5243 | Flickr XSRF to Change Photo Details |
XSRF |
Flickr |
Abdullah Hussam (@Abdulahhusam) |
Bug Bounty | 2014-08-06 | 2023-06-13 |
5214 | Blind SQL Inejction [Hootsuite] |
Blind SQL injection |
Hootsuite |
Abdullah Hussam (@Abdulahhusam) |
Bug Bounty | 2015-08-01 | 2023-06-13 |
5213 | One Payload to XSS Them All! |
Flash XSS |
Adobe |
Abdullah Hussam (@Abdulahhusam) |
Bug Bounty | 2015-08-03 | 2023-06-13 |
5206 | Cloudflare WAF XSS |
XSS |
Cloudflare |
Abdullah Hussam (@Abdulahhusam) |
Bug Bounty | 2015-11-16 | 2023-06-13 |
5205 | How To Hack PayU – And Buy 10x More For The Same Price |
RCE |
PayU |
Rick Harris (@codel10n) |
Bug Bounty | 2015-12-18 | 2023-06-13 |
5194 | How I Hacked [Oculus] OAuth +Ebay +IBM |
Unrestricted file upload
XSS |
Meta / Facebook
Ebay
IBM
AnswerHub |
Abdullah Hussam (@Abdulahhusam) |
Bug Bounty | 2016-02-12 | 2023-06-13 |
5164 | Medium Full Account Takeover By One Click |
XSS |
Medium |
Abdullah Hussam (@Abdulahhusam) |
Bug Bounty | 2016-06-23 | 2023-06-13 |
5148 | Samsung Galaxy Apps MiTM vulnerabilities |
MiTM
Android |
Samsung |
Simone Margaritelli (@evilsocket) |
Bug Bounty | 2016-08-17 | 2023-06-13 |
5136 | Vine Re-auth Bypass [Twitter Bug Bounty] |
Authentication flaw |
Twitter |
Abdullah Hussam (@Abdulahhusam) |
Bug Bounty | 2016-09-21 | 2023-06-13 |
5126 | Leak Private Videos [Vimeo Bug Bounty] |
Logic flaw
Authorization flaw |
Vimeo |
Abdullah Hussam (@Abdulahhusam) |
Bug Bounty | 2016-10-23 | 2023-06-13 |
5067 | Android Browser Same Origin Policy Bypass < 4.4 - CVE-2014-6041 |
SOP bypass |
Google |
Rafay Baloch (@rafaybaloch) |
Bug Bounty | 2017-06-01 | 2023-06-13 |
5041 | Medium Content Spoofing Leads to XSS |
Content spoofing
Stored XSS |
Medium |
Abdullah Hussam (@Abdulahhusam) |
Bug Bounty | 2017-07-08 | 2023-06-13 |
5005 | Reflected XSS on www.yahoo.com |
Reflected XSS |
Yahoo! / Verizon Media |
Samuel (@saamux) |
Bug Bounty | 2017-08-12 | 2023-06-13 |
4979 | Exploiting a Single Request for Multiple Vulnerabilities |
Stored XSS
Reflected XSS
SSRF
OS command injection |
NA |
Osama Ansari (@AnsariOsama10) |
Bug Bounty | 2017-09-19 | 2023-06-13 |
4978 | First bounty, time to step up my game |
Same Origin Method Execution |
NA |
Roderick Schaefer (@kciredor_) |
Bug Bounty | 2017-09-19 | 2023-06-13 |
4969 | Filter Bypass to Reflected XSS on https://finance.yahoo.com (mobile version) |
Reflected XSS |
Yahoo! / Verizon Media |
Samuel (@saamux) |
Bug Bounty | 2017-09-24 | 2023-06-13 |
4960 | Leaking Amazon.com CSRF Tokens Using Service Worker API |
CSRF |
Amazon |
Abdullah Hussam (@Abdulahhusam) |
Bug Bounty | 2017-10-11 | 2023-06-13 |
4952 | Slack SAML authentication bypass |
Authentication bypass |
Slack |
Antonio Sanso (@asanso) |
Bug Bounty | 2017-10-26 | 2023-06-13 |
4937 | How I Pwned a company using IDOR & Blind XSS |
IDOR
Blind XSS |
NA |
Osama Ansari (@AnsariOsama10) |
Bug Bounty | 2017-11-15 | 2023-06-13 |
4880 | Full Account Takeover through CORS with connection Sockets |
CORS misconfiguration
Account takeover |
NA |
Samuel (@saamux) |
Bug Bounty | 2018-01-25 | 2023-06-13 |
4832 | Leaking WordPress CSRF Tokens for Fun, $1337 bounty, and CVE-2017-5489 |
CSRF |
WordPress |
Abdullah Hussam (@Abdulahhusam) |
Bug Bounty | 2018-03-15 | 2023-06-13 |
4800 | Spoof an user to create a description of a group in Flickr |
IDOR |
Flickr |
Samuel (@saamux) |
Bug Bounty | 2018-04-16 | 2023-06-13 |
4791 | #BugBounty — "Journey from LFI to RCE!!!"-How I was able to get the same in one of the India’s popular property buy/sell company. |
LFI
RCE |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-04-19 | 2023-06-13 |
4783 | How I earned 60K+ from private program |
Open redirect
Subdomain takeover
XSS
HTTP parameter pollution |
NA |
Siva Krishna Samireddi (@le4rner) |
Bug Bounty | 2018-04-25 | 2023-06-13 |
4744 | How I Earned $750 Bounty Reward From AT&T bug Bounty -Adesh Kolte |
RCE
Clickjacking
XSS
Same Origin Method Execution |
AT&T |
Adesh Nandkishor kolte (@AdeshKolte) |
Bug Bounty | 2018-06-01 | 2023-06-13 |