4509 | #BugBounty — How I was able to download the Source Code of India’s Largest Telecom Service Provider including dozens of more popular websites! |
.git folder disclosure
Source code disclosure |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-10-27 | 2023-06-13 |
4508 | Journey through Google referer leakage bugs. |
Information disclosure
Referer leakage |
Google |
KL Sreeram (@kl_sree) |
Bug Bounty | 2018-10-28 | 2023-06-13 |
4507 | Improper CSRF token handling leads to site-wide CSRF issue, chained with clickjacking = woot! Multiple sites vulnerable |
CSRF
Clickjacking |
NA |
Zseano (@zseano) |
Bug Bounty | 2018-10-29 | 2023-06-13 |
4506 | CVE-2018-9411: New critical vulnerability in multiple high-privileged Android services |
Memory corruption |
Google |
Tamir Zahavi-Brunner (@tamir_zb) |
Bug Bounty | 2018-10-30 | 2023-06-13 |
4505 | IDOR in JWT and the shortest token you will ever see {}.{“uid”: “1234567890”} |
IDOR |
NA |
Plenum (@plenumlab) |
Bug Bounty | 2018-10-30 | 2023-06-13 |
4504 | CSRF %27protection%27 bypass on xvideos |
CSRF |
xvideos |
Zseano (@zseano) |
Bug Bounty | 2018-10-30 | 2023-06-13 |
4503 | It’s all in the detail: Email leak & Account takeover thanks to WayBackMachine & extensive knowledge about the program |
Information disclosure
Authentication bypass
Account takeover |
NA |
Zseano (@zseano) |
Bug Bounty | 2018-10-30 | 2023-06-13 |
4502 | Bypass HackerOne 2FA requirement and reporter blacklist |
Logic flaw
MFA bypass
Authentication flaw |
HackerOne |
Japz Divino (@japzdivino) |
Bug Bounty | 2018-10-31 | 2023-06-13 |
4501 | Stored XSS in Bug Bounty |
Stored XSS |
NA |
KatsuragiCSL (@ZuuitterE) |
Bug Bounty | 2018-11-01 | 2023-06-13 |
4500 | P1 Like a Boss | Information Disclosure via Github leads to Employee Account Takeover | Bug Bounty POC |
Information disclosure |
NA |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2018-11-01 | 2023-06-13 |
4499 | Finding hidden gems vol. 3: quick win with .sh file |
Information disclosure |
NA |
Mateusz Olejarka (@molejarka) |
Bug Bounty | 2018-11-01 | 2023-06-13 |
4498 | CVE-2018-11759 – Apache mod_jk access control bypass |
Path traversal |
Apache HTTP Server |
Raphaël Arrouas |
Bug Bounty | 2018-11-01 | 2023-06-13 |
4497 | Imagemagick GIF coder vulnerability leads to memory disclosure (Hackerone) |
Memory leak
Outdated component with a known vulnerability |
HackerOne |
Kunal pandey (@kunalp94) |
Bug Bounty | 2018-11-02 | 2023-06-13 |
4496 | How Outdated JIRA Instances suffers from multiple security vulnerabilities? |
XSS
SSRF |
Visma |
Yeasir Arafat |
Bug Bounty | 2018-11-13 | 2023-06-13 |
4495 | Full Account Takeover via Referer Header (OAuth token Steal, Open Redirect Vulnerability Chaining) |
Open redirect
Token leak
Account takeover |
NA |
Muhammad Asim Shahzad (@protector47) |
Bug Bounty | 2018-11-03 | 2023-06-13 |
4494 | Unauthenticated RSFTP to Command Injection |
Path traversal
RCE |
NA |
Nicodemo Gawronski |
Bug Bounty | 2018-11-03 | 2023-06-13 |
4493 | Duplicate but still cool |
IDOR
Account takeover |
NA |
Plenum (@plenumlab) |
Bug Bounty | 2018-11-05 | 2023-06-13 |
4492 | Evernote For Windows Read Local File and Command Execute Vulnerabilities |
Stored XSS
LFI
RCE |
Evernote |
TongQing Zhu |
Bug Bounty | 2018-11-05 | 2023-06-13 |
4491 | XSS in Dynamics 365 |
XSS |
Microsoft |
Tim Kent (@__timk) |
Bug Bounty | 2018-11-06 | 2023-06-13 |
4490 | WordPress Design Flaw Leads to WooCommerce RCE |
RCE |
Automattic (WooCommerce) |
Simon Scannell (@scannell_simon) |
Bug Bounty | 2018-11-06 | 2023-06-13 |
4489 | Vine User’s Private information disclosure |
IDOR
Information disclosure |
Vine |
Prial Islam Khan (@prial261) |
Bug Bounty | 2018-11-07 | 2023-06-13 |
4488 | How I earned 5040$ from Twitter by showing a way to Harvest other users IP address |
Information disclosure |
Twitter |
Prial Islam Khan (@prial261) |
Bug Bounty | 2018-11-07 | 2023-06-13 |
4487 | Object name Exposure — ING Bank Responsible Disclosure Program |
Information disclosure |
ING Bank |
Rohit kumar (@rohitcoder) |
Bug Bounty | 2018-11-08 | 2023-06-13 |
4486 | #bugbounty How I Takeover Microsoft Store. |
Subdomain takeover |
Microsoft |
Sadiq West |
Bug Bounty | 2018-11-08 | 2023-06-13 |
4485 | CVE-2018-9539: Use-after-free vulnerability in privileged Android service |
Memory corruption
Use-After-Free |
Google |
Tamir Zahavi-Brunner (@tamir_zb) |
Bug Bounty | 2018-11-09 | 2023-06-13 |