3462 | RCE in Google Cloud Deployment Manager |
SSRF
RCE |
Google |
Ezequiel Pereira (@epereiralopez) |
Bug Bounty | 2020-05-21 | 2023-06-13 |
3457 | How dangerous is Request Splitting, a vulnerability in Golang or how we found the RCE in Portainer and hacked Uber |
HTTP request splitting
SSRF
CRLF injection
RCE |
Uber |
Andrey Abakumov (@andrewaeva) |
Bug Bounty | 2020-05-25 | 2023-06-13 |
3443 | My Expense Report resulted in a Server-Side Request Forgery (SSRF) on Lyft |
SSRF |
Lyft |
Ben Sadeghipour (@nahamsec) |
Bug Bounty | 2020-05-29 | 2023-06-13 |
3433 | How I made $31500 by submitting a bug to Facebook |
SSRF |
Meta / Facebook |
Bipin Jitiya (@win3zz) |
Bug Bounty | 2020-05-31 | 2023-06-13 |
3430 | When it’s not only about a Kubernetes CVE… |
SSRF |
Microsoft |
Reever Zax (@ReeverZax) |
Bug Bounty | 2020-06-02 | 2023-06-13 |
3370 | Leveraging an SSRF to leak a secret API key |
SSRF |
NA |
Julien Cretel (@jub0bs) |
Bug Bounty | 2020-06-22 | 2023-06-13 |
3369 | A tale of my first ever full SSRF bug |
SSRF |
NA |
Jadek Mark (@mase289) |
Bug Bounty | 2020-06-22 | 2023-06-13 |
3346 | Story of a 2.5k Bounty — SSRF on Zimbra Led to Dump All Credentials in Clear Text |
SSRF |
Cafebazaar |
Yashar Shahinzadeh (@YShahinzadeh) |
Bug Bounty | 2020-07-02 | 2023-06-13 |
3340 | Bug bounty write-up: From SSRF to $4000 |
SSRF
RCE |
NA |
thehackerish (@thehackerish) |
Bug Bounty | 2020-07-03 | 2023-06-13 |
3330 | My First Bug: Blind SSRF Through Profile Picture Upload |
SSRF |
NA |
swaysthinking (@swaysThinking) |
Bug Bounty | 2020-07-05 | 2023-06-13 |
3326 | From . in regex to SSRF — part 3 |
SSRF
CRLF injection |
NA |
Niemiec Marcin (@xvnpw) |
Bug Bounty | 2020-07-07 | 2023-06-13 |
3307 | SSRF in import file function |
SSRF |
NA |
Rafael Silva |
Bug Bounty | 2020-07-14 | 2023-06-13 |
3258 | CVE-2020-13379 Unauthenticated Full-Read SSRF in Grafana |
SSRF
Open redirect |
NA |
Justin Gardner (@Rhynorater) |
Bug Bounty | 2020-08-01 | 2023-06-13 |
3175 | How_i_was_able_to_pawned_website_via_escilating_webcache deception to rce |
Web cache deception
SSRF
RCE |
NA |
mohit (@mohit29295572) |
Bug Bounty | 2020-09-05 | 2023-06-13 |
3163 | How I hacked redbus [An online bus-ticketing application] |
LFI
SSRF |
redBus |
Sangeetha Rajesh S (@rajesh_sangi12) |
Bug Bounty | 2020-09-12 | 2023-06-13 |
3116 | Watch your requests! Open redirect to a complete account takeover |
Path traversal
Open redirect
SSRF
Account takeover |
NA |
Suraj Disoja (@ninetyn1ne_) |
Bug Bounty | 2020-10-05 | 2023-06-13 |
3109 | We Hacked Apple for 3 Months: Here’s What We Found |
RCE
Authentication bypass
Authorization bypass
SSRF
XXE
Blind XSS
IDOR
OS command injection
SQL injection |
Apple |
Sam Curry (@samwcyo) |
Bug Bounty | 2020-10-07 | 2023-06-13 |
3097 | Blind SSRF - The Hide & Seek Game |
Blind SSRF |
NA |
Shrey Shah (@ShreySh43332033) |
Bug Bounty | 2020-10-13 | 2023-06-13 |
3084 | IBM Datapower Exploit CVE-2020-5014 |
SSRF
HTTP Request Smuggling |
IBM |
Thomas Cope |
Bug Bounty | 2020-10-21 | 2023-06-13 |
3044 | SSRF (Server Side Request Forgery) worth $4,913 | My Highest Bounty Ever ! |
SSRF |
Dropbox |
Sayaan Alam (@ehsayaan) |
Bug Bounty | 2020-11-10 | 2023-06-13 |
3043 | 31k$ SSRF in Google Cloud Monitoring led to metadata exposure |
SSRF |
Google |
David Nechuta (@david_nechuta) |
Bug Bounty | 2020-11-10 | 2023-06-13 |
3019 | Tale of 3 vulnerabilities to account takeover! |
SSRF
Account takeover |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2020-11-17 | 2023-06-13 |
3013 | Exploiting dynamic rendering engines to take control of web apps |
SSRF
Open redirect |
NA |
Vasilii Ermilov (@ermil0v) |
Bug Bounty | 2020-11-19 | 2023-06-13 |
3007 | SD-PWN — Part 3 — Cisco vManage — Another Day, Another Network Takeover |
RCE
SSRF
Arbitrary file write
Path traversal
OS command injection
Local Privilege Escalation |
Cisco |
Realmode Labs (@RealmodeLabs) |
Bug Bounty | 2020-11-23 | 2023-06-13 |
2998 | WonderCMS 3.1.3 - Authenticated RCE & Blind SSRF Vulnerability |
Blind SSRF
RCE |
WonderCMS |
Mas Zet (@zetc0de) |
Bug Bounty | 2020-11-29 | 2023-06-13 |