5226 | vimeo IDOR ( buying pro membership & ondemand videos for 0.1$ ) |
IDOR |
Vimeo |
N B Sri Harsha (@nbsriharsha) |
Bug Bounty | 2015-01-16 | 2023-06-13 |
4682 | RCE due to ShowExceptions |
RCE
Information disclosure
Debugging enabled |
NA |
Harsh Jaiswal (@rootxharsh) |
Bug Bounty | 2018-07-20 | 2023-06-13 |
4528 | Path traversal while uploading results in RCE |
Path traversal
RCE |
NA |
Harsh Jaiswal (@rootxharsh) |
Bug Bounty | 2018-10-15 | 2023-06-13 |
4483 | OLX Reflected XSS on Resend Code link !! |
Reflected XSS |
OLX |
Harshad Gaikwad (@h4rsh4d) |
Bug Bounty | 2018-11-12 | 2023-06-13 |
4263 | Vimeo SSRF with code execution potential. |
SSRF |
Vimeo |
Harsh Jaiswal (@rootxharsh) |
Bug Bounty | 2019-03-08 | 2023-06-13 |
4179 | Stealing local storage data through XSS |
Stored XSS
Account takeover |
NA |
Harshad Gaikwad (@h4rsh4d) |
Bug Bounty | 2019-04-25 | 2023-06-13 |
3774 | Abusing feature to steal your tokens |
OAuth |
NA |
Harsh Jaiswal (@rootxharsh) |
Bug Bounty | 2019-12-17 | 2023-06-13 |
3528 | From Recon to P1 (Critical) — An Easy Win |
Exposed registration page |
NA |
Harsh Bothra (@harshbothra_) |
Bug Bounty | 2020-04-24 | 2023-06-13 |
3519 | Recon to Sensitive Information Disclosure in Minutes |
Information disclosure
Outdated component with a known vulnerability |
NA |
Harsh Bothra (@harshbothra_) |
Bug Bounty | 2020-04-28 | 2023-06-13 |
3483 | Weak Cryptography in Password Reset to Full Account Takeover |
Account takeover
Password reset
Cryptographic issues |
NA |
Harsh Bothra (@harshbothra_) |
Bug Bounty | 2020-05-15 | 2023-06-13 |
3471 | Multiple flaws leads to Account Takeover within an Application |
Account takeover
Password reset |
NA |
Harshit Sengar (@sengarharshit1) |
Bug Bounty | 2020-05-18 | 2023-06-13 |
3415 | XSS to Database Credential Leakage & Database Access — Story of total luck! |
Reflected XSS
Information disclosure |
NA |
Harsh Bothra (@harshbothra_) |
Bug Bounty | 2020-06-06 | 2023-06-13 |
3400 | Let’s Bypass CSRF Protection & Password Confirmation to Takeover Victim Accounts :D |
CSRF |
NA |
Harsh Bothra (@harshbothra_) |
Bug Bounty | 2020-06-12 | 2023-06-13 |
3348 | Misconfigured S3 Bucket Access Controls to Critical Vulnerability |
AWS misconfiguration |
NA |
Harsh Bothra (@harshbothra_) |
Bug Bounty | 2020-07-02 | 2023-06-13 |
3296 | Unique Case for Price Manipulation | BugBounty | VAPT |
Payment tampering |
NA |
Harshit Sengar (@sengarharshit1) |
Bug Bounty | 2020-07-18 | 2023-06-13 |
3211 | Witnet Network Bug Bounty: DOS Bug from Harsh Jain |
DoS |
Witnet |
Harsh Jain |
Bug Bounty | 2020-08-17 | 2023-06-13 |
3146 | How I By-pass the login page and 2FA authentication….. |
Authentication bypass
OTP bypass
MFA bypass |
NA |
Harsh |
Bug Bounty | 2020-09-20 | 2023-06-13 |
3121 | Journey Of My First Bug Bounty (Nov 2018) |
Authentication bypass |
Samsung |
Harsh Tyagi (@harshtya9i) |
Bug Bounty | 2020-10-02 | 2023-06-13 |
3098 | How I find my first P1 level Bug. $$$ |
XSS |
NA |
Harsh |
Bug Bounty | 2020-10-13 | 2023-06-13 |
3081 | Accidental Observation to Critical IDOR |
IDOR |
NA |
Harsh Bothra (@harshbothra_) |
Bug Bounty | 2020-10-24 | 2023-06-13 |
3080 | My first bug on Google |
IDOR |
Google |
Manas Harsh (@ManasH4rsh) |
Bug Bounty | 2020-10-25 | 2023-06-13 |
3039 | Evading Filters to perform the Arbitrary URL Redirection Attack |
Open redirect |
NA |
Harsh Bothra (@harshbothra_) |
Bug Bounty | 2020-11-12 | 2023-06-13 |
2890 | Finding 0day to hack Apple |
RCE
ColdFusion |
Apple |
Harsh Jaiswal (@rootxharsh) |
Bug Bounty | 2021-01-16 | 2023-06-13 |
2862 | Bragging Rights(Part 1): Short story of a bug wave |
IDOR
Stored XSS
SSRF
Subdomain takeover
Hardcoded credentials |
NA |
Manas Harsh (@ManasH4rsh) |
Bug Bounty | 2021-01-27 | 2023-06-13 |
2755 | Bragging Rights: Killing File Uploads softly |
Unrestricted file upload
Stored XSS |
NA |
Manas Harsh (@ManasH4rsh) |
Bug Bounty | 2021-02-28 | 2023-06-13 |