5287 | My Experience with the PayPal Bug Bounty Programme |
CSRF |
Paypal |
Jack Whitton (@fin1te) |
Bug Bounty | 2012-10-12 | 2023-06-13 |
5285 | Persistent XSS on myworld.ebay.com |
XSS |
Ebay |
Jack Whitton (@fin1te) |
Bug Bounty | 2013-01-27 | 2023-06-13 |
5284 | Framing, Part 1: Click-Jacking Etsy |
Clickjacking |
Etsy |
Jack Whitton (@fin1te) |
Bug Bounty | 2013-02-05 | 2023-06-13 |
5281 | Stealing Facebook Access Tokens with a Double Submit |
CSRF
OAuth |
Meta / Facebook |
Jack Whitton (@fin1te) |
Bug Bounty | 2013-04-13 | 2023-06-13 |
5279 | Overwriting Banner Images on Etsy |
Authorization flaw |
Etsy |
Jack Whitton (@fin1te) |
Bug Bounty | 2013-05-21 | 2023-06-13 |
5278 | Hijacking a Facebook Account with SMS |
Authorization flaw
Account takeover |
Meta / Facebook |
Jack Whitton (@fin1te) |
Bug Bounty | 2013-06-26 | 2023-06-13 |
5271 | Removing Covers Images on Friendship Pages, on Facebook |
Authorization flaw |
Meta / Facebook |
Jack Whitton (@fin1te) |
Bug Bounty | 2013-09-25 | 2023-06-13 |
5268 | Content Types and XSS: Facebook Studio |
XSS |
Meta / Facebook |
Jack Whitton (@fin1te) |
Bug Bounty | 2013-10-21 | 2023-06-13 |
5264 | Instagram%27s One-Click Privacy Switch |
CSRF |
Meta / Facebook |
Jack Whitton (@fin1te) |
Bug Bounty | 2013-10-31 | 2023-06-13 |
5260 | Abusing CORS for an XSS on Flickr |
XSS |
Flickr |
Jack Whitton (@fin1te) |
Bug Bounty | 2013-12-12 | 2023-06-13 |
5247 | Google Docs %27ClickJacking%27 (Information Disclosure) |
Clickjacking |
Google |
Matt Austin (@mattaustin) |
Bug Bounty | 2014-05-13 | 2023-06-13 |
5215 | Bypassing Google Authentication on Periscope%27s Administration Panel |
Authentication bypass |
Google |
Jack Whitton (@fin1te) |
Bug Bounty | 2015-07-20 | 2023-06-13 |
5198 | An XSS on Facebook via PNGs & Wonky Content Types |
XSS |
Meta / Facebook |
Jack Whitton (@fin1te) |
Bug Bounty | 2016-01-27 | 2023-06-13 |
5189 | Uber Bug Bounty: Turning Self-XSS into Good-XSS |
XSS |
Uber |
Jack Whitton (@fin1te) |
Bug Bounty | 2016-03-22 | 2023-06-13 |
5186 | Obtaining Login Tokens for an Outlook, Office or Azure Account |
CSRF |
Microsoft |
Jack Whitton (@fin1te) |
Bug Bounty | 2016-04-03 | 2023-06-13 |
5182 | Facebook ClickJacking – How we put a new dress on Facebook UI |
Clickjacking |
Meta / Facebook |
Mohamed A. Baset |
Bug Bounty | 2016-04-22 | 2023-06-13 |
5181 | Official Telegram Web Client ClickJacking Vulnerability – When crypto is strong and client is weak |
Clickjacking |
Telegram |
Mohamed A. Baset |
Bug Bounty | 2016-04-28 | 2023-06-13 |
5180 | WhatsApp Clickjacking Vulnerability – Yet another web client failure! |
Clickjacking |
Meta / Facebook |
Mohamed A. Baset |
Bug Bounty | 2016-05-04 | 2023-06-13 |
5177 | FirefoxOS Find My Device Service Clickjacking Bug results in Changing PINs, Wiping and Locking Phones! |
Clickjacking |
Mozilla |
Mohamed A. Baset |
Bug Bounty | 2016-05-12 | 2023-06-13 |
5171 | Microsoft Yammer Clickjacking – Exploiting HTML5 Security Features |
Clickjacking |
Microsoft |
Mohamed A. Baset |
Bug Bounty | 2016-05-18 | 2023-06-13 |
5162 | TopCoder.com Vulnerabilities – A tail of site-wide bugs leads to accounts compromise & payments hijacking |
CSRF
Account takeover |
Topcoder.com |
Mohamed A. Baset |
Bug Bounty | 2016-06-28 | 2023-06-13 |
5154 | BMW Vulnerabilities – Hijack Cars ConnectedDrive™ Service! |
Clickjacking
CSRF |
BMW |
Mohamed A. Baset |
Bug Bounty | 2016-07-24 | 2023-06-13 |
5153 | Messenger.com Site-Wide CSRF |
CSRF |
Meta / Facebook |
Jack Whitton (@fin1te) |
Bug Bounty | 2016-07-26 | 2023-06-13 |
5065 | Stored XSS, CSRF And Clickjacking Vulnerabilities in Opera |
Stored XSS
CSRF
Clickjacking |
Opera |
Rafay Baloch (@rafaybaloch) |
Bug Bounty | 2017-06-01 | 2023-06-13 |
5033 | ctrl+c & ctrl+v to Steal SESSIONID |
Clickjacking |
NA |
Arbaz Hussain (@ArbazKiraak) |
Bug Bounty | 2017-07-18 | 2023-06-13 |