4281 | Bug Bounty 101 — Always Check The Source Code |
Lack of rate limiting
Information disclosure |
NA |
Spazzy |
Bug Bounty | 2019-02-23 | 2023-06-13 |
4280 | Chain of hacks leading to Database Compromise! |
LFI
SSRF |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2019-02-23 | 2023-06-13 |
4279 | SHAREit Multiple Vulnerabilities Enable Unrestricted Access to Adjacent Devices’ Files |
Android
Arbitrary file download
Authentication bypass |
SHAREit |
Abdulrahman Nour (@aboodnour) |
Bug Bounty | 2019-02-25 | 2023-06-13 |
4278 | Web Cache Deception Attack leads to user info disclosure |
Web cache deception
Information disclosure |
NA |
Kunal pandey (@kunalp94) |
Bug Bounty | 2019-02-25 | 2023-06-13 |
4277 | How I alert(1) in Azure DevOps |
XSS
CSP bypass |
Microsoft |
SpyD3r (@TarunkantG) |
Bug Bounty | 2019-02-26 | 2023-06-13 |
4276 | [Still work] Redirect Yahoo Subdomain XSS Reflected from americangreetings.com |
Reflected XSS |
Yahoo! / Verizon Media |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2019-02-26 | 2023-06-13 |
4275 | Horizontal Privilege Escalation on Quora which can compromise all users on Quora |
Privilege escalation |
Quora |
SpyD3r (@TarunkantG) |
Bug Bounty | 2019-02-26 | 2023-06-13 |
4274 | Yet Another (unexpected) Hack for Bounty |
Information disclosure |
Sli.do |
Pumudu Ruhunage |
Bug Bounty | 2019-03-01 | 2023-06-13 |
4273 | Bypassing a restrictive JS sandbox |
JS sandbox breakout
RCE |
NA |
Licencia para Hackear |
Bug Bounty | 2019-03-01 | 2023-06-13 |
4271 | XSS in Edmodo within 5 Minute (My First Bug Bounty) |
Reflected XSS |
Edmodo |
Vala Keyur (@valakeyur) |
Bug Bounty | 2019-03-04 | 2023-06-13 |
4270 | Auditing GitHub Repo Wikis for Fun and Profit |
Misconfigured Github wiki |
NA |
Smeege (@SmeegeSec) |
Bug Bounty | 2019-03-04 | 2023-06-13 |
4269 | Facebook exploit – Confirm website visitor identities |
Information disclosure
IDOR |
Meta / Facebook |
Tom Anthony (@TomAnthonySEO) |
Bug Bounty | 2019-03-04 | 2023-06-13 |
4268 | Fixed : Brute-force Instagram account’s passwords |
Bruteforce
Rate limiting bypass |
Meta / Facebook |
Sameer Rao |
Bug Bounty | 2019-03-05 | 2023-06-13 |
4267 | Fixed : Register any email address on Facebook Account |
Authorization flaw |
Meta / Facebook |
Sameer Rao |
Bug Bounty | 2019-03-05 | 2023-06-13 |
4266 | 3 XSS in ProtonMail for iOS |
XSS |
Apple |
Vladimir Metnew (@vladimir_metnew) |
Bug Bounty | 2019-03-06 | 2023-06-13 |
4265 | Facebook Messenger server random memory exposure through corrupted GIF image |
Information disclosure |
Meta / Facebook |
Dzmitry Lukyanenka (@vulnano) |
Bug Bounty | 2019-03-06 | 2023-06-13 |
4264 | Mapping Communication Between Facebook Accounts Using a Browser-Based Side Channel Attack |
Side-channel attack
Cross-Site Frame Leakage (CSFL) |
Meta / Facebook |
Ron Masas (@RonMasas) |
Bug Bounty | 2019-03-07 | 2023-06-13 |
4263 | Vimeo SSRF with code execution potential. |
SSRF |
Vimeo |
Harsh Jaiswal (@rootxharsh) |
Bug Bounty | 2019-03-08 | 2023-06-13 |
4262 | Account Takeover Using Cross-Site WebSocket Hijacking (CSWH) |
Cross-Site WebSocket Hijacking (CSWH)
Account takeover |
NA |
Sharan Panegav (@PanegavSharan) |
Bug Bounty | 2019-03-09 | 2023-06-13 |
4261 | SQL injection for $50 bounty, but still worth reading!! |
SQL injection |
NA |
Ronaldo Messi |
Bug Bounty | 2019-03-10 | 2023-06-13 |
4260 | Inserting malware into anyone’s Google Earth Projects Archive |
IDOR
XSS
Authorization flaw |
Google |
Thomas Orlita (@ThomasOrlita) |
Bug Bounty | 2019-03-10 | 2023-06-13 |
4258 | Escalating SSRF to RCE |
SSRF
RCE |
NA |
Youssef A. Mohamed (@GeneralEG64) |
Bug Bounty | 2019-03-25 | 2023-06-13 |
4257 | Brute Forcing User IDS via CSRF To Delete all Users with CSRF attack. |
CSRF
Bruteforce |
NA |
Armaan Pathan (@armaancrockroax) |
Bug Bounty | 2019-03-12 | 2023-06-13 |
4256 | How I found Blind XSS Vulnerability in redacted.com |
Blind XSS |
NA |
ssid (@newp_th) |
Bug Bounty | 2019-03-12 | 2023-06-13 |
4255 | Hack Your Form-New vector for Blind XSS |
Blind XSS
Stored XSS |
NA |
Youssef A. Mohamed (@GeneralEG64) |
Bug Bounty | 2019-03-13 | 2023-06-13 |