4416 | #BugBounty — “User Account Takeover-I just need your email id to login into your shopping portal account” |
OAuth
Authentication bypass
Account takeover |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-12-13 | 2023-06-13 |
4403 | Exploiting Two Endpoints to get Account Takeover |
Authorization flaw
Privilege escalation |
NA |
Hritik Sharma |
Bug Bounty | 2018-12-19 | 2023-06-13 |
4395 | Tokopedia Account Takeover Bug Worth 8 Million IDR |
Password reset
Account takeover |
Tokopedia |
Mukul Lohar (@ironfisto) |
Bug Bounty | 2018-12-24 | 2023-06-13 |
4390 | How I Was Able To Takeover All User Account And Admin Panel |
IDOR
Account takeover |
NA |
Dipak kumar Das (@d1pakdas) |
Bug Bounty | 2018-12-28 | 2023-06-13 |
4389 | How I Takeover Wordpress Admin fiiipay.my |
Account takeover
CMS default files |
FiiiPay |
Syahrul Akbar Rohmani (@sahruldotid) |
Bug Bounty | 2018-12-28 | 2023-06-13 |
4377 | How I could have taken over any Pinterest account |
CSRF
Account takeover |
Pinterest |
Arnold Anthony (@armold9anthony) |
Bug Bounty | 2019-01-05 | 2023-06-13 |
4359 | Oauth Misconfiguration lead to complete account takeover |
CSRF
OAuth
Account takeover |
NA |
Jackson kv (@Jacksonkv22) |
Bug Bounty | 2019-01-20 | 2023-06-13 |
4262 | Account Takeover Using Cross-Site WebSocket Hijacking (CSWH) |
Cross-Site WebSocket Hijacking (CSWH)
Account takeover |
NA |
Sharan Panegav (@PanegavSharan) |
Bug Bounty | 2019-03-09 | 2023-06-13 |
4250 | User Account Takeover [Password Change]— Nice Catch! |
Account takeover
Password reset |
NA |
Rohit kumar (@rohitcoder) |
Bug Bounty | 2019-03-14 | 2023-06-13 |
4214 | Old but GOLD Dot Dot Slash to Get the Flag — Uber Microservice |
SSRF
Path traversal
Account takeover |
Uber |
Ron Chan (@ngalongc) |
Bug Bounty | 2019-04-07 | 2023-06-13 |
4207 | Account Takeover by chaining two vulnerabilities. |
CSRF
Open redirect
Account takeover |
NA |
Sheraz Khalid |
Bug Bounty | 2019-04-10 | 2023-06-13 |
4206 | Unauthenticated Account Takeover Through HTTP Leak |
HTML injection
HTTP Leak
Account takeover |
NA |
Nikhil (niks) (@niksthehacker) |
Bug Bounty | 2019-04-11 | 2023-06-13 |
4179 | Stealing local storage data through XSS |
Stored XSS
Account takeover |
NA |
Harshad Gaikwad (@h4rsh4d) |
Bug Bounty | 2019-04-25 | 2023-06-13 |
4169 | From Reflected XSS to Account Takeover — Showing XSS Impact |
Reflected XSS
Account takeover |
NA |
A Bug’z Life (@abugzlife1) |
Bug Bounty | 2019-04-30 | 2023-06-13 |
4164 | Why You Shouldn%27t Use a Password Manager For Your Linode Account |
Account takeover
Information disclosure |
Linode |
Utku Şen (@utkusen) |
Bug Bounty | 2019-05-02 | 2023-06-13 |
4158 | 4x CSRFs Chained For Company Account Takeover |
CSRF
Account takeover |
NA |
A Bug’z Life (@abugzlife1) |
Bug Bounty | 2019-05-08 | 2023-06-13 |
4146 | Open-redirect to Account Takeover. |
Open redirect
Account takeover |
NA |
Rishabh (@____cypher____) |
Bug Bounty | 2019-05-19 | 2023-06-13 |
4129 | My First CSRF to Account Takeover worth $750 |
CSRF
Account takeover |
NA |
Nishant Saurav (@inishantsinha) |
Bug Bounty | 2019-05-30 | 2023-06-13 |
4115 | Account takeover using IDOR and the misleading case of error 403. |
IDOR |
NA |
Plenum (@plenumlab) |
Bug Bounty | 2019-06-11 | 2023-06-13 |
4109 | IDOR — Account Takeover |
IDOR |
NA |
Saad Ahmed (@XSaadAhmedX) |
Bug Bounty | 2019-06-14 | 2023-06-13 |
4101 | Account Takeover Worth $900 |
Account takeover
CSRF |
NA |
Saad Ahmed (@XSaadAhmedX) |
Bug Bounty | 2019-06-16 | 2023-06-13 |
4091 | Account Takeover with Clickjacking |
Clickjacking |
NA |
Osama Avvan (@osamaavvan) |
Bug Bounty | 2019-06-19 | 2023-06-13 |
4089 | How a classical XSS can lead to persistent ATO Vulnerability? |
XSS
Account takeover |
NA |
Milind Purswani (@MilindPurswani) |
Bug Bounty | 2019-06-19 | 2023-06-13 |
4080 | Password Reset Vulnerability — Full Account takeover (Insecure Direct Object Reference) |
Password reset
IDOR
Account takeover |
NA |
Muhammad Asim Shahzad (@protector47) |
Bug Bounty | 2019-06-22 | 2023-06-13 |
4073 | 1-Click Account Takeover in Virgool.io — a Nice Case Study |
Account takeover
Open redirect |
NA |
Yashar Shahinzadeh (@YShahinzadeh) |
Bug Bounty | 2019-06-27 | 2023-06-13 |