3685 | How, I dumped crypto data by chaining directory listing to open S3 Bucket |
AWS misconfiguration
Directory listing
Information disclosure |
NA |
Ddigvijay |
Bug Bounty | 2020-02-05 | 2023-06-13 |
3684 | Hijacking shared report links in Google Data Studio |
Authorization flaw |
Google |
sushiwushi (@sushiwushi2) |
Bug Bounty | 2020-02-05 | 2023-06-13 |
3683 | An Unexpected Bounty — Email Bounce Issues |
DoS
Email Bounce Issue |
NA |
Keshav Malik (@g0t_rOoT_) |
Bug Bounty | 2020-02-05 | 2023-06-13 |
3682 | Using CSRF I Got Weird Account Takeover |
CSRF
Account takeover |
NA |
Mohamed Sayed (@FlEx0Geek) |
Bug Bounty | 2020-02-05 | 2023-06-13 |
3681 | How I Made $600 in Bug Bounty in 15 Minutes with Contrast CE – CVE- 2019-8442 |
Information disclosure |
Atlassian |
David Lindner (@golfhackerdave) |
Bug Bounty | 2020-02-05 | 2023-06-13 |
3680 | Site wide CSRF on a popular program |
CSRF |
NA |
Ajinkya Pathare (@fellchase) |
Bug Bounty | 2020-02-05 | 2023-06-13 |
3679 | Google APIS ClickJacking ( $1337) |
Clickjacking |
Google |
Myo Min Thu (@myominthu1337) |
Bug Bounty | 2020-02-05 | 2023-06-13 |
3678 | Simple Remote Code Execution Vulnerability Examples for Beginners |
RCE
Unrestricted file upload |
NA |
Ozgur Alp (@ozgur_bbh) |
Bug Bounty | 2020-02-05 | 2023-06-13 |
3677 | Popping Alerts in Mixmax Chrome Extension (Write Up) |
XSS |
Mixmax |
Evan Ricafort (@evanricafort) |
Bug Bounty | 2020-02-06 | 2023-06-13 |
3676 | How Inspect Element Got me a Bounty |
Client-side enforcement of server-side security |
NA |
Aditya Soni (@hetroublemakr) |
Bug Bounty | 2020-02-06 | 2023-06-13 |
3675 | IDOR leads to Data leakage and Profile Update |
IDOR
Bruteforce |
NA |
vict0ni (@vict0ni) |
Bug Bounty | 2020-02-07 | 2023-06-13 |
3673 | External XML Entity via File Upload (SVG) |
XXE
Unrestricted file upload |
NA |
Atul (@atul_hax) |
Bug Bounty | 2020-02-08 | 2023-06-13 |
3672 | A step-by-step walk-through of an Invalid Endpoint |
Information disclosure |
NA |
Mohammed Israil (@mdisrail2468) |
Bug Bounty | 2020-02-09 | 2023-06-13 |
3671 | How I discovered an SSRF leading to AWS Metadata Leakage |
SSRF |
NA |
Amey Anekar (@ameyanekar) |
Bug Bounty | 2020-02-10 | 2023-06-13 |
3670 | Weird Vulnerabilities Happening on Load Balancers, Shallow Copies and Caches |
Information disclosure |
NA |
Ozgur Alp (@ozgur_bbh) |
Bug Bounty | 2020-02-11 | 2023-06-13 |
3669 | A Simple IDOR to Account Takeover |
IDOR
Account takeover |
NA |
Swapnil Maurya (@swapmaurya20) |
Bug Bounty | 2020-02-11 | 2023-06-13 |
3668 | CVE-2019-18426 - WhatsApp Vulnerabilities Disclosure - Open Redirect + CSP Bypass + Persistent XSS + FS read permissions + potential for RCE |
RCE
Stored XSS
CSP bypass
Arbitrary file read
Open redirect
Security code review |
Meta / Facebook (WhatsApp) |
Gal Weizman (@WeizmanGal) |
Bug Bounty | 2020-02-14 | 2023-06-13 |
3666 | Open-redirect Vulnerability on Facebook |
Open redirect |
Meta / Facebook |
dw1 |
Bug Bounty | 2020-02-16 | 2023-06-13 |
3664 | Uploading Backdoor For Fun And Profit. |
Unrestricted file upload
RCE |
NA |
Mohammed Abdul Raheem (@mohdaltaf163) |
Bug Bounty | 2020-02-17 | 2023-06-13 |
3663 | How I Gain Unrestricted File Upload Remote Code Execution Bug Bounty |
Unrestricted file upload |
NA |
Shay Grant (@kidshay) |
Bug Bounty | 2020-02-17 | 2023-06-13 |
3662 | Exploiting WebSocket [Application Wide XSS / CSRF] |
XSS
CSRF |
NA |
Osama Avvan (@osamaavvan) |
Bug Bounty | 2020-02-17 | 2023-06-13 |
3661 | Plan Change Logic in Google Fiber (Webpass) |
Logic flaw
Payment tampering |
Google |
Craig Arendt (@signalchaos) |
Bug Bounty | 2020-02-17 | 2023-06-13 |
3660 | How We Found Another XSS in Google with Acunetix |
XSS |
Google |
Andrey Leonov (@4lemon) |
Bug Bounty | 2020-02-17 | 2023-06-13 |
3659 | My First Bounty From Google. |
Self-XSS
HTML injection |
Google |
Syahri Ramadan (@adonkidz7) |
Bug Bounty | 2020-02-18 | 2023-06-13 |
3658 | From Recon to Optimizing RCE Results – Simple Story with One of the Biggest ICT Company in the World |
Information disclosure
RCE |
NA |
YoKo Kho (@YokoAcc) |
Bug Bounty | 2020-02-18 | 2023-06-13 |