4836 | Union Based Sql injection Write up ->A private Company Site |
SQL injection |
NA |
Nur A Alam Dipu (@Dipu1A) |
Bug Bounty | 2018-03-12 | 2023-06-13 |
4835 | #BugBounty — “Let me reset your password and login into your account “-How I was able to Compromise any User Account via Reset Password Functionality |
Logic flaw
Password reset
Account takeover |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-03-14 | 2023-06-13 |
4833 | CVE-2017-13253: Buffer overflow in multiple Android DRM services |
Memory corruption
Local Privilege Escalation |
Google |
Tamir Zahavi-Brunner (@tamir_zb) |
Bug Bounty | 2018-03-15 | 2023-06-13 |
4832 | Leaking WordPress CSRF Tokens for Fun, $1337 bounty, and CVE-2017-5489 |
CSRF |
WordPress |
Abdullah Hussam (@Abdulahhusam) |
Bug Bounty | 2018-03-15 | 2023-06-13 |
4820 | My Best Small Report Bounty Report in Private Program ( Django REST framework Admin Login ByPass ) |
SQL injection
Authentication bypass
Account takeover |
NA |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2018-04-01 | 2023-06-13 |
4818 | Beyond XSS: Edge Side Include Injection |
ESI injection
SSRF
XSS |
Squid
Varnish |
Louis Dion-Marcil (@ldionmarcil) |
Bug Bounty | 2018-04-03 | 2023-06-13 |
4816 | #BugBounty — ” Your details are saved into my account”-User info disclosure Vulnerability in Practo (India’s biggest healthcare app) |
IDOR |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-04-05 | 2023-06-13 |
4814 | “Exploiting a Single Parameter” |
SSRF
XSS |
NA |
Hisham Mir (@Hishammir1) |
Bug Bounty | 2018-04-06 | 2023-06-13 |
4812 | Stealing HttpOnly Cookie via XSS |
XSS |
NA |
Yasser Gersy (@yassergersy) |
Bug Bounty | 2018-04-08 | 2023-06-13 |
4808 | Please email me your password |
Blind XSS
Blind SQL injection
SMTP injection
Account takeover |
NA |
Jasmin Laundry (@JR0ch17) |
Bug Bounty | 2018-04-11 | 2023-06-13 |
4803 | #SecurityBreach — "How I was able to book hotel room for 1.50₹!" |
CORS misconfiguration |
NA |
Hariom Vashisth |
Bug Bounty | 2018-04-15 | 2023-06-13 |
4801 | Bypassing Captcha Like a Boss |
Captcha bypass |
NA |
Ak1T4 (@akita_zen) |
Bug Bounty | 2018-04-16 | 2023-06-13 |
4799 | From an error message to DB disclosure |
Hardcoded credentials |
NA |
Yumi |
Bug Bounty | 2018-04-17 | 2023-06-13 |
4798 | How I got stored XSS using file upload |
Stored XSS |
NA |
gujjuboy10x00 (@vis_hacker) |
Bug Bounty | 2018-04-17 | 2023-06-13 |
4797 | IDOR (at Private Bug Bounty Program) that could Leads to Personal Data Leaks |
IDOR |
NA |
YoKo Kho (@YokoAcc) |
Bug Bounty | 2018-04-17 | 2023-06-13 |
4796 | How I Get the Name of the Hotel (and other Data) that you ever Stay - Personal Data Leaks: Private Bug Bounty Program |
IDOR |
NA |
YoKo Kho (@YokoAcc) |
Bug Bounty | 2018-04-18 | 2023-06-13 |
4791 | #BugBounty — "Journey from LFI to RCE!!!"-How I was able to get the same in one of the India’s popular property buy/sell company. |
LFI
RCE |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-04-19 | 2023-06-13 |
4790 | Story Of a Stored XSS Bypass |
Stored XSS |
NA |
Prial Islam Khan (@prial261) |
Bug Bounty | 2018-04-21 | 2023-06-13 |
4789 | Turning Self-XSS into non-Self Stored-XSS via Authorization Issue at “PayPal Tech-Support and Brand Central Portal |
Stored XSS |
Paypal |
YoKo Kho (@YokoAcc) |
Bug Bounty | 2018-04-21 | 2023-06-13 |
4788 | Three Cases, Three Open Redirect Bypasses |
Open redirect |
NA |
Mmohammed Eldeeb (@malcolmx0x) |
Bug Bounty | 2018-04-22 | 2023-06-13 |
4786 | How we got LFI in apache Drill (Recon like a boss) |
LFI |
NA |
gujjuboy10x00 (@vis_hacker) |
Bug Bounty | 2018-04-23 | 2023-06-13 |
4785 | XSS “403 forbidden” bypass write up |
XSS |
NA |
Nur A Alam Dipu (@Dipu1A) |
Bug Bounty | 2018-04-25 | 2023-06-13 |
4784 | The Unknown Hero-App Logic Bugs |
Logic flaw |
Canva |
Circle Ninja (@circleninja) |
Bug Bounty | 2018-04-25 | 2023-06-13 |
4783 | How I earned 60K+ from private program |
Open redirect
Subdomain takeover
XSS
HTTP parameter pollution |
NA |
Siva Krishna Samireddi (@le4rner) |
Bug Bounty | 2018-04-25 | 2023-06-13 |
4780 | #BugBounty — How I was able to bypass firewall to get RCE and then went from server shell to get root user account! |
RCE |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-04-29 | 2023-06-13 |