5197 | XSS without HTML: Client-Side Template Injection with AngularJS |
CSTI
XSS |
Google |
Gareth Heyes (@garethheyes) |
Bug Bounty | 2016-01-27 | 2023-06-13 |
5196 | How I got access to millions of [redacted] accounts |
RFI |
NA |
Bitquark (@bitquark) |
Bug Bounty | 2016-02-09 | 2023-06-13 |
5195 | A Hilarious ESET Broken Authentication Vulnerability (one click free purchase) |
Authentication flaw
SQL injection |
ESET |
Mohamed A. Baset |
Bug Bounty | 2016-02-12 | 2023-06-13 |
5194 | How I Hacked [Oculus] OAuth +Ebay +IBM |
Unrestricted file upload
XSS |
Meta / Facebook
Ebay
IBM
AnswerHub |
Abdullah Hussam (@Abdulahhusam) |
Bug Bounty | 2016-02-12 | 2023-06-13 |
5193 | Ubiquiti Bug Bounty: UniFi v3.2.10 Generic CSRF Protection Bypass |
CSRF |
Ubiquity Networks |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2016-02-23 | 2023-06-13 |
5192 | Hacking Magento eCommerce For Fun And 17.000 USD |
Information disclosure
LFI
RFI |
Adobe |
Egidio Romano / EgiX |
Bug Bounty | 2016-03-03 | 2023-06-13 |
5191 | SQL Injection On MEGA.NZ |
SQL injection |
MEGA |
Naresh LamGade (@nlamgade) |
Bug Bounty | 2016-03-11 | 2023-06-13 |
5190 | Command injection which got me "6000$" from #Google |
OS command injection |
Google |
Venkatesh Sivakumar (@pranavvenkats) |
Bug Bounty | 2016-03-15 | 2023-06-13 |
5189 | Uber Bug Bounty: Turning Self-XSS into Good-XSS |
XSS |
Uber |
Jack Whitton (@fin1te) |
Bug Bounty | 2016-03-22 | 2023-06-13 |
5188 | How I Could Compromise 4% (Locked) Instagram Accounts |
IDOR
DoS
Authorization flaw |
Meta / Facebook |
Arne Swinnen (@ArneSwinnen) |
Bug Bounty | 2016-03-27 | 2023-06-13 |
5187 | Watch Paint Dry: How I got a game on the Steam Store without anyone from Valve ever looking at it. |
Authorization flaw
Logic flaw |
Valve |
Ruby Nealon (@_ruby) |
Bug Bounty | 2016-03-29 | 2023-06-13 |
5186 | Obtaining Login Tokens for an Outlook, Office or Azure Account |
CSRF |
Microsoft |
Jack Whitton (@fin1te) |
Bug Bounty | 2016-04-03 | 2023-06-13 |
5185 | Facebook Invitees Email Address Disclosure |
Information disclosure |
Meta / Facebook |
Shahar Albeck |
Bug Bounty | 2016-04-03 | 2023-06-13 |
5184 | Yahoo Login Protection Seal – Stored CSS Injection |
CSS injection |
Yahoo! / Verizon Media |
Brett Buerhaus (@bbuerhaus) |
Bug Bounty | 2016-04-18 | 2023-06-13 |
5183 | ESEA Server-Side Request Forgery and Querying AWS Meta Data |
SSRF |
ESEA |
Brett Buerhaus (@bbuerhaus) |
Bug Bounty | 2016-04-18 | 2023-06-13 |
5182 | Facebook ClickJacking – How we put a new dress on Facebook UI |
Clickjacking |
Meta / Facebook |
Mohamed A. Baset |
Bug Bounty | 2016-04-22 | 2023-06-13 |
5181 | Official Telegram Web Client ClickJacking Vulnerability – When crypto is strong and client is weak |
Clickjacking |
Telegram |
Mohamed A. Baset |
Bug Bounty | 2016-04-28 | 2023-06-13 |
5180 | WhatsApp Clickjacking Vulnerability – Yet another web client failure! |
Clickjacking |
Meta / Facebook |
Mohamed A. Baset |
Bug Bounty | 2016-05-04 | 2023-06-13 |
5179 | Facebook movies recommendation vulnerability – A bug capable of erasing all your important notifications! |
Logic flaw
DoS |
Meta / Facebook |
Mohamed A. Baset |
Bug Bounty | 2016-05-05 | 2023-06-13 |
5178 | Poisoning the Well – Compromising GoDaddy Customer Support With Blind XSS |
Blind XSS |
GoDaddy |
Matthew Bryant (@IAmMandatory) |
Bug Bounty | 2016-05-08 | 2023-06-13 |
5177 | FirefoxOS Find My Device Service Clickjacking Bug results in Changing PINs, Wiping and Locking Phones! |
Clickjacking |
Mozilla |
Mohamed A. Baset |
Bug Bounty | 2016-05-12 | 2023-06-13 |
5176 | Fiverr.com Full Accounts Takeover – A Vulnerability Puts $50 Million Company At Risk |
CSRF |
Fiverr |
Mohamed A. Baset |
Bug Bounty | 2016-05-13 | 2023-06-13 |
5175 | Facebook Vulnerability – a "Cute Bug" that reveals the "likes" of deleted posts regardless of their privacy settings |
Logic flaw |
Meta / Facebook |
Mohamed Aty (@m_aty) |
Bug Bounty | 2016-05-13 | 2023-06-13 |
5174 | How I bypassed Facebook CSRF once again! |
CSRF |
Meta / Facebook |
Pouya Darabi (@Pouyadarabi) |
Bug Bounty | 2016-05-17 | 2023-06-13 |
5173 | Sleeping stored Google XSS Awakens a $5000 Bounty |
Stored XSS |
Google |
Patrik Fehrenbach (@ITSecurityguard) |
Bug Bounty | 2016-05-17 | 2023-06-13 |