4776 | Stealing money from one account to another account |
Logic flaw |
NA |
Ajay Gautam (@evilboyajay) |
Bug Bounty | 2018-05-02 | 2023-06-13 |
4774 | $4500 bounty - How I got lucky |
Subdomain takeover |
NA |
Eray Mitrani (@ErayMitrani) |
Bug Bounty | 2018-05-03 | 2023-06-13 |
4773 | How I Got Paid $0 From the India’s largest online gifting portal — Bug Bounty Program |
Payment tampering
Parameter tampering |
NA |
Hariom Vashisth |
Bug Bounty | 2018-05-05 | 2023-06-13 |
4772 | A Five Minute SQL-I |
SQL injection |
NA |
Ashish Jha |
Bug Bounty | 2018-05-06 | 2023-06-13 |
4771 | Asus Control Center – An Information Disclosure and a database connection Clear-Text password leakage Vulnerability |
Authorization flaw
Information disclosure |
Asus |
Mohamed A. Baset |
Bug Bounty | 2018-05-08 | 2023-06-13 |
4767 | Whatsapp- DOS vulnerability on Android/iOS/Web |
DoS |
Meta / Facebook |
Pratheesh P Narayanan (@PRATHEESH_PPN) |
Bug Bounty | 2018-05-15 | 2023-06-13 |
4763 | How i HACKED admin account via password reset IDOR function of one private currency exchanger site |
IDOR
Account takeover
Password reset |
NA |
Aayush Pokhrel (@aayushpok) |
Bug Bounty | 2018-05-19 | 2023-06-13 |
4762 | How i got 100$ from one private website |
Information disclosure |
NA |
Aayush Pokhrel (@aayushpok) |
Bug Bounty | 2018-05-19 | 2023-06-13 |
4759 | Self-XSS + CSRF to Stored XSS |
Self-XSS
CSRF
Stored XSS |
NA |
Renwa (@RenwaX23) |
Bug Bounty | 2018-05-20 | 2023-06-13 |
4756 | RCE by uploading a web.config |
RCE |
NA |
003random (@rub003) |
Bug Bounty | 2018-05-22 | 2023-06-13 |
4755 | #BugBounty — "How I was able to hack any user account via password reset?" |
IDOR
Account takeover
Password reset |
NA |
Bikash Gupta (@BgxDoc) |
Bug Bounty | 2018-05-23 | 2023-06-13 |
4751 | How i was able to get admin panel on a private program |
Weak credentials |
NA |
Shahzad Sadiq (@ShahzadSadiq25) |
Bug Bounty | 2018-05-29 | 2023-06-13 |
4750 | How I got hall of fame in two fortune 500 companies — An RCE story… |
RCE |
NA |
Alfie (@emenalf) |
Bug Bounty | 2018-05-29 | 2023-06-13 |
4749 | How I found 5 store XSS on a private program. Each worth "1,016.66$" |
Stored XSS |
NA |
Shahzad Sadiq (@ShahzadSadiq25) |
Bug Bounty | 2018-05-30 | 2023-06-13 |
4748 | Account Takeover and Blind XSS! Go Pro, get Bugs! |
IDOR
Stored XSS
Account takeover
Blind XSS |
NA |
Tabahi (@_tabahi) |
Bug Bounty | 2018-05-30 | 2023-06-13 |
4747 | 5k$ for path traversal on *.paypal-corp.com subdomain |
Path traversal |
Paypal |
lalka (@0x01alka) |
Bug Bounty | 2018-05-30 | 2023-06-13 |
4745 | #Bug Bounty — How I booked a rental house for just 1.00 INR — Price Manipulation in Citrus Pay |
Parameter tampering |
NA |
Raghavendra Reddy |
Bug Bounty | 2018-05-31 | 2023-06-13 |
4744 | How I Earned $750 Bounty Reward From AT&T bug Bounty -Adesh Kolte |
RCE
Clickjacking
XSS
Same Origin Method Execution |
AT&T |
Adesh Nandkishor kolte (@AdeshKolte) |
Bug Bounty | 2018-06-01 | 2023-06-13 |
4743 | How i converted SSRF to XSS in Jira. |
SSRF
XSS |
NA |
Ashish Kunwar (@D0rkerDevil) |
Bug Bounty | 2018-06-01 | 2023-06-13 |
4742 | Getting PHP Code Execution and leverage access to panels,databases,server |
Code injection |
NA |
Shawar Khan (@ShawarkOFFICIAL) |
Bug Bounty | 2018-06-01 | 2023-06-13 |
4740 | Reading Your Emails With A Read&Write Chrome Extension Same Origin Policy Bypass (~8 Million Users Affected) |
SOP bypass
Browser extension hacking |
NA |
Matthew Bryant (@IAmMandatory) |
Bug Bounty | 2018-06-05 | 2023-06-13 |
4739 | Are you sure this is a trusted email? |
Open mail relay |
NA |
Khaled Hassan |
Bug Bounty | 2018-06-05 | 2023-06-13 |
4738 | Searching for XSS found LDAP injection |
LDAP injection |
NA |
Davide Tampellini (@tampe125) |
Bug Bounty | 2018-06-05 | 2023-06-13 |
4736 | #BugBounty —" Database hacked of India’s Popular Sports company"-Bypassing Host Header to SQL injection to dumping Database — An unusual case of SQL injection. |
SQL injection |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-06-06 | 2023-06-13 |
4735 | How I found XSS via SSRF vulnerability -Adesh Kolte |
SSRF
XSS |
CERT-EU
Motorola
Stanford |
Adesh Nandkishor kolte (@AdeshKolte) |
Bug Bounty | 2018-06-07 | 2023-06-13 |