4039 | The Bugs Are Out There, Hiding in Plain Sight |
IDOR
SSRF
Information disclosure
CORS misconfiguration |
NA |
A Bug’z Life (@abugzlife1) |
Bug Bounty | 2019-07-15 | 2023-06-13 |
4038 | How I Could Get The Instagram Username of Anyone on Tinder |
Information disclosure |
Tinder |
Shahar Albeck |
Bug Bounty | 2019-07-16 | 2023-06-13 |
4037 | What do Netcat, SMTP and self XSS have in common? Stored XSS |
Stored XSS |
NA |
Plenum (@plenumlab) |
Bug Bounty | 2019-07-16 | 2023-06-13 |
4036 | Bypass CSRF With ClickJacking Worth $1250 |
CSRF
Clickjacking |
NA |
Saad Ahmed (@XSaadAhmedX) |
Bug Bounty | 2019-07-16 | 2023-06-13 |
4035 | CSRF Email Confirmation Vulnerability for Gmail & G-Suite in Facebook |
CSRF |
Meta / Facebook |
Lokesh Kumar (@lokeshdlk77) |
Bug Bounty | 2019-07-16 | 2023-06-13 |
4034 | Facebook Informative Bug From Triaged |
Lack of rate limiting |
Meta / Facebook |
Circle Ninja (@circleninja) |
Bug Bounty | 2019-07-17 | 2023-06-13 |
4033 | How Recon helped me to to find a Facebook domain takeover |
Subdomain takeover |
Meta / Facebook |
Sudhanshu Rajbhar (@sudhanshur705) |
Bug Bounty | 2019-07-17 | 2023-06-13 |
4032 | Account Takeover Vulnerability :) |
Password reset
Account takeover |
NA |
Sumit Jain (@sumit_cfe) |
Bug Bounty | 2019-07-17 | 2023-06-13 |
4031 | Сookie-based XSS exploitation | $2300 Bug Bounty story |
XSS |
NA |
Max (@iSecMax) |
Bug Bounty | 2019-07-17 | 2023-06-13 |
4030 | How to lock a GitHub user out of their repos (bug or feature?) |
DoS |
GitHub |
Teserakt AG |
Bug Bounty | 2019-07-18 | 2023-06-13 |
4029 | SQL Injection in Forget Password Function |
SQL injection |
NA |
Khaled Gaber |
Bug Bounty | 2019-07-18 | 2023-06-13 |
4028 | Microsoft Office 365 - Outlook XSS |
XSS |
Microsoft |
Abdulrahman Alqabandi (@Qab) |
Bug Bounty | 2019-07-19 | 2023-06-13 |
4027 | Microsoft ID Open Redirect |
Open redirect |
Microsoft |
Burninator Sec |
Bug Bounty | 2019-07-19 | 2023-06-13 |
4025 | Exploiting a Tricky Blind SQL Injection inside LIMIT clause |
SQL injection |
NA |
Rahul Maini (@iamnoooob) |
Bug Bounty | 2019-07-21 | 2023-06-13 |
4024 | Shopping Products For Free- Parameter Tampering Vulnerability |
Parameter tampering
Payment tampering |
NA |
D1vy4n5hu 5hukl4 (@justm0rph3u5) |
Bug Bounty | 2019-07-21 | 2023-06-13 |
4022 | Not a fancy bug, just HTML Injection in Clause - clause.io (Write Up) |
HTML injection |
Clause |
Evan Ricafort (@evanricafort) |
Bug Bounty | 2019-07-21 | 2023-06-13 |
4021 | Reflected XSS in Ebay.com |
Reflected XSS |
Ebay |
Sukhmeet Singh (@MadGuyyy) |
Bug Bounty | 2019-07-22 | 2023-06-13 |
4020 | XSS On Twitter [Worth 1120$] |
XSS |
NA |
Bywalks (@bywalkss) |
Bug Bounty | 2019-07-22 | 2023-06-13 |
4019 | Pwning child company to get access to ParentCompany%27s Slack Team |
SQL injection
Default credentials |
NA |
Parth Malhotra (@Parth_Malhotra)< |
Bug Bounty | 2019-07-23 | 2023-06-13 |
4018 | XX to XXX in one day |
Account takeover
Parameter tampering |
WePay |
Baibhav Anand (@SpongeBhav) |
Bug Bounty | 2019-07-23 | 2023-06-13 |
4017 | Disclose any main and 3rd party contributors email address and movie local path thru XML file in Plex TV - plex.tv (Write Up) |
Information disclosure
Internal path disclosure |
Plex |
Evan Ricafort (@evanricafort) |
Bug Bounty | 2019-07-24 | 2023-06-13 |
4016 | How I found the most critical bug in live bug bounty event? |
Password reset
Account takeover |
NA |
Lakshay (@inn0c3ntd3v1L) |
Bug Bounty | 2019-07-24 | 2023-06-13 |
4015 | Price Parameter Tampering On Bukalapak |
Parameter tampering
Payment tampering |
Bukalapak |
apapedulimu / Nosa Shandy (@LocalHost31337) |
Bug Bounty | 2019-07-24 | 2023-06-13 |
4014 | Full Account Takeover via Changing Email And Password of any User through API Parameters |
IDOR
Password reset
Account takeover |
NA |
Adesh Nandkishor kolte (@AdeshKolte) |
Bug Bounty | 2019-07-26 | 2023-06-13 |
4013 | Facebook BugBounty: Tale of an Instagram bug disclosing user’s phone number via checkpoint |
Information disclosure |
Meta / Facebook |
Bijan Murmu (@0xBijan) |
Bug Bounty | 2019-07-26 | 2023-06-13 |