3024 | Pentest-Story: Empirum password decryption |
Weak crypto
Reverse engineering |
Matrix42 |
evait security GmbH (@evait_security) |
Bug Bounty | 2020-11-16 | 2023-06-13 |
3023 | Stealing User’s PII info by visiting API endpoint directly |
Information disclosure
Logic flaw |
NA |
Kunal pandey (@kunalp94) |
Bug Bounty | 2020-11-16 | 2023-06-13 |
3022 | Firefox: How a website could steal all your cookies |
Arbitrary file read |
Mozilla |
Pedro Oliveira (@kanytu) |
Bug Bounty | 2020-11-16 | 2023-06-13 |
3021 | Hacking into (RCE) Government Server operated for the US Department of Energy’s National Nuclear Security Administration. |
RCE
OS command injection |
US Department of Energy |
Shaheen Fazim |
Bug Bounty | 2020-11-16 | 2023-06-13 |
3020 | OpenEMR 5.0.1.3 Arbitrary File Actions |
Arbitrary file write
Arbitrary file read
Security code review |
OpenEMR |
Josh Fam (@Pullerze) |
Bug Bounty | 2020-11-17 | 2023-06-13 |
3019 | Tale of 3 vulnerabilities to account takeover! |
SSRF
Account takeover |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2020-11-17 | 2023-06-13 |
3018 | Server Side Misconfigurartion - A Funny Fix |
Information disclosure |
Basecamp |
Jerry Shah (@Jerry) |
Bug Bounty | 2020-11-18 | 2023-06-13 |
3017 | GraphQL IDOR in Facebook streamer dashboard. |
IDOR
GraphQL |
Meta / Facebook |
Kailash (@Corrupted_brain) |
Bug Bounty | 2020-11-18 | 2023-06-13 |
3016 | Out of Band XXE in an E-commerce IOS app |
XXE |
NA |
Gaurang Bhatnagar (@0xgaurang) |
Bug Bounty | 2020-11-19 | 2023-06-13 |
3015 | Arbitrary File Write On Client By ADB Pull |
Arbitrary file write |
Google |
Serafina (Sera) Tonin Brocious (@daeken) |
Bug Bounty | 2020-11-19 | 2023-06-13 |
3014 | Bypassing the Redirect filters with 7 ways |
Open redirect
OAuth |
NA |
ElMahdi Mrhassel (@ElMrhassel) |
Bug Bounty | 2020-11-19 | 2023-06-13 |
3013 | Exploiting dynamic rendering engines to take control of web apps |
SSRF
Open redirect |
NA |
Vasilii Ermilov (@ermil0v) |
Bug Bounty | 2020-11-19 | 2023-06-13 |
3012 | Turning Blind Error Based SQL Injection into Exploitable Boolean One |
SQL injection |
NA |
Ozgur Alp (@ozgur_bbh) |
Bug Bounty | 2020-11-21 | 2023-06-13 |
3011 | 2 Reflected XSS In Razer |
Reflected XSS |
Razer |
Mostafa |
Bug Bounty | 2020-11-21 | 2023-06-13 |
3010 | Weird (im)possible XSS on error page |
Reflected XSS |
NA |
Rody Shahnazarian (@Komradz86) |
Bug Bounty | 2020-11-21 | 2023-06-13 |
3009 | Escalating XSS to Account Takeover |
Reflected XSS
Account takeover |
NA |
Aditya Verma (@0cirius0) |
Bug Bounty | 2020-11-22 | 2023-06-13 |
3008 | Fixing a Google Vulnerability |
Privilege escalation |
Google |
I (@InsecureNature) |
Bug Bounty | 2020-11-22 | 2023-06-13 |
3007 | SD-PWN — Part 3 — Cisco vManage — Another Day, Another Network Takeover |
RCE
SSRF
Arbitrary file write
Path traversal
OS command injection
Local Privilege Escalation |
Cisco |
Realmode Labs (@RealmodeLabs) |
Bug Bounty | 2020-11-23 | 2023-06-13 |
3006 | Reflected Cross Site Scripting on REDACTED Program (Bounty: 750$) |
Reflected XSS |
NA |
can1337 (@canmustdie) |
Bug Bounty | 2020-11-23 | 2023-06-13 |
3005 | How images on Github will leak your private information |
Information disclosure |
GitHub |
fuomag9 (@fuomag9) |
Bug Bounty | 2020-11-24 | 2023-06-13 |
3004 | SD-PWN Part 4 — VMware VeloCloud — The Last Takeover |
RCE
Authentication bypass
Default credentials
SQL injection
Path traversal
LFI |
VMware |
Realmode Labs (@RealmodeLabs) |
Bug Bounty | 2020-11-26 | 2023-06-13 |
3003 | Pre-Account Takeover using OAuth Misconfiguration |
OAuth |
NA |
the_unluck_guy (@7he_unlucky_guy) |
Bug Bounty | 2020-11-26 | 2023-06-13 |
3002 | How i got easy $$$ for SQL Injection Bug |
SQL injection |
NA |
Rafi Andhika Galuh |
Bug Bounty | 2020-11-26 | 2023-06-13 |
3001 | The Story of my first critical bug |
SQL injection |
NA |
Shellbr3ak (@0xShellbr3ak) |
Bug Bounty | 2020-11-29 | 2023-06-13 |
3000 | Bcrypt — Account TakeOver Due To Weak Encryption — #HR51KDB |
Information disclosure
Account takeover |
NA |
DarkLotus (@darklotuskdb) |
Bug Bounty | 2020-11-29 | 2023-06-13 |