3444 | IDOR in session cookie leading to Mass Account Takeover |
IDOR
Account takeover |
NA |
Zonduhackerone (@zonduu1) |
Bug Bounty | 2020-05-29 | 2023-06-13 |
3435 | Hunting on ASPX Application For P1%27s [Unauthenticated SOAP,RCE, Info Disclosure] |
RCE
Information disclosure
IDOR |
NA |
ElMahdi Mrhassel (@ElMrhassel) |
Bug Bounty | 2020-05-31 | 2023-06-13 |
3423 | Another image removal vulnerability on Facebook |
IDOR |
Meta / Facebook |
Pouya Darabi (@Pouyadarabi) |
Bug Bounty | 2020-06-04 | 2023-06-13 |
3421 | [IDOR] Delete saved credit cards from any Business Manager Account — Facebook Bug Bounty |
IDOR |
Meta / Facebook |
Rohit kumar (@rohitcoder) |
Bug Bounty | 2020-06-05 | 2023-06-13 |
3390 | Business logic flaw in the invitation system allows to Takeover any account at a private company |
Account takeover
IDOR |
NA |
Daniel V. (@d4niel_v) |
Bug Bounty | 2020-06-15 | 2023-06-13 |
3367 | All About Getting First Bounty with IDOR |
IDOR |
NA |
Mukul Trivedi (@M0hn1sh) |
Bug Bounty | 2020-06-23 | 2023-06-13 |
3341 | [Writeup][Bug Bounty][Tokopedia] Manipulate Other User’s Cart and Wishlist on Tokopedia [EN] |
IDOR |
Tokopedia |
Muhammad Thomas Fadhila Yahya (@fadhilthomas) |
Bug Bounty | 2020-07-03 | 2023-06-13 |
3333 | Taking Over Files in a chat —IDOR in Microsoft Teams |
IDOR |
Microsoft |
Aly Anwar (@alyanwarr) |
Bug Bounty | 2020-07-05 | 2023-06-13 |
3329 | Make Featured Product in any video |
IDOR |
Meta / Facebook |
abdellah yaala (@yaalaab) |
Bug Bounty | 2020-07-05 | 2023-06-13 |
3322 | Journey from low to critical bug $$$ |
IDOR |
NA |
Dheeraj Madhukar (@Dheerajmadhukar) |
Bug Bounty | 2020-07-09 | 2023-06-13 |
3299 | Idor in google product |
IDOR |
Google |
Baluz (@t3chman) |
Bug Bounty | 2020-07-17 | 2023-06-13 |
3288 | Hack Till Your Last Breath |
IDOR |
NA |
mechboy / _m.u.h.e_ (@Muhe76355002) |
Bug Bounty | 2020-07-21 | 2023-06-13 |
3282 | A Simple IDOR which should not be missed on dating site ;) |
IDOR
Information disclosure |
NA |
neelam |
Bug Bounty | 2020-07-26 | 2023-06-13 |
3273 | Authentication Token Leads To IDOR |
Authentication bypass |
NA |
mohit (@mohit29295572) |
Bug Bounty | 2020-07-28 | 2023-06-13 |
3196 | Upload to the future |
IDOR |
NA |
Vuk Ivanovic |
Bug Bounty | 2020-08-22 | 2023-06-13 |
3188 | Delete IDOR on a Fashion eCommerce Website |
IDOR |
NA |
Amey Anekar (@ameyanekar) |
Bug Bounty | 2020-08-26 | 2023-06-13 |
3179 | Cloud firewall management API SNAFU put 500k SonicWall customers at risk |
IDOR |
SonicWall |
Vangelis Stykas (@evstykas) |
Bug Bounty | 2020-09-02 | 2023-06-13 |
3176 | Account Takeover via IDOR |
IDOR
Account takeover |
NA |
Roma Ramazanoff (@r0hack) |
Bug Bounty | 2020-09-04 | 2023-06-13 |
3152 | Privilege Escalation via Account Takeover on NodeBB Forum Software — Bug Bounty (512$) — CVE-2020–15149 |
IDOR
Account takeover |
NodeBB |
Muhammed Eren Uygun (@erenuyguun) |
Bug Bounty | 2020-09-19 | 2023-06-13 |
3139 | #Bugbounty- “How I was able to see other users Payments in a travel application” — IDOR #800$ |
IDOR
Information disclosure |
NA |
ganiganesh (@ganiganeshss79) |
Bug Bounty | 2020-09-22 | 2023-06-13 |
3136 | PII Leakage via IDOR + Weak PasswordReset = Full Account Takeover |
IDOR
Information disclosure |
NA |
Pradeep Kumar (@Killer007p) |
Bug Bounty | 2020-09-25 | 2023-06-13 |
3131 | 5 Ways to do Account Takeover in a Single Website |
Account takeover
Lack of rate limiting
OTP bypass
IDOR
OAuth
JWT |
NA |
letmeslidein (@VasuYadaav) |
Bug Bounty | 2020-09-27 | 2023-06-13 |
3127 | The Art of IDOR: 7 IDORs in Edm0d0 |
IDOR |
Edmodo |
Pratyush Anjan Sarangi |
Bug Bounty | 2020-09-29 | 2023-06-13 |
3112 | 6k$ Worth Account Takeover via IDOR in Starbucks Singapore |
IDOR
Account takeover |
Starbucks |
Kamil Onur Özkaleli (@ko2sec) |
Bug Bounty | 2020-10-07 | 2023-06-13 |
3109 | We Hacked Apple for 3 Months: Here’s What We Found |
RCE
Authentication bypass
Authorization bypass
SSRF
XXE
Blind XSS
IDOR
OS command injection
SQL injection |
Apple |
Sam Curry (@samwcyo) |
Bug Bounty | 2020-10-07 | 2023-06-13 |