3714 | User Account Takeover via Signup Feature | Bug Bounty POC |
Account takeover
Logic flaw
Authorization flaw |
NA |
Muzammil Kayani (@muzammilabbas2) |
Bug Bounty | 2020-01-22 | 2023-06-13 |
3712 | Password Reset Token Leak Via Referrer |
Password reset
Information disclosure |
NA |
Shrey Shah (@ShreySh43332033) |
Bug Bounty | 2020-01-22 | 2023-06-13 |
3711 | A Less Known Attack Vector, Second Order IDOR Attacks |
IDOR |
NA |
Ozgur Alp (@ozgur_bbh) |
Bug Bounty | 2020-01-22 | 2023-06-13 |
3710 | CORS Misconfiguration leading to Private Information Disclosure |
CORS misconfiguration |
NA |
Virus0X01 (@Virus0X01) |
Bug Bounty | 2020-01-23 | 2023-06-13 |
3709 | How I was able to take over any users account with host header injection |
Host header injection |
NA |
Ajay Gautam (@evilboyajay) |
Bug Bounty | 2020-01-23 | 2023-06-13 |
3707 | The unexpected bounty: A story of Zendesk takeover on REDACTED.com |
Subdomain takeover |
NA |
wis4nggeni |
Bug Bounty | 2020-01-25 | 2023-06-13 |
3706 | Accidental IDOR that Deleted Admin Account. |
IDOR |
NA |
Sayaan Alam (@ehsayaan) |
Bug Bounty | 2020-01-25 | 2023-06-13 |
3701 | Escalating reflected XSS with HTTP Smuggling |
Reflected XSS
HTTP request smuggling |
NA |
Hazana (@HazanaSec) |
Bug Bounty | 2020-01-27 | 2023-06-13 |
3700 | Tale of a Misconfiguration in Password Reset |
Password reset
Information disclosure |
NA |
Naveenroy |
Bug Bounty | 2020-01-27 | 2023-06-13 |
3699 | Adding anyone including non-friend and blocked people as co-host in personal event! |
IDOR |
Meta / Facebook |
Binit Ghimire (@WHOISbinit) |
Bug Bounty | 2020-01-28 | 2023-06-13 |
3698 | Hyperlink Injection - Easy Money (sometimes) |
Hyperlink injection |
NA |
Abhishek Yadav (@abhishake100) |
Bug Bounty | 2020-01-28 | 2023-06-13 |
3696 | How I was able to takeover the company’s LinkedIn Page |
Broken link hijacking |
NA |
Vijaysimha Reddy Bathini (@fatratfatrat) |
Bug Bounty | 2020-01-29 | 2023-06-13 |
3695 | 2FA Bypass via Logical Rate Limiting Bypass |
MFA bypass
Logic flaw |
NA |
Jeppe Bonde Weikop |
Bug Bounty | 2020-01-30 | 2023-06-13 |
3691 | CSRF CSRF CSRF… |
CSRF |
NA |
Navneet (@na5n33t) |
Bug Bounty | 2020-02-03 | 2023-06-13 |
3690 | Easily leaking passenger information on an Airline |
IDOR |
NA |
Zseano (@zseano) |
Bug Bounty | 2020-02-04 | 2023-06-13 |
3689 | Exploiting Insecure Firebase Database! |
Insecure Firebase database
Android |
NA |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2020-02-04 | 2023-06-13 |
3686 | Arbitary File Upload too Stored XSS - Bug Bounty |
Arbitrary file upload
Stored XSS |
NA |
m0chan (@m0chan98) |
Bug Bounty | 2020-02-04 | 2023-06-13 |
3685 | How, I dumped crypto data by chaining directory listing to open S3 Bucket |
AWS misconfiguration
Directory listing
Information disclosure |
NA |
Ddigvijay |
Bug Bounty | 2020-02-05 | 2023-06-13 |
3683 | An Unexpected Bounty — Email Bounce Issues |
DoS
Email Bounce Issue |
NA |
Keshav Malik (@g0t_rOoT_) |
Bug Bounty | 2020-02-05 | 2023-06-13 |
3682 | Using CSRF I Got Weird Account Takeover |
CSRF
Account takeover |
NA |
Mohamed Sayed (@FlEx0Geek) |
Bug Bounty | 2020-02-05 | 2023-06-13 |
3681 | How I Made $600 in Bug Bounty in 15 Minutes with Contrast CE – CVE- 2019-8442 |
Information disclosure |
Atlassian |
David Lindner (@golfhackerdave) |
Bug Bounty | 2020-02-05 | 2023-06-13 |
3680 | Site wide CSRF on a popular program |
CSRF |
NA |
Ajinkya Pathare (@fellchase) |
Bug Bounty | 2020-02-05 | 2023-06-13 |
3678 | Simple Remote Code Execution Vulnerability Examples for Beginners |
RCE
Unrestricted file upload |
NA |
Ozgur Alp (@ozgur_bbh) |
Bug Bounty | 2020-02-05 | 2023-06-13 |
3676 | How Inspect Element Got me a Bounty |
Client-side enforcement of server-side security |
NA |
Aditya Soni (@hetroublemakr) |
Bug Bounty | 2020-02-06 | 2023-06-13 |
3675 | IDOR leads to Data leakage and Profile Update |
IDOR
Bruteforce |
NA |
vict0ni (@vict0ni) |
Bug Bounty | 2020-02-07 | 2023-06-13 |