4376 | Facebook Android Application |
Authorization flaw |
Meta / Facebook |
Ashley King (@AshleyKingUK) |
Bug Bounty | 2019-01-05 | 2023-06-13 |
4375 | How I hacked Altervista.org |
Open redirect |
Altervista |
Jacopo Tediosi (@jacopotediosi) |
Bug Bounty | 2019-01-05 | 2023-06-13 |
4374 | Stored XSS Via Alternate Text At Zendesk Support |
Stored XSS |
Zendesk |
Hariharan.s (@DJHARIZ1) |
Bug Bounty | 2019-01-06 | 2023-06-13 |
4373 | Reflected XSS ON ASUS. |
Reflected XSS |
Asus |
Thejus Krishnan |
Bug Bounty | 2019-01-06 | 2023-06-13 |
4372 | When Cookie Hijacking + HTML Injection become dangerous |
Cookie hijacking
HTML injection |
NA |
Daniel V. (@d4niel_v) |
Bug Bounty | 2019-01-07 | 2023-06-13 |
4371 | Tips for bug bounty beginners from a real life experience |
XSS
SQL injection |
YNAB |
Renaud Martinet (@karouf) |
Bug Bounty | 2019-01-08 | 2023-06-13 |
4369 | Facebook PageAnalyst Could Add oneself as Moderator on Group |
Authorization flaw |
Meta / Facebook |
onehackzero |
Bug Bounty | 2019-01-11 | 2023-06-13 |
4368 | Workplace Logo ID to workplace owner name Disclosure Facebook Bug Bounty |
IDOR |
Meta / Facebook |
Ajay Gautam (@evilboyajay) |
Bug Bounty | 2019-01-11 | 2023-06-13 |
4367 | Turning Self XSS to good XSS via access control |
Stored XSS
Self-XSS |
NA |
Yusuf Yazir (@Hacklad) |
Bug Bounty | 2019-01-13 | 2023-06-13 |
4366 | Gaining access to Uber%27s user data through AMPScript evaluation |
AMPScript injection |
Uber |
Shubham Shah (@infosec_au) |
Bug Bounty | 2019-01-14 | 2023-06-13 |
4365 | Abusing MySQL clients to get LFI from the server/client |
LFI |
NA |
Jarkko Vesiluoma (@jvesiluoma) |
Bug Bounty | 2019-01-15 | 2023-06-13 |
4364 | #BugBounty How I Hack Billion $ Company |
Directory listing |
NA |
Sadiq West |
Bug Bounty | 2019-01-15 | 2023-06-13 |
4363 | Facebook Vulnerability: Unremovable facebook group admin |
Logic flaw |
Meta / Facebook |
Ritish Kumar Singh |
Bug Bounty | 2019-01-15 | 2023-06-13 |
4362 | Command Injection PoC |
OS command injection |
NA |
NoGe (@p4c3n0g3) |
Bug Bounty | 2019-01-15 | 2023-06-13 |
4361 | Bypass Content Security Policy framing restriction rule - OLX |
CSP bypass |
OLX |
Taha Ibrahim Draidia |
Bug Bounty | 2019-01-17 | 2023-06-13 |
4360 | XSS Through SWF file! |
Flash XSS |
NA |
Friendly (@SkeletorKeys) |
Bug Bounty | 2019-01-18 | 2023-06-13 |
4359 | Oauth Misconfiguration lead to complete account takeover |
CSRF
OAuth
Account takeover |
NA |
Jackson kv (@Jacksonkv22) |
Bug Bounty | 2019-01-20 | 2023-06-13 |
4358 | A Simple CORS Misconfig Leaked Private Post Of Twitter, Facebook & Instagram |
CORS misconfiguration |
NA |
Rohan aggarwal (@nahoragg) |
Bug Bounty | 2019-01-20 | 2023-06-13 |
4357 | Reflected XSS in Zomato |
Reflected XSS |
Zomato |
Sudhanshu Rajbhar (@sudhanshur705) |
Bug Bounty | 2019-01-21 | 2023-06-13 |
4345 | Frappé Technologies ERPNext Server Side Template Injection |
SSTI |
ERPNext |
Brian Hyde (@0xHyde) |
Bug Bounty | 2019-01-23 | 2023-06-13 |
4343 | Antihack.me Blind XSS To PHP File Upload Vulnerability |
Blind XSS |
AntiHack.me |
SayCure (@SaycureIO) |
Bug Bounty | 2019-01-24 | 2023-06-13 |
4342 | Magento – RCE & Local File Read with low privilege admin rights |
LFI
RCE
Path traversal |
Magento |
Daniel Le Gall (@Blaklis_) |
Bug Bounty | 2019-01-24 | 2023-06-13 |
4341 | How I abused 2FA to maintain persistence after a password change (Google, Microsoft, Instagram, Cloudflare, etc) |
Logic flaw
Authentication flaw |
Google
Microsoft
Meta / Facebook |
Luke Berner |
Bug Bounty | 2019-01-25 | 2023-06-13 |
4340 | Facebook Change Product Availability as a PageAnalyst |
Logic flaw
Authorization flaw |
Meta / Facebook |
onehackzero |
Bug Bounty | 2019-01-25 | 2023-06-13 |
4339 | AntiHack IDOR on Create Submission |
IDOR |
AntiHack.me |
Syahrul Akbar Rohmani (@sahruldotid) |
Bug Bounty | 2019-01-26 | 2023-06-13 |