3242 | Reflected XSS at fotoservice.hema.nl |
Reflected XSS
Open redirect |
Hema |
Jonathan Bouman (@JonathanBouman) |
Bug Bounty | 2020-08-06 | 2023-06-13 |
3227 | How I made $2000 with URL REDIRECTION? |
Open redirect
SQL injection |
NA |
Simran Singh |
Bug Bounty | 2020-08-12 | 2023-06-13 |
3218 | Crowdsource Success Story: From an Out-of-Scope Open Redirect to CVE-2020-1323 |
Open redirect |
Microsoft |
Ozgur Alp (@ozgur_bbh) |
Bug Bounty | 2020-08-14 | 2023-06-13 |
3217 | Open Sesame: Escalating Open Redirect to RCE with Electron Code Review |
Open redirect
RCE
Security code review |
NA |
Eugene Lim (@spaceraccoonsec) |
Bug Bounty | 2020-08-14 | 2023-06-13 |
3216 | How recon helped me to find an interesting bug… |
Open redirect |
NA |
Vedant Tekale (@_justYnot) |
Bug Bounty | 2020-08-15 | 2023-06-13 |
3126 | RCE on Spip and Root-Me |
RCE
SQL injection
XSS
Open redirect
Reflected file download |
SPIP |
Laluka (@TheLaluka) |
Bug Bounty | 2020-09-29 | 2023-06-13 |
3116 | Watch your requests! Open redirect to a complete account takeover |
Path traversal
Open redirect
SSRF
Account takeover |
NA |
Suraj Disoja (@ninetyn1ne_) |
Bug Bounty | 2020-10-05 | 2023-06-13 |
3091 | GitHub Gist - Account takeover via open redirect - $10,000 Bounty |
Open redirect
Account takeover |
GitHub |
William Bowling / vakzz (@wcbowling) |
Bug Bounty | 2020-10-19 | 2023-06-13 |
3053 | 1000$ for Open redirect via unknown technique [BugBounty writeup] |
Open redirect |
GitLab |
ruvlol |
Bug Bounty | 2020-11-05 | 2023-06-13 |
3039 | Evading Filters to perform the Arbitrary URL Redirection Attack |
Open redirect |
NA |
Harsh Bothra (@harshbothra_) |
Bug Bounty | 2020-11-12 | 2023-06-13 |
3014 | Bypassing the Redirect filters with 7 ways |
Open redirect
OAuth |
NA |
ElMahdi Mrhassel (@ElMrhassel) |
Bug Bounty | 2020-11-19 | 2023-06-13 |
3013 | Exploiting dynamic rendering engines to take control of web apps |
SSRF
Open redirect |
NA |
Vasilii Ermilov (@ermil0v) |
Bug Bounty | 2020-11-19 | 2023-06-13 |
2995 | Chaining vulnerabilities lead to account takeover |
Account takeover
Password reset
Open redirect
Lack of rate limiting |
NA |
Ahmed (@ahzsec) |
Bug Bounty | 2020-12-01 | 2023-06-13 |
2985 | How Redirects work on Facebook? Technical breakdown |
Open redirect |
Meta / Facebook |
Abhisek R (@abh1sek_r) |
Bug Bounty | 2020-12-06 | 2023-06-13 |
2980 | Facebook push notification linkshim bypassed |
Open redirect |
Meta / Facebook |
Neil Mark Ochea (@nmochea) |
Bug Bounty | 2020-12-07 | 2023-06-13 |
2978 | Facebook leak referrer data |
Open redirect |
Meta / Facebook |
Neil Mark Ochea (@nmochea) |
Bug Bounty | 2020-12-08 | 2023-06-13 |
2965 | TikTok Careers Portal Account Takeover |
CSRF
Open redirect
Account takeover |
TikTok |
Lauritz Holtmann (@_lauritz_) |
Bug Bounty | 2020-12-15 | 2023-06-13 |
2903 | Stealing User Information Via XSS Via Parameter Pollution |
Open redirect
XSS |
NA |
Hamza Avvan (@hamzaavvan) |
Bug Bounty | 2021-01-12 | 2023-06-13 |
2882 | Open-redirect [in email] |
Open redirect |
NA |
Akhil |
Bug Bounty | 2021-01-19 | 2023-06-13 |
2852 | How I chained P4 To P2 [Open Redirection To Full Account Takeover] |
Open redirect
Account takeover |
NA |
Bishal Shrestha (@bishal0x01) |
Bug Bounty | 2021-01-30 | 2023-06-13 |
2838 | Open Redirect vulnerability found using link parameter |
Open redirect |
NA |
Muhammad Aamir (@Muhammad__Aamir) |
Bug Bounty | 2021-02-04 | 2023-06-13 |
2768 | Stealing user passwords through a VPN’s SSO |
Open redirect
SSTI |
NA |
Alain Mowat (@plopz0r) |
Bug Bounty | 2021-02-25 | 2023-06-13 |
2686 | How I made to Paypal Bug Bounty $750 |
Open redirect |
Paypal |
Pethuraj (@Pethuraj) |
Bug Bounty | 2021-03-28 | 2023-06-13 |
2623 | Playing With iframes: Bypassing Content-Security-Policy |
CSP bypass
Open redirect
HTML injection |
NA |
JM Sanchez / 0xEchidonut (@jmrcsnchz) |
Bug Bounty | 2021-04-20 | 2023-06-13 |
2616 | Got Nice catch by Google |
OAuth
Open redirect
CSRF |
Google |
Parth Desani (@DesaniParth) |
Bug Bounty | 2021-04-22 | 2023-06-13 |