4733 | Steam, Fire, and Paste – A Story of UXSS via DOM-XSS & Clickjacking in Steam Inventory Helper |
DOM XSS
Universal XSS
Clickjacking
Browser extension hacking |
NA |
Matthew Bryant (@IAmMandatory) |
Bug Bounty | 2018-06-08 | 2023-06-13 |
4732 | [PayPal BBP] I could’ve deleted All SMC messages. Using Brute-Force technique. |
CSRF |
Paypal |
Ayoub Ait Elmokhtar (@aessadek) |
Bug Bounty | 2018-06-10 | 2023-06-13 |
4731 | How I Found CVE-2018-8819: Out-of-Band (OOB) XXE in WebCTRL |
XXE |
NA |
Darrell Damstedt |
Bug Bounty | 2018-06-11 | 2023-06-13 |
4730 | Server-Side Spreadsheet Injection – Formula Injection to Remote Code Execution |
CSV injection
Server side spreadsheet injection
Formula injection
RCE |
Google |
Jake Miller |
Bug Bounty | 2018-06-11 | 2023-06-13 |
4729 | Full account Takeover via reset password function |
IDOR
Account takeover
Password reset |
NA |
Khaled Hassan |
Bug Bounty | 2018-06-12 | 2023-06-13 |
4727 | Vulnerability Netflix (cross-site-scripting) XSS |
Reflected XSS |
Netflix |
Bada Diaz (@bada77) |
Bug Bounty | 2018-06-13 | 2023-06-13 |
4726 | How I got paid premium plan for free on many popular websites |
Logic flaw |
NA |
Khaled Hassan |
Bug Bounty | 2018-06-13 | 2023-06-13 |
4725 | The 2.5 BTC Stored XSS |
Stored XSS |
NA |
Khaled Hassan |
Bug Bounty | 2018-06-13 | 2023-06-13 |
4713 | How I got access to local AWS info via Jira |
SSRF |
NA |
Coen Goedegebure (@CoenHimself) |
Bug Bounty | 2018-06-24 | 2023-06-13 |
4712 | Account Take over via reset password |
Password reset
Account takeover |
NA |
Yasser Gersy (@yassergersy) |
Bug Bounty | 2018-06-25 | 2023-06-13 |
4710 | How re-signing up for an account lead to account takeover |
Logic flaw
Account takeover |
NA |
Zseano (@zseano) |
Bug Bounty | 2018-06-26 | 2023-06-13 |
4709 | Take Advantage of Out-of-Scope Domains in Bug Bounty Programs |
XSS |
NA |
Abdullah Hussam (@Abdulahhusam) |
Bug Bounty | 2018-06-27 | 2023-06-13 |
4707 | Unauthenticated Command Injection Vulnerability in VMware NSX SD-WAN by VeloCloud |
OS command injection
RCE |
VMware |
Brian Sullivan |
Bug Bounty | 2018-06-29 | 2023-06-13 |
4706 | https://leigh-annegalloway.com/tumblr/ |
Captcha bypass
Username enumeration
Information disclosure |
Automattic |
Leigh-Anne Galloway (@L_AGalloway) |
Bug Bounty | 2018-06-29 | 2023-06-13 |
4705 | Chaining Multiple Vulnerabilities to Gain Admin Access |
IDOR
Account takeover |
NA |
Ben Sadeghipour (@nahamsec) |
Bug Bounty | 2018-07-02 | 2023-06-13 |
4703 | Latex to RCE, Private Bug Bounty Program |
RCE |
NA |
Yashar Shahinzadeh (@YShahinzadeh) |
Bug Bounty | 2018-07-06 | 2023-06-13 |
4702 | CVE-2016-3473 |
XXE |
NA |
hateshape (@hateshaped) |
Bug Bounty | 2018-07-06 | 2023-06-13 |
4701 | CVE-2018-8819 |
XXE |
NA |
hateshape (@hateshaped) |
Bug Bounty | 2018-07-07 | 2023-06-13 |
4699 | #BugBounty - Compromising User Account- "How I was able to compromise user account via HTTP Parameter Pollution(HPP)" |
HTTP parameter pollution
Password reset
Account takeover |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-07-07 | 2023-06-13 |
4694 | Bug Bounty at Bangladeshi Site. |
SQL injection |
NA |
Shaifullah Shaon |
Bug Bounty | 2018-07-15 | 2023-06-13 |
4693 | Attacking PostgreSQL Database |
Bruteforce
Weak credentials |
NA |
Vishnuraj |
Bug Bounty | 2018-07-16 | 2023-06-13 |
4691 | CVE-2018-13784: PrestaShop 1.6.x Privilege Escalation |
Privilege escalation
Session management issue |
PrestaShop |
Charles Fol (@cfreal_) |
Bug Bounty | 2018-07-16 | 2023-06-13 |
4690 | Hacking thousands of companies through their helpdesk |
Account takeover
DoS
Logic flaw |
NA |
Khaled Hassan |
Bug Bounty | 2018-07-17 | 2023-06-13 |
4687 | Oracle WebLogic - Multiple SAML Vulnerabilities (CVE-2018-2998/CVE-2018-2933) |
SAML
Authentication bypass |
Oracle (WebLogic) |
Denis Andzakovic |
Bug Bounty | 2018-07-18 | 2023-06-13 |
4682 | RCE due to ShowExceptions |
RCE
Information disclosure
Debugging enabled |
NA |
Harsh Jaiswal (@rootxharsh) |
Bug Bounty | 2018-07-20 | 2023-06-13 |