5121 | Bypassing Ebay XSS Protection to launch XSS by Nirmal Dahal |
Reflected XSS |
Ebay |
Nirmal Dahal (@TheNittam) |
Bug Bounty | 2016-11-18 | 2023-06-13 |
5120 | Authentication bypass on Ubiquity’s Single Sign-On via subdomain takeover |
Subdomain takeover
Authentication bypass |
Ubiquity Networks |
Arne Swinnen (@ArneSwinnen) |
Bug Bounty | 2016-11-29 | 2023-06-13 |
5119 | Atom.io Misconfiguration Allowed Code Execution on Untrusted Networks |
RCE |
GitHub |
Adam Baldwin (@adam_baldwin) |
Bug Bounty | 2016-11-30 | 2023-06-13 |
5118 | The Orphaned Internet – Taking Over 120K Domains via a DNS Vulnerability in AWS, Google Cloud, Rackspace and Digital Ocean |
Domain takeover |
Google
Amazon
Rackspace
DigitalOcean |
Matthew Bryant (@IAmMandatory) |
Bug Bounty | 2016-12-05 | 2023-06-13 |
5117 | IDOR in Facebook%27s Acquisition (Parse) |
IDOR |
Meta / Facebook |
Venkatesh Sivakumar (@pranavvenkats) |
Bug Bounty | 2016-12-11 | 2023-06-13 |
5116 | Cross-site-scripting on one of the largest Dutch franchisors |
DOM XSS |
Hema |
Tijme Gommers (@tijme) |
Bug Bounty | 2016-12-20 | 2023-06-13 |
5115 | Stealing passwords from McDonald%27s users |
Reflected XSS
AngularJS sandbox bypass |
McDonalds |
Tijme Gommers (@tijme) |
Bug Bounty | 2017-01-09 | 2023-06-13 |
5114 | How I could have Hacked IIT Guwahati’s website |
Unrestricted file upload |
IIT Guwahati |
Sai Krishna Kothapalli (@kmskrishna) |
Bug Bounty | 2017-01-09 | 2023-06-13 |
5113 | 0day writeup: XXE in uber.com |
XXE |
Uber |
- |
Bug Bounty | 2017-01-24 | 2023-06-13 |
5112 | How I could have compromised any account on one of the biggest startup based in California |
Account takeover
IDOR
Password reset |
NA |
Prateek Tiwari (@prateek_0490) |
Bug Bounty | 2017-01-28 | 2023-06-13 |
5111 | I got emails - G Suite Vulnerability |
Logic flaw
Authorization flaw |
Google
Meta / Facebook
Yelp |
Rojan Rijal (@uraniumhacker) |
Bug Bounty | 2017-02-02 | 2023-06-13 |
5110 | Spring Boot RCE |
RCE
SpEL injection
Spring Boot |
NA |
Tushar (@0xdeadpool) |
Bug Bounty | 2017-02-02 | 2023-06-13 |
5109 | Cross Site Request Forgery in Facebook |
CSRF |
Meta / Facebook |
Zahid Ali |
Bug Bounty | 2017-02-04 | 2023-06-13 |
5108 | Facebook Groups Hack |
Authorization flaw
Logic flaw |
Meta / Facebook |
Zahid Ali |
Bug Bounty | 2017-02-04 | 2023-06-13 |
5107 | Type Juggling and PHP Object Injection, and SQLi, Oh My! |
Type juggling
PHP Object Injection
Insecure deserialization
SQL injection |
NA |
Justin Kennedy (@jstnkndy) |
Bug Bounty | 2017-02-07 | 2023-06-13 |
5106 | Bypassed Facebook Phone Number Security |
Authorization flaw
Logic flaw
Information disclosure |
Meta / Facebook |
Zahid Ali |
Bug Bounty | 2017-02-10 | 2023-06-13 |
5105 | Facebook Account Recovery Form (CONFLICTING) |
Logic flaw |
Meta / Facebook |
Zahid Ali |
Bug Bounty | 2017-02-13 | 2023-06-13 |
5104 | Vulnerabilities in Facebook Login Approval Form |
Authorization flaw
Logic flaw |
Meta / Facebook |
Zahid Ali |
Bug Bounty | 2017-02-14 | 2023-06-13 |
5103 | Lightweight markup: a trio of persistent XSS in GitLab |
Stored XSS |
GitLab |
Yasin Soliman (@SecurityYasin) |
Bug Bounty | 2017-02-15 | 2023-06-13 |
5102 | SQL injection in an UPDATE query - a bug bounty story! |
SQL injection |
NA |
Mahmoud Gamal (@Zombiehelp54) |
Bug Bounty | 2017-02-17 | 2023-06-13 |
5101 | From RSS to XXE: feed parsing on Hootsuite |
XSS
XXE |
Hootsuite |
Yasin Soliman (@SecurityYasin) |
Bug Bounty | 2017-02-17 | 2023-06-13 |
5100 | How I was able to remove your Instagram Phone number |
Bruteforce |
Meta / Facebook |
Neeraj Sonaniya (@neeraj_sonaniya) |
Bug Bounty | 2017-02-20 | 2023-06-13 |
5099 | How I bypassed State Bank of India OTP. |
OTP bypass |
State Bank of India |
Neeraj Sonaniya (@neeraj_sonaniya) |
Bug Bounty | 2017-02-20 | 2023-06-13 |
5098 | Practical Exploitation of Error Based Sql Injection |
SQL injection |
NA |
Eslam Salem (@net_code) |
Bug Bounty | 2017-02-20 | 2023-06-13 |
5097 | How I got your phone number through Facebook |
Logic flaw |
Meta / Facebook |
Inti De Ceukelaire (@securinti) |
Bug Bounty | 2017-02-20 | 2023-06-13 |