading a file: write-up of one of my first bug bounty |
Unrestricted file upload |
Semrush |
Riccardo Malatesta (@seeu_inspace) |
Bug Bounty | 2022-08-02 | 2023-06-13 |
1242 | File Upload Bypass to RCE == $$$$ |
Unrestricted file upload
RCE |
NA |
Sagar Sajeev (@Sagar__Sajeev) |
Bug Bounty | 2022-08-12 | 2023-06-13 |
1210 | RCE on Spip and Root-Me, v2! |
RCE
SSTI
DNS rebinding
XSS
Code injection
Unrestricted file upload |
SPIP |
Laluka (@TheLaluka) |
Bug Bounty | 2022-08-16 | 2023-06-13 |
1100 | Riding The Inforail To Exploit Ivanti Avalanche Part 2 |
RCE
Insecure deserialization
Path traversal
Authentication bypass
Unrestricted file upload
Arbitrary file write
Arbitrary file read |
Ivanti |
Piotr Bazydło (@chudyPB) |
Bug Bounty | 2021-09-08 | 2023-06-13 |
1081 | How I abused the file upload function to get a high severity vulnerability in Bug Bounty |
Unrestricted file upload
Information disclosure |
NA |
Omar Hashem (@OmarHashem666) |
Bug Bounty | 2022-09-14 | 2023-06-13 |
984 | Persistent PHP Payloads In PNGs: How To Inject PHP Code In An Image – And Keep It There ! |
Unrestricted file upload
Code injection
RCE |
NA |
Quentin Roland (@ROLANDQuentin2) |
Bug Bounty | 2022-10-10 | 2023-06-13 |
930 | 23000$ for Authentication Bypass & File Upload & Arbitrary File Overwrite |
JWT
Authentication bypass
Arbitrary file write
Unrestricted file upload |
NA |
Souhaib Naceri (@h4x0r_dz) |
Bug Bounty | 2022-10-19 | 2023-06-13 |
868 | Case of Admin Bypass for RCE, XSS, and Information Disclosure |
RCE
Unrestricted file upload
Stored XSS
Information disclosure |
NA |
Sam Paredes (@caffeinevulns) |
Bug Bounty | 2022-11-03 | 2023-06-13 |
867 | How I hacked into a Cambridge’s server and got appreciation letter. |
Unrestricted file upload
RCE |
Cambridge |
Prathamrajgor |
Bug Bounty | 2022-11-04 | 2023-06-13 |
864 | PENTEST TALES: EXIF Data Manipulation |
Unrestricted file upload
Stored XSS |
NA |
Armand Jasharaj |
Bug Bounty | 2022-11-05 | 2023-06-13 |
808 | Remote Command Execution in a Bank Server |
RCE
Arbitrary file read
Unrestricted file upload |
NA |
Bipin Jitiya (@win3zz) |
Bug Bounty | 2022-11-18 | 2023-06-13 |
755 | Unrestricted file upload in Rocket TRUfusion Enterprise <= 7.9.6.0 |
Unrestricted file upload
Security code review
RCE |
Rocket Software |
Mehdi Elyassa |
Bug Bounty | 2022-11-30 | 2023-06-13 |
702 | Not usual CSP bypass case |
Unrestricted file upload
XSS
CSP bypass |
NA |
Karol Mazurek |
Bug Bounty | 2022-12-12 | 2023-06-13 |
648 | How I found multiple critical bugs in Red Bull |
Authentication bypass
HTTP response manipulation
Path traversal
LFI
XSS
SQL injection
RCE
Unrestricted file upload
RFI
Security code review |
Red Bull |
Bartłomiej Bergier (@_bergee_) |
Bug Bounty | 2022-12-26 | 2023-06-13 |
609 | Uploading the Webshell using filename of Content-Disposition Header Story! |
Unrestricted file upload
Arbitrary file write |
NA |
Yashar Mohagheghi |
Bug Bounty | 2023-01-09 | 2023-06-13 |
607 | Lexmark MC3224adwe RCE exploit |
RCE
SSRF
Printer hacking
Unrestricted file upload
Local Privilege Escalation |
Lexmark |
blasty (@bl4sty) |
Bug Bounty | 2023-01-09 | 2023-06-13 |
585 | CVE-2022-21587 (Oracle E-Business Suite Unauthenticated RCE) |
RCE
Unrestricted file upload
Zip Slip attack |
Oracle |
@vudq16 |
Bug Bounty | 2023-01-16 | 2023-06-13 |