5172 | When your privacy disclosure is a “feature” not a “bug” – Badoo & HotorNot failure! |
Information disclosure |
Badoo
Hot Or Not |
Mohamed A. Baset |
Bug Bounty | 2016-05-17 | 2023-06-13 |
5171 | Microsoft Yammer Clickjacking – Exploiting HTML5 Security Features |
Clickjacking |
Microsoft |
Mohamed A. Baset |
Bug Bounty | 2016-05-18 | 2023-06-13 |
5170 | InstaBrute: Two Ways to Brute-force Instagram Account Credentials |
Bruteforce
Username enumeration |
Meta / Facebook |
Arne Swinnen (@ArneSwinnen) |
Bug Bounty | 2016-05-19 | 2023-06-13 |
5169 | RunKeeper Stored XSS Vulnerability – Where worms are able to run too! |
Stored XSS
CSRF |
RunKeeper |
Mohamed A. Baset |
Bug Bounty | 2016-06-06 | 2023-06-13 |
5168 | Popping the Pornhub Cherry |
Information disclosure |
PornHub |
Andy Gill (@ZephrFish) |
Bug Bounty | 2016-06-07 | 2023-06-13 |
5167 | Why you shouldn’t share links on Facebook |
Information disclosure |
Meta / Facebook |
Inti De Ceukelaire (@securinti) |
Bug Bounty | 2016-06-09 | 2023-06-13 |
5166 | Two vulnerabilities makes an Exploit!! (XSS and CSRF in Bing) |
XSS
CSRF |
Microsoft |
Sai Krishna Kothapalli (@kmskrishna) |
Bug Bounty | 2016-06-10 | 2023-06-13 |
5165 | Critical LinkedIn vulnerability proactively resolved by Wallarm (XXE in application server) |
XXE |
LinkedIn |
Wallarm (@Wallarm)< |
Bug Bounty | 2016-06-10 | 2023-06-13 |
5164 | Medium Full Account Takeover By One Click |
XSS |
Medium |
Abdullah Hussam (@Abdulahhusam) |
Bug Bounty | 2016-06-23 | 2023-06-13 |
5163 | Uber Hacking: How we found out who you are, where you are and where you went |
Bruteforce
Information disclosure
Logic flaw
IDOR |
Uber |
Vitor “r0t” Oliveira (@r0t1v) |
Bug Bounty | 2016-06-24 | 2023-06-13 |
5162 | TopCoder.com Vulnerabilities – A tail of site-wide bugs leads to accounts compromise & payments hijacking |
CSRF
Account takeover |
Topcoder.com |
Mohamed A. Baset |
Bug Bounty | 2016-06-28 | 2023-06-13 |
5161 | Race conditions on the web |
Race condition |
Cobalt.io
Meta / Facebook
MEGA
Keybase |
Josip Franjkovic (@josipfranjkovic) |
Bug Bounty | 2016-07-12 | 2023-06-13 |
5160 | How I Could Steal Money from Instagram, Google and Microsoft |
Logic flaw |
Google
Microsoft
Meta / Facebook |
Arne Swinnen (@ArneSwinnen) |
Bug Bounty | 2016-07-15 | 2023-06-13 |
5159 | Stealing Facebook access_tokens using CSRF in device login flow |
CSRF
OAuth
Information disclosure |
Meta / Facebook |
Josip Franjkovic (@josipfranjkovic) |
Bug Bounty | 2016-07-19 | 2023-06-13 |
5158 | Blind XSS in Spotify%27s Salesforce Integration |
Blind XSS
Salesforce |
Spotify |
Mohammed Diaa (@mhmdiaa) |
Bug Bounty | 2016-07-19 | 2023-06-13 |
5157 | Twitter%27s Vine Source code dump - $10080 |
Source code disclosure
Information disclosure |
Twitter |
avicoder (@avicoder) |
Bug Bounty | 2016-07-22 | 2023-06-13 |
5156 | How we broke PHP, hacked Pornhub and earned $20,000 |
RCE
Memory corruption
Use-After-Free |
PornHub |
Ruslan Habalov (@evonide) |
Bug Bounty | 2016-07-23 | 2023-06-13 |
5155 | Remote Code Execution (RCE) on Microsoft%27s %27signout.live.com%27 |
RCE |
Microsoft |
Peter Adkins (@darkarnium) |
Bug Bounty | 2016-07-24 | 2023-06-13 |
5154 | BMW Vulnerabilities – Hijack Cars ConnectedDrive™ Service! |
Clickjacking
CSRF |
BMW |
Mohamed A. Baset |
Bug Bounty | 2016-07-24 | 2023-06-13 |
5153 | Messenger.com Site-Wide CSRF |
CSRF |
Meta / Facebook |
Jack Whitton (@fin1te) |
Bug Bounty | 2016-07-26 | 2023-06-13 |
5152 | CSV Injection -> Meterpreter on Pornhub |
CSV injection |
PornHub |
Andy Gill (@ZephrFish) |
Bug Bounty | 2016-07-29 | 2023-06-13 |
5151 | XSS on Flickr |
XSS |
Flickr |
Shubham Gupta (@hackerspider1) |
Bug Bounty | 2016-07-31 | 2023-06-13 |
5150 | Xss filter bypass in Yahoo dev.flurry.com |
XSS |
Yahoo! / Verizon Media |
Shubham Gupta (@hackerspider1) |
Bug Bounty | 2016-07-31 | 2023-06-13 |
5149 | Swf XSS (Dom Based Xss) |
Flash XSS
DOM XSS |
Ubiquity Networks |
Shubham Gupta (@hackerspider1) |
Bug Bounty | 2016-07-31 | 2023-06-13 |
5148 | Samsung Galaxy Apps MiTM vulnerabilities |
MiTM
Android |
Samsung |
Simone Margaritelli (@evilsocket) |
Bug Bounty | 2016-08-17 | 2023-06-13 |