2870 | IDOR Revealing Images CDN Links |
IDOR |
NA |
susan wagle |
Bug Bounty | 2021-01-25 | 2023-06-13 |
2869 | Chaining a self XSS to Account Takeover |
Self-XSS
Reflected XSS
Account takeover |
NA |
Arman Sameer (@ArmanSameer95) |
Bug Bounty | 2021-01-25 | 2023-06-13 |
2868 | Get paid by smuggling, the legal way |
HTTP Request Smuggling |
NA |
James Ling (@James_puppykok) |
Bug Bounty | 2021-01-25 | 2023-06-13 |
2867 | Leaking issues from linked Jira – Atlassian Confluence Server |
XS-Search |
Atlassian |
yeuchimse (@yeuchimse) |
Bug Bounty | 2021-01-25 | 2023-06-13 |
2866 | BMW Bug Bounty – Account Verification Bypass writeup |
OTP bypass
Bruteforce
Lack of rate limiting |
BMW |
Pethuraj (@Pethuraj) |
Bug Bounty | 2021-01-26 | 2023-06-13 |
2865 | Finding SSRF BY Full Automation |
SSRF |
NA |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2021-01-27 | 2023-06-13 |
2864 | $500 For No Rate Limit On Forgot Password Page |
Lack of rate limiting
Password reset |
NA |
BBHC (@community_bug) |
Bug Bounty | 2021-01-27 | 2023-06-13 |
2863 | Hijacking Google Drive Files (Documents, Photo & Video) Through Google Docs Sharing |
Clickjacking |
Google |
santuySec (@santuySec) |
Bug Bounty | 2021-01-27 | 2023-06-13 |
2862 | Bragging Rights(Part 1): Short story of a bug wave |
IDOR
Stored XSS
SSRF
Subdomain takeover
Hardcoded credentials |
NA |
Manas Harsh (@ManasH4rsh) |
Bug Bounty | 2021-01-27 | 2023-06-13 |
2861 | Weird functionality leads to Account Takeover (Millions of Users affected) |
Account takeover
Authentication flaw |
NA |
Sahil Mehra (@nullr3x) |
Bug Bounty | 2021-01-27 | 2023-06-13 |
2860 | How We Escaped Docker in Azure Functions |
Privilege escalation
Cloud |
Microsoft |
Intezer |
Bug Bounty | 2021-01-27 | 2023-06-13 |
2859 | Business Logic Error Methodology (easy way) + PoC-s |
Logic flaw |
NA |
Vuk Ivanovic |
Bug Bounty | 2021-01-28 | 2023-06-13 |
2858 | OTP Bypass Account Takeover to Admin Panel — Ft. Header Injection |
OTP bypass
Account takeover |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2021-01-28 | 2023-06-13 |
2857 | Remote Code Execution – LimeSurvey (CVE-2018-7556) |
RCE |
NA |
yeuchimse (@yeuchimse) |
Bug Bounty | 2021-01-28 | 2023-06-13 |
2856 | Analysing Crash Messages To Achieve Blind Root Command Injection |
OS command injection |
NA |
Shawar Khan (@ShawarkOFFICIAL) |
Bug Bounty | 2021-01-28 | 2023-06-13 |
2855 | Launching Internal & Non-Exported Deeplinks On Facebook |
CSRF |
Meta / Facebook |
Ashley King (@AshleyKingUK) |
Bug Bounty | 2021-01-28 | 2023-06-13 |
2854 | Destroying Armies and Villages through Cross-Site Scripting - Bug Bounty Write-up |
Stored XSS |
InnoGames |
Fábio Freitas (@0xfabiof) |
Bug Bounty | 2021-01-29 | 2023-06-13 |
2853 | Broken Access Control & Stored XSS - Easy Hunt |
Stored XSS
IDOR |
NA |
Kabeer (@iTheKabeer) |
Bug Bounty | 2021-01-29 | 2023-06-13 |
2852 | How I chained P4 To P2 [Open Redirection To Full Account Takeover] |
Open redirect
Account takeover |
NA |
Bishal Shrestha (@bishal0x01) |
Bug Bounty | 2021-01-30 | 2023-06-13 |
2851 | Android apk leaks access token to takeover the whole infrastructure |
Information disclosure
Hardcoded credentials
Android |
NA |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2021-01-30 | 2023-06-13 |
2850 | An Interesting Account Takeover Vulnerability |
IDOR
Account takeover |
NA |
Avanish Pathak (@avanish46) |
Bug Bounty | 2021-01-30 | 2023-06-13 |
2849 | An unexpected bug |
Bruteforce |
NA |
Nitin yadav (@Nitinydv14) |
Bug Bounty | 2021-01-31 | 2023-06-13 |
2848 | An Account Takeover Vulnerability Due to Response Manipulation. |
Authentication bypass
Account takeover |
NA |
Avanish Pathak (@avanish46) |
Bug Bounty | 2021-01-31 | 2023-06-13 |
2847 | Disclose the FB profile of Facebook employees who create official announcement messages (Bug Bounty) |
Information disclosure |
Meta / Facebook |
Amine Aboud (@amineaboud) |
Bug Bounty | 2021-02-01 | 2023-06-13 |
2846 | Access developer tasks list of any Facebook Application (GraphQL IDOR) |
IDOR |
Meta / Facebook |
Amine Aboud (@amineaboud) |
Bug Bounty | 2021-02-01 | 2023-06-13 |