4604 | RCE Unsecure Jenkins Instance | Bug Bounty POC |
RCE
Exposed Jenkins instance |
NA |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2018-09-07 | 2023-06-13 |
4580 | Chain The Bugs to Pwn an Organisation ( LFI + Unrestricted File Upload = Remote Code Execution ) |
LFI
Unrestricted file upload
RCE |
NA |
Armaan Pathan (@armaancrockroax) |
Bug Bounty | 2018-09-18 | 2023-06-13 |
4566 | How I got $4000 from Visma for RCE |
RCE |
Visma |
Ratnadip Gajbhiye (@scspcommunity) |
Bug Bounty | 2018-09-25 | 2023-06-13 |
4563 | #BugBounty — From finding Jenkins instance to Command Execution.Secure your Jenkins Instance! |
RCE
Exposed Jenkins instance |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-09-27 | 2023-06-13 |
4549 | GoogleMeetRoulette: Joining random meetings |
Bruteforce
Logic flaw |
Google |
Martin Vigo (@martin_vigo) |
Bug Bounty | 2018-10-04 | 2023-06-13 |
4548 | Apache Struts double evaluation RCE lottery |
RCE
Double OGNL evaluation |
Apache Struts |
Man Yue Mo (@mmolgtm) |
Bug Bounty | 2018-10-04 | 2023-06-13 |
4534 | Microsoft Edge Remote Code Execution |
RCE |
Microsoft |
Abdulrahman Alqabandi (@Qab) |
Bug Bounty | 2018-10-11 | 2023-06-13 |
4528 | Path traversal while uploading results in RCE |
Path traversal
RCE |
NA |
Harsh Jaiswal (@rootxharsh) |
Bug Bounty | 2018-10-15 | 2023-06-13 |
4509 | #BugBounty — How I was able to download the Source Code of India’s Largest Telecom Service Provider including dozens of more popular websites! |
.git folder disclosure
Source code disclosure |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-10-27 | 2023-06-13 |
4494 | Unauthenticated RSFTP to Command Injection |
Path traversal
RCE |
NA |
Nicodemo Gawronski |
Bug Bounty | 2018-11-03 | 2023-06-13 |
4492 | Evernote For Windows Read Local File and Command Execute Vulnerabilities |
Stored XSS
LFI
RCE |
Evernote |
TongQing Zhu |
Bug Bounty | 2018-11-05 | 2023-06-13 |
4490 | WordPress Design Flaw Leads to WooCommerce RCE |
RCE |
Automattic (WooCommerce) |
Simon Scannell (@scannell_simon) |
Bug Bounty | 2018-11-06 | 2023-06-13 |
4461 | XS-Searching Google’s bug tracker to find out vulnerable source code |
XS-Search
Information disclosure |
Google |
Luan Herrera (@lbherrera_) |
Bug Bounty | 2018-11-19 | 2023-06-13 |
4447 | Pwning eBay - How I Dumped eBay Japan%27s Website Source Code |
.git folder disclosure
Source code disclosure |
Ebay |
David (@slashcrypto) |
Bug Bounty | 2018-11-28 | 2023-06-13 |
4437 | GitHub Desktop RCE (OSX) |
RCE |
GitHub |
André Baptista (@0xacb) |
Bug Bounty | 2018-12-04 | 2023-06-13 |
4430 | RCE in Hubspot with EL injection in HubL |
RCE |
HubSpot |
Fyoorer (@ƒyoorer) |
Bug Bounty | 2018-12-07 | 2023-06-13 |
4425 | Token Brute-Force to Account Take-over to Privilege Escalation to Organization Take-Over |
Account takeover
Privilege escalation
Bruteforce |
NA |
Plenum (@plenumlab) |
Bug Bounty | 2018-12-10 | 2023-06-13 |
4419 | Second bite on GitLab, and some interesting Ruby functions/features |
RCE |
GitLab |
Nyangawa |
Bug Bounty | 2018-12-12 | 2023-06-13 |
4411 | Remote Code Execution on a Facebook server |
LFI
RCE
CSRF |
phpMyAdmin |
Daniel Le Gall (@Blaklis_) |
Bug Bounty | 2018-12-14 | 2023-06-13 |
4402 | Story of my two (but actually three) RCEs in SharePoint in 2018 |
RCE |
Microsoft |
Soroush Dalili (@irsdl) |
Bug Bounty | 2018-12-19 | 2023-06-13 |
4397 | Client side validation strikes again: PIN code bypass ! |
Client-side enforcement of server-side security
Authentication bypass
Authorization flaw |
Netflix
Linxo |
Davy (@RandoriSec) |
Bug Bounty | 2018-12-22 | 2023-06-13 |
4393 | RCE in nokia.com |
RCE |
Nokia |
Sampanna Chimoriya |
Bug Bounty | 2018-12-27 | 2023-06-13 |
4392 | From Hunting for a Laptop to Hunting down Remote Code Execution |
RCE
WebDAV |
Asus |
Anil Tom (mr_4nk) |
Bug Bounty | 2018-12-27 | 2023-06-13 |
4383 | How i found web shell on AntiHack.me and Awarded Gold Coin And SWAG |
RCE |
Rudra Sarkar (@rudr4_sarkar) |
AntiHack.me |
Bug Bounty | 2019-01-01 | 2023-06-13 |
4342 | Magento – RCE & Local File Read with low privilege admin rights |
LFI
RCE
Path traversal |
Magento |
Daniel Le Gall (@Blaklis_) |
Bug Bounty | 2019-01-24 | 2023-06-13 |