5026 | Self XSS to Good XSS Clickjacking |
XSS
Clickjacking |
NA |
Arbaz Hussain (@ArbazKiraak) |
Bug Bounty | 2017-07-20 | 2023-06-13 |
5003 | Password Not Provided - Compromising Any Flurry User%27s Account [Yahoo Bug Bounty] |
Authentication flaw
Account takeover |
Yahoo! / Verizon Media |
Jack Cable (@jackhcable) |
Bug Bounty | 2017-08-15 | 2023-06-13 |
4981 | Chaining Self XSS with UI Redressing is Leading to Session Hijacking (PWN users like a boss) |
Self-XSS
Clickjacking |
NA |
Armaan Pathan (@armaancrockroax) |
Bug Bounty | 2017-09-18 | 2023-06-13 |
4943 | Get your Microsoft account hijacked by simply clicking connect button -Adesh Kolte |
Stored XSS |
Microsoft |
Adesh Nandkishor kolte (@AdeshKolte) |
Bug Bounty | 2017-11-06 | 2023-06-13 |
4914 | Don%27t Trust the Host Header for Sending Password Reset Emails |
Password reset
Account takeover |
Mavenlink |
Jack Cable (@jackhcable) |
Bug Bounty | 2017-12-13 | 2023-06-13 |
4845 | Re-dressing Instagram – Leaking Application Tokens via Instagram ClickJacking Vulnerability! |
Clickjacking |
Meta / Facebook |
Mohamed A. Baset |
Bug Bounty | 2018-02-25 | 2023-06-13 |
4840 | Clickjackings in Google worth 12644.7$ |
Clickjacking |
Google |
Raushan Raj (@raushan_rajj) |
Bug Bounty | 2018-03-06 | 2023-06-13 |
4807 | Hijacking User’s Private Information access_token from Microsoft Office360 facebook App |
Logic flaw |
Microsoft |
Mohamed A. Baset |
Bug Bounty | 2018-04-13 | 2023-06-13 |
4744 | How I Earned $750 Bounty Reward From AT&T bug Bounty -Adesh Kolte |
RCE
Clickjacking
XSS
Same Origin Method Execution |
AT&T |
Adesh Nandkishor kolte (@AdeshKolte) |
Bug Bounty | 2018-06-01 | 2023-06-13 |
4733 | Steam, Fire, and Paste – A Story of UXSS via DOM-XSS & Clickjacking in Steam Inventory Helper |
DOM XSS
Universal XSS
Clickjacking
Browser extension hacking |
NA |
Matthew Bryant (@IAmMandatory) |
Bug Bounty | 2018-06-08 | 2023-06-13 |
4704 | The $12,000 Intersection between Clickjacking, XSS, and Denial of Service |
Clickjacking
XSS
DoS |
Bustabit |
Sam Curry (@samwcyo) |
Bug Bounty | 2018-07-04 | 2023-06-13 |
4680 | Unclaimed Medium Publication takeover in WeTransfer |
Medium publication takeover
Broken link hijacking |
WeTransfer |
Prial Islam Khan (@prial261) |
Bug Bounty | 2018-07-21 | 2023-06-13 |
4672 | Binary.com ClickJacking Vulnerability — Exploiting HTML5 Security Features |
Clickjacking |
Binary.com |
Ameer Assadi (@AmeerAssadi) |
Bug Bounty | 2018-07-28 | 2023-06-13 |
4589 | Reflected DOM XSS and CLICKJACKING on https://silvergoldbull.de/bt.html |
DOM XSS
Clickjacking |
Silver Gold Bull |
Daniel Maksimovic |
Bug Bounty | 2018-09-13 | 2023-06-13 |
4586 | How I hijacked your account when you opened my cat picture |
Logout CSRF |
NA |
Matti Bijnens (@MattiBijnens) |
Bug Bounty | 2018-09-14 | 2023-06-13 |
4547 | Clickjacking in Google Docs and Voice typing feature. |
Clickjacking |
Google |
Raushan Raj (@raushan_rajj) |
Bug Bounty | 2018-10-05 | 2023-06-13 |
4507 | Improper CSRF token handling leads to site-wide CSRF issue, chained with clickjacking = woot! Multiple sites vulnerable |
CSRF
Clickjacking |
NA |
Zseano (@zseano) |
Bug Bounty | 2018-10-29 | 2023-06-13 |
4484 | Clickjacking on Google MyAccount Worth 7,500$ |
Clickjacking |
Google |
apapedulimu / Nosa Shandy (@LocalHost31337) |
Bug Bounty | 2018-11-11 | 2023-06-13 |
4482 | Chain exploitation of XSS |
DOM XSS
Clickjacking
CSRF |
NA |
Mikhail Klyuchnikov (@__Mn1__) |
Bug Bounty | 2018-11-12 | 2023-06-13 |
4440 | Remotely Hijacking Zoom Clients |
Logic flaw |
Zoom |
David Wells |
Bug Bounty | 2018-12-03 | 2023-06-13 |
4439 | [BBP系列三] Hijack the JS File of Uber%27s Website |
JS file hijacking |
Uber |
Chaobin Zhang |
Bug Bounty | 2018-12-03 | 2023-06-13 |
4398 | How I accidentally found a clickjacking “feature” in Facebook |
Clickjacking |
Meta / Facebook |
Lasq (@lasq88) |
Bug Bounty | 2018-12-21 | 2023-06-13 |
4372 | When Cookie Hijacking + HTML Injection become dangerous |
Cookie hijacking
HTML injection |
NA |
Daniel V. (@d4niel_v) |
Bug Bounty | 2019-01-07 | 2023-06-13 |
4359 | Oauth Misconfiguration lead to complete account takeover |
CSRF
OAuth
Account takeover |
NA |
Jackson kv (@Jacksonkv22) |
Bug Bounty | 2019-01-20 | 2023-06-13 |
4335 | Hijacking accounts by retrieving JWT tokens via unvalidated redirects |
Open redirect
Token leak |
NA |
Shawar Khan (@ShawarkOFFICIAL) |
Bug Bounty | 2019-01-27 | 2023-06-13 |