3551 | Hacking a Telecommunication company(MTN) |
OTP bypass
Bruteforce |
MTN Group |
Afolic |
Bug Bounty | 2020-04-13 | 2023-06-13 |
3550 | Bounty Tip !! Easiest way to bypass API’s Rate Limit. |
Rate limiting bypass |
NA |
Shaurya Sharma (@ShauryaSharma05) |
Bug Bounty | 2020-04-14 | 2023-06-13 |
3549 | Business Logic Errors - A New Look |
Logic flaw |
NA |
Shrey Shah (@ShreySh43332033) |
Bug Bounty | 2020-04-14 | 2023-06-13 |
3548 | Netflix Party — XSS Vulnerabilities |
XSS |
Netflix |
kr-b (@pirxcy) |
Bug Bounty | 2020-04-14 | 2023-06-13 |
3547 | Multiple Kernel Vulnerabilities Affecting All Qualcomm Devices |
Memory corruption
Race condition |
Qalcomm
Samsung |
Tamir Zahavi-Brunner (@tamir_zb) |
Bug Bounty | 2020-04-15 | 2023-06-13 |
3546 | Tricky Oracle SQL Injection Situation |
SQL injection |
NA |
yappare (@yappare) |
Bug Bounty | 2020-04-16 | 2023-06-13 |
3545 | [Writeup][Bug Bounty][Instagram] Instagram Still Send New DMs and Video Calls to Device After Logout [ID][EN] |
Session management issue |
Meta / Facebook |
Muhammad Thomas Fadhila Yahya (@fadhilthomas) |
Bug Bounty | 2020-04-16 | 2023-06-13 |
3544 | OTP Verification Bypass |
OTP bypass |
NA |
Kanhaiya Kumar Singh |
Bug Bounty | 2020-04-17 | 2023-06-13 |
3543 | Strange Redirect (Fixed but no bounty) |
Open redirect |
NA |
Abhishek Yadav (@abhishake100) |
Bug Bounty | 2020-04-17 | 2023-06-13 |
3542 | Here is the Non Technical write-up on Technical Bug for My Second Bounty of $xxxx From Facebook |
Logic flaw
Privacy issue |
Meta / Facebook |
Ashok Chapagai (@ashokcpg) |
Bug Bounty | 2020-04-17 | 2023-06-13 |
3541 | How was i able to find privilege escalation. |
IDOR
Authorization flaw |
NA |
Akshar Tank (@Akshar__tank) |
Bug Bounty | 2020-04-18 | 2023-06-13 |
3540 | CSRF to RCE bug chain in Prestashop v1.7.6.4 and below |
RCE
CSRF
Stored XSS
Unrestricted file upload |
PrestaShop |
Sivanesh Ashok (@sivaneshashok) |
Bug Bounty | 2020-04-18 | 2023-06-13 |
3539 | Abusing HTTP Path Normalization and Cache Poisoning to steal Rocket League accounts |
HTTP cache poisoning
Open redirect |
Rocket League |
Sam Curry (@samwcyo) |
Bug Bounty | 2020-04-19 | 2023-06-13 |
3538 | Google Maps API (Not the Key) Bugs That I Found Over the Years |
Logic flaw |
Google |
Ozgur Alp (@ozgur_bbh) |
Bug Bounty | 2020-04-19 | 2023-06-13 |
3537 | DOM based open redirect to the leak of a JWT token |
Open redirect
DOM-based open redirect
Token leak |
NA |
Adolphoramirez |
Bug Bounty | 2020-04-20 | 2023-06-13 |
3536 | CORS bug on GOOGLE’s 404 page REWARDED!!! |
CORS misconfiguration |
Google |
Jayateertha Guruprasad (@JayateerthaG) |
Bug Bounty | 2020-04-21 | 2023-06-13 |
3535 | Exploiting a Race Condition Vulnerability |
Race condition |
NA |
Vivek Kumar Singh (@v7nc3nz) |
Bug Bounty | 2020-04-22 | 2023-06-13 |
3534 | The Secret sauce of bug bounty |
CSTI
Stored XSS
CORS misconfiguration |
NA |
Mohamed Slamat (@oxxy37) |
Bug Bounty | 2020-04-22 | 2023-06-13 |
3533 | From P5 to P2, from nothing to 1000+$ |
Race condition
Self-XSS
Blind XSS |
NA |
Mohamed Daher (@DaherMohamed4) |
Bug Bounty | 2020-04-22 | 2023-06-13 |
3532 | Misconfigured WordPress takeover to Remote Code Execution |
Wordpress takeover
RCE
Security misconfiguration |
NA |
Smaran Chand (@smaranchand) |
Bug Bounty | 2020-04-22 | 2023-06-13 |
3531 | Hiding ourself in close friend’s list and avoiding victim to remove us from his close friend’s list. |
Authorization flaw
Logic flaw |
Meta / Facebook |
Baibhav Anand (@SpongeBhav) |
Bug Bounty | 2020-04-23 | 2023-06-13 |
3530 | Messenger Rooms Bug Bounty Write-up |
Privilege escalation
Authorization flaw |
Meta / Facebook |
Jane Manchun Wong (@wongmjane) |
Bug Bounty | 2020-04-24 | 2023-06-13 |
3529 | Two Factor Authentication Bypass [ $50 ] |
MFA bypass |
NA |
Aung Pyae Ko Ko (@BlcKVRtuL1) |
Bug Bounty | 2020-04-24 | 2023-06-13 |
3528 | From Recon to P1 (Critical) — An Easy Win |
Exposed registration page |
NA |
Harsh Bothra (@harshbothra_) |
Bug Bounty | 2020-04-24 | 2023-06-13 |
3527 | Web Cache Poisoning in Postmates [$1500] |
Web cache poisoning |
Postmates |
Aung Pyae Ko Ko (@BlcKVRtuL1) |
Bug Bounty | 2020-04-24 | 2023-06-13 |