3673 | External XML Entity via File Upload (SVG) |
XXE
Unrestricted file upload |
NA |
Atul (@atul_hax) |
Bug Bounty | 2020-02-08 | 2023-06-13 |
3672 | A step-by-step walk-through of an Invalid Endpoint |
Information disclosure |
NA |
Mohammed Israil (@mdisrail2468) |
Bug Bounty | 2020-02-09 | 2023-06-13 |
3671 | How I discovered an SSRF leading to AWS Metadata Leakage |
SSRF |
NA |
Amey Anekar (@ameyanekar) |
Bug Bounty | 2020-02-10 | 2023-06-13 |
3670 | Weird Vulnerabilities Happening on Load Balancers, Shallow Copies and Caches |
Information disclosure |
NA |
Ozgur Alp (@ozgur_bbh) |
Bug Bounty | 2020-02-11 | 2023-06-13 |
3669 | A Simple IDOR to Account Takeover |
IDOR
Account takeover |
NA |
Swapnil Maurya (@swapmaurya20) |
Bug Bounty | 2020-02-11 | 2023-06-13 |
3668 | CVE-2019-18426 - WhatsApp Vulnerabilities Disclosure - Open Redirect + CSP Bypass + Persistent XSS + FS read permissions + potential for RCE |
RCE
Stored XSS
CSP bypass
Arbitrary file read
Open redirect
Security code review |
Meta / Facebook (WhatsApp) |
Gal Weizman (@WeizmanGal) |
Bug Bounty | 2020-02-14 | 2023-06-13 |
3666 | Open-redirect Vulnerability on Facebook |
Open redirect |
Meta / Facebook |
dw1 |
Bug Bounty | 2020-02-16 | 2023-06-13 |
3664 | Uploading Backdoor For Fun And Profit. |
Unrestricted file upload
RCE |
NA |
Mohammed Abdul Raheem (@mohdaltaf163) |
Bug Bounty | 2020-02-17 | 2023-06-13 |
3663 | How I Gain Unrestricted File Upload Remote Code Execution Bug Bounty |
Unrestricted file upload |
NA |
Shay Grant (@kidshay) |
Bug Bounty | 2020-02-17 | 2023-06-13 |
3662 | Exploiting WebSocket [Application Wide XSS / CSRF] |
XSS
CSRF |
NA |
Osama Avvan (@osamaavvan) |
Bug Bounty | 2020-02-17 | 2023-06-13 |
3659 | My First Bounty From Google. |
Self-XSS
HTML injection |
Google |
Syahri Ramadan (@adonkidz7) |
Bug Bounty | 2020-02-18 | 2023-06-13 |
3658 | From Recon to Optimizing RCE Results – Simple Story with One of the Biggest ICT Company in the World |
Information disclosure
RCE |
NA |
YoKo Kho (@YokoAcc) |
Bug Bounty | 2020-02-18 | 2023-06-13 |
3657 | A Tale of Two Formats: Exploiting Insecure XML and ZIP File Parsers to Create a Web Shell |
XXE
RCE
Directory Traversal |
NA |
Eugene Lim (@spaceraccoonsec) |
Bug Bounty | 2020-02-18 | 2023-06-13 |
3656 | Hacking SMS API Service Provider of a Company |Android App Static Security Analysis | Bug Bounty POC |
Information disclosure
Hardcoded credentials |
NA |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2020-02-19 | 2023-06-13 |
3653 | Tale of Account Takeovers (Part-1) |
Account takeover
HTTP parameter pollution
Password reset
OTP bypass |
NA |
Vijaysimha Reddy Bathini (@fatratfatrat) |
Bug Bounty | 2020-02-22 | 2023-06-13 |
3649 | Stored-XSS-on-groups-google-com |
Stored XSS |
Google |
Alessandro Rumampuk (@Rando02355205) |
Bug Bounty | 2020-02-25 | 2023-06-13 |
3647 | How i found 3 SSRF in one day on different bug bounty targets |
SSRF |
NA |
- |
Bug Bounty | 2020-02-25 | 2023-06-13 |
3646 | How I Get my first P1 (Sensitive Information Disclosure) using WPScan |
Information disclosure |
NA |
Harrmahar (@harrmahar) |
Bug Bounty | 2020-02-26 | 2023-06-13 |
3645 | Long String DoS |
DoS |
NA |
Shrey Shah (@ShreySh43332033) |
Bug Bounty | 2020-02-26 | 2023-06-13 |
3644 | Write-up: AWS Document Signing Security Control Bypass |
AWS misconfiguration |
NA |
Ozgur Alp (@ozgur_bbh) |
Bug Bounty | 2020-02-26 | 2023-06-13 |
3643 | RCE via Apache Struts2 - Still out there. |
RCE |
NA |
Abhishek (@abhishake100) |
Bug Bounty | 2020-02-27 | 2023-06-13 |
3641 | The Tricky XSS |
XSS |
NA |
Smaran Chand (@smaranchand) |
Bug Bounty | 2020-02-28 | 2023-06-13 |
3639 | Account Hijack using Authorization bypass $$$$ |
Account takeover
Authorization flaw |
NA |
Bhavesh Thakur (@Bhavesh_Thakur_) |
Bug Bounty | 2020-02-28 | 2023-06-13 |
3638 | A mysterious bug in the firmware of Google%27s Titan M chip (CVE-2019-9465) |
Cryptographic issues |
Google |
Alexander Bakker |
Bug Bounty | 2020-02-29 | 2023-06-13 |
3635 | SSRF on PDF generator. |
SSRF |
NA |
John Michael (@michan2514) |
Bug Bounty | 2020-03-02 | 2023-06-13 |