4748 | Account Takeover and Blind XSS! Go Pro, get Bugs! |
IDOR
Stored XSS
Account takeover
Blind XSS |
NA |
Tabahi (@_tabahi) |
Bug Bounty | 2018-05-30 | 2023-06-13 |
4729 | Full account Takeover via reset password function |
IDOR
Account takeover
Password reset |
NA |
Khaled Hassan |
Bug Bounty | 2018-06-12 | 2023-06-13 |
4717 | Using a GitHub app to escalate to an organization owner for a $10,000 bounty |
Authorization flaw
IDOR |
GitHub |
Tanner Emek (@itscachemoney) |
Bug Bounty | 2018-06-20 | 2023-06-13 |
4705 | Chaining Multiple Vulnerabilities to Gain Admin Access |
IDOR
Account takeover |
NA |
Ben Sadeghipour (@nahamsec) |
Bug Bounty | 2018-07-02 | 2023-06-13 |
4697 | Gsuite Hangouts Chat 5k IDOR |
IDOR |
Google |
Cam (@SecretlyHidden1) |
Bug Bounty | 2018-07-10 | 2023-06-13 |
4686 | How I was able to delete 13k+ Microsoft Translator projects |
CSRF
IDOR |
Microsoft |
Haider Mahmood (@haiderinfosec) |
Bug Bounty | 2018-07-19 | 2023-06-13 |
4679 | IDOR FACEBOOK: malicious person add people to the "Top Fans" |
IDOR |
Meta / Facebook |
Jafar Abo Nada (@Jafar_Abo_Nada) |
Bug Bounty | 2018-07-21 | 2023-06-13 |
4662 | #BugBounty — @Paytm Customer Information is at risk — India’s largest digital wallet company |
IDOR |
Paytm |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-08-03 | 2023-06-13 |
4650 | How I hacked a Crypto Exchange (Bug Bounty Writeup) |
IDOR |
NA |
Muhammad Abdullah |
Bug Bounty | 2018-08-07 | 2023-06-13 |
4637 | IDOR leads to getting Access tokens of users linked to Google Drive on Edmodo |
IDOR |
Edmodo |
Aagam shah (@neutrinoguy) |
Bug Bounty | 2018-08-12 | 2023-06-13 |
4634 | IDOR leads to account takeover |
IDOR |
NA |
s0cket7 (@s0cket7) |
Bug Bounty | 2018-08-16 | 2023-06-13 |
4632 | YAHOO IDOR -elimination of any comment |
IDOR |
Yahoo! / Verizon Media |
Bada Diaz (@bada77) |
Bug Bounty | 2018-08-17 | 2023-06-13 |
4626 | Privileged Escalation in Facebook Messenger Rooms |
Privilege escalation
IDOR |
Meta / Facebook |
Jafar Abo Nada (@Jafar_Abo_Nada) |
Bug Bounty | 2018-08-24 | 2023-06-13 |
4622 | IDOR FACEBOOK: malicious person add people to the “Top Fans” |
IDOR |
Meta / Facebook |
Jafar Abo Nada (@Jafar_Abo_Nada) |
Bug Bounty | 2018-08-28 | 2023-06-13 |
4607 | #BugBounty — How Naaptol (India’s popular home shopping company) Kept their Millions of User Data at Risk! |
IDOR |
Naaptol |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-09-07 | 2023-06-13 |
4606 | Simple Login Brute Force / Current Password Requirement Bypass |
IDOR
Account takeover
Bruteforce |
NA |
Mandeep Jadon (@1337tr0lls) |
Bug Bounty | 2018-09-07 | 2023-06-13 |
4584 | IDOR User Account Takeover By Connecting My Facebook Account with victims Account |
IDOR |
Meta / Facebook |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2018-09-16 | 2023-06-13 |
4573 | Bypassing Firebase authorization to create custom goo.gl subdomains |
Logic flaw
IDOR |
Google |
Thomas Orlita (@ThomasOrlita) |
Bug Bounty | 2018-09-21 | 2023-06-13 |
4562 | Just another tale of severe bugs on a private program. |
Open redirect
SSRF
IDOR
Logic flaw |
NA |
Siva Krishna Samireddi (@le4rner) |
Bug Bounty | 2018-09-28 | 2023-06-13 |
4561 | IDOR, Content Spoofing and Url Redirection via unsubscribe email in Confluent |
IDOR
Content spoofing
Open redirect |
Confluent |
Divyanshu Shukla (@justm0rph3u5) |
Bug Bounty | 2018-09-28 | 2023-06-13 |
4541 | Make any Unit in Facebook Groups Undeletable |
Logic flaw
IDOR
Authorization flaw |
Meta / Facebook |
Sarmad Hassan (@JubaBaghdad) |
Bug Bounty | 2018-10-09 | 2023-06-13 |
4539 | Get as image function pulls any Insights/NRQL data from any New Relic account (IDOR) |
IDOR |
New Relic |
Jon Bottarini (@jon_bottarini) |
Bug Bounty | 2018-10-09 | 2023-06-13 |
4533 | Add description to Instagram Posts on behalf of other users - 6500$ |
IDOR |
Meta / Facebook |
Sarmad Hassan (@JubaBaghdad) |
Bug Bounty | 2018-10-12 | 2023-06-13 |
4525 | Add comment on a private Oculus Developer bug report |
IDOR
Authorization flaw |
Meta / Facebook |
Sarmad Hassan (@JubaBaghdad) |
Bug Bounty | 2018-10-18 | 2023-06-13 |
4511 | How Misconfigured API leaked user private information? |
IDOR
Authorization flaw |
NA |
Yeasir Arafat |
Bug Bounty | 2018-10-26 | 2023-06-13 |