2612 | AWS internal metadata accessed through SSRF by Chaining an Open Redirect bug |
SSRF
Open redirect |
NA |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2021-04-24 | 2023-06-13 |
2610 | From Wayback Machine To Account Takeover |
Account takeover
Password reset
Open redirect |
NA |
Demon (@R29k_) |
Bug Bounty | 2021-04-25 | 2023-06-13 |
2607 | From Wayback Machine To Account Takeover |
Open redirect
Account takeover |
NA |
Demon (@R29k_) |
Bug Bounty | 2021-04-25 | 2023-06-13 |
2592 | Facebook account takeover due to unsafe redirects after the OAuth flow |
OAuth
Open redirect
Account takeover |
Meta / Facebook |
Youssef Sammouda (@samm0uda) |
Bug Bounty | 2021-04-30 | 2023-06-13 |
2578 | XSS Through Parameter Pollution |
Open redirect
XSS
HTTP parameter pollution |
NA |
Saajan Bhujel (@saajanbhujel11) |
Bug Bounty | 2021-05-05 | 2023-06-13 |
2508 | Exploiting Open Redirect - Whitelist Bypass Using Salesforce Environment |
Open redirect
Token theft
Salesforce |
NA |
Gaurav Nayak (@4auvar) |
Bug Bounty | 2021-06-02 | 2023-06-13 |
2399 | Hacking Xiaomi%27S Android Apps - Part 1 |
Android
Information disclosure
Open redirect
Privacy issue |
Xiaomi |
Ameya (@iamTakeMyHand) |
Bug Bounty | 2021-07-19 | 2023-06-13 |
2373 | Chaining Open Redirect with XSS to Account Takeover |
Open redirect
XSS
Account takeover |
NA |
Radian ID |
Bug Bounty | 2021-07-29 | 2023-06-13 |
2372 | How I could have hacked your medium account by phishing your FB, Twitter & Google credentials. |
Open redirect
OAuth |
Medium |
Renganathan (@IamRenganathan) |
Bug Bounty | 2021-07-29 | 2023-06-13 |
2347 | How I found Open Redirect on Hashnode.com |
Open redirect |
Hashnode |
Jefferson Gonzales (@gonzxph) |
Bug Bounty | 2021-08-05 | 2023-06-13 |
2323 | 1st Bug Bounty WriteUp: Open Redirect To XSS on Login Page |
Open redirect
XSS |
NA |
Nassim Chami (@nvccim) |
Bug Bounty | 2021-08-15 | 2023-06-13 |
2250 | Eye for an eye: Unusual single click JWT token takeover |
Open redirect
JWT
Account takeover |
JetBrains |
Yurii Sanin (@SaninYurii) |
Bug Bounty | 2021-09-05 | 2023-06-13 |
2158 | How I got $500 with Open redirect |
Open redirect |
NA |
khan mamun (@mamunwhh) |
Bug Bounty | 2021-10-10 | 2023-06-13 |
2097 | SONY Hunting I: Discovering Hidden Parameters (5x SWAG) |
Open redirect |
Sony |
can1337 (@canmustdie) |
Bug Bounty | 2021-11-07 | 2023-06-13 |
2061 | Open Redirect Vulnerability On Zapier: An Accidental Find |
Open redirect |
Zapier |
Monish Basaniwal |
Bug Bounty | 2021-11-21 | 2023-06-13 |
2003 | Open Redirection - QR Code Magic |
Open redirect |
NA |
Jerry Shah (@Jerry) |
Bug Bounty | 2021-12-11 | 2023-06-13 |
1955 | Bug Hunting Journey of 2021 |
Stored XSS
Open redirect
Token leak
CSRF
Logic flaw
Information disclosure
IDOR
Account takeover |
NA |
Sudhanshu Rajbhar (@sudhanshur705) |
Bug Bounty | 2021-12-31 | 2023-06-13 |
1857 | A technique to semi-automatically find vulnerabilities in WordPress plugins |
XSS
SQL injection
Open redirect
CSRF |
NA |
kazet (@kazet1234) |
Bug Bounty | 2022-02-03 | 2023-06-13 |
1843 | What I Found on Sony Vulnerability Disclosure Program |
Information disclosure
Lack of rate limiting
Open redirect
IDOR
XSS |
Sony |
Aditya Singh / rook1337 (@imrook1337) |
Bug Bounty | 2022-02-07 | 2023-06-13 |
1742 | A Tale of Open Redirection to Stored XSS |
Stored XSS
Open redirect |
NA |
Tushar Sharma (@tusharSharma_0) |
Bug Bounty | 2022-03-12 | 2023-06-13 |
1741 | Open Redirect via Sendgrid Email Misconfiguration |
Open redirect |
NA |
Rifqi Hilmy Zhafrant |
Bug Bounty | 2022-03-13 | 2023-06-13 |
1739 | Party time: Injecting code into Teleparty extension |
HTML injection
Open redirect
Browser extension hacking |
Teleparty |
Wladimir Palant (@WPalant) |
Bug Bounty | 2022-03-14 | 2023-06-13 |
1676 | Small bugs are more dangerous than you think |
Self-XSS
Stored XSS
Open redirect
CSRF |
NA |
Liv Matan (@terminatorLM) |
Bug Bounty | 2022-04-01 | 2023-06-13 |
1615 | Full Account Takeover via Open Redirection |
Open redirect
Token leak
Account takeover
OAuth |
NA |
vFlexo (@vflexo) |
Bug Bounty | 2022-04-17 | 2023-06-13 |
1611 | Adobe Acrobat hollowing out same-origin policy |
XSS
SOP bypass
Open redirect
postMessage |
Adobe |
Wladimir Palant (@WPalant) |
Bug Bounty | 2022-04-19 | 2023-06-13 |