3983 | Privilege Escalation using Api endpoint |
Privilege escalation |
NA |
Ronak Patel (@ronak_9889) |
Bug Bounty | 2019-08-09 | 2023-06-13 |
3982 | Read other user support tickets in https://support..com (Write Up) |
IDOR |
NA |
Evan Ricafort (@evanricafort) |
Bug Bounty | 2019-08-09 | 2023-06-13 |
3981 | Two Easy RCE in Atlassian Products |
Credential stuffing |
Atlassian |
Valeriy Shevchenko (@Krevetk0Valeriy) |
Bug Bounty | 2019-08-09 | 2023-06-13 |
3980 | Application Level Denial of Service [DoS] using SVG file in https://[REDACTED].com (Write Up) |
Application-level DoS |
NA |
Evan Ricafort (@evanricafort) |
Bug Bounty | 2019-08-10 | 2023-06-13 |
3979 | Clickjacking DOM XSS on Google.org |
Clickjacking
DOM XSS |
Google |
Thomas Orlita (@ThomasOrlita) |
Bug Bounty | 2019-08-12 | 2023-06-13 |
3978 | Reporting - Amazon 1 click device XSS |
XSS |
Amazon |
Sneakerhax (@sneakerhax) |
Bug Bounty | 2019-08-12 | 2023-06-13 |
3977 | SSRF Vulnerability in https://app.[REDACTED].com |
SSRF |
NA |
Evan Ricafort (@evanricafort) |
Bug Bounty | 2019-08-13 | 2023-06-13 |
3975 | BugBounty WriteUp — take attention and get Stored XSS |
Stored XSS |
NA |
Oleksandr Opanasiuk (@Lekssik2) |
Bug Bounty | 2019-08-14 | 2023-06-13 |
3974 | [Business Logic] Bypassing Nickname Feature |
Logic flaw |
NA |
Kent Bayron / kntx (@bayronkentoy) |
Bug Bounty | 2019-08-14 | 2023-06-13 |
3973 | BookMyShow account takeover using social login |
OAuth
Account takeover |
BookMyShow |
Sukhmeet Singh (@MadGuyyy) |
Bug Bounty | 2019-08-15 | 2023-06-13 |
3972 | Facebook Messenger exposing deleted messages using [Remove for Everyone] |
Logic flaw |
Meta / Facebook |
Renwa (@RenwaX23) |
Bug Bounty | 2019-08-15 | 2023-06-13 |
3971 | ByPassing fix of Domain Blocking feature in Business Manager |
Authorization flaw
Logic flaw |
Meta / Facebook |
Rohit kumar (@rohitcoder) |
Bug Bounty | 2019-08-15 | 2023-06-13 |
3970 | How I was able to earn 1000$ with just 10 minutes of bug bounty? |
Password reset |
NA |
Ninad Mathpati (@ninad_mathpati) |
Bug Bounty | 2019-08-17 | 2023-06-13 |
3967 | U.S. Department of Defense - Info Disclosure and SQLi Writeup |
Information disclosure
SQL injection |
U.S. Dept Of Defense |
Aaron Esau (@arinerron) |
Bug Bounty | 2019-08-19 | 2023-06-13 |
3966 | Facebook Bug Bounty: Reading WhatsApp contacts list without unlocking the device |
Authorization flaw |
Meta / Facebook |
Arvind (@ar_arv1nd) |
Bug Bounty | 2019-08-19 | 2023-06-13 |
3965 | Kaspersky in the Middle – what could possibly go wrong? |
Clickjacking
Universal XSS
MiTM |
Kaspersky |
Wladimir Palant (@WPalant) |
Bug Bounty | 2019-08-19 | 2023-06-13 |
3964 | How I upgraded my privileges to the administrator of Odnoklassniki’s url shortener |
Privilege escalation |
ok.ru |
Sergey Kashatov (@iframe0x01) |
Bug Bounty | 2019-08-20 | 2023-06-13 |
3963 | How I made my first $$$ from finding a bug in Facebook |
Authorization flaw |
Meta / Facebook |
Aayush Pokhrel (@aayushpok) |
Bug Bounty | 2019-08-21 | 2023-06-13 |
3962 | Sending Message as page being an analyst/ advertiser? |
Authorization flaw |
Meta / Facebook |
Baibhav Anand (@SpongeBhav) |
Bug Bounty | 2019-08-21 | 2023-06-13 |
3960 | Rights Manager Graph API Disclosure of business employee to non business employee |
Information disclosure |
Meta / Facebook |
Jafar Abo Nada (@Jafar_Abo_Nada) |
Bug Bounty | 2019-08-22 | 2023-06-13 |
3959 | One Bug To Rule Them All: Modern Android Password Managers and FLAG_SECURE Misuse |
Information disclosure
Content leak |
1Password
Keeper
Dashlane |
Lorenzo Stella (@lorenzostella) |
Bug Bounty | 2019-08-22 | 2023-06-13 |
3957 | From Github Recon To Account Takeover |
Information disclosure
Account takeover |
NA |
Dipak kumar Das (@d1pakdas) |
Bug Bounty | 2019-08-24 | 2023-06-13 |
3955 | Bug Bounty: Bypassing a crappy WAF to exploit a blind SQL injection |
Blind SQL injection |
NA |
Robin Verton (@robinverton) |
Bug Bounty | 2019-08-25 | 2023-06-13 |
3954 | How I Hacked Instagram Again |
Password reset
Account takeover |
Meta / Facebook |
Laxman Muthiyah (@LaxmanMuthiyah) |
Bug Bounty | 2019-08-26 | 2023-06-13 |
3953 | How i was able to exploit the same endpoint 2 times ( multiple xss & open Redirection on 10 subdomain) |
XSS
Open redirect |
Sanity.io |
Ratnadip Gajbhiye (@scspcommunity) |
Bug Bounty | 2019-08-26 | 2023-06-13 |