3634 | SQL Injection Via Stopping the redirection to a login page |
SQL injection
Authorization flaw |
NA |
Abde Ouabala (@4mgh0z) |
Bug Bounty | 2020-03-03 | 2023-06-13 |
3633 | How I CSRF’d My First Bounty! |
CSRF |
NA |
Rajesh Ranjan (@rajesh_ranjan4) |
Bug Bounty | 2020-03-03 | 2023-06-13 |
3632 | ManageEngine ServiceDesk Plus: Arbitrary File Upload |
Arbitrary file upload
RCE |
NA |
Duc Anh Bui |
Bug Bounty | 2020-03-03 | 2023-06-13 |
3631 | Exploiting an SSRF: Trials and Tribulations |
SSRF |
NA |
A Bug’z Life (@abugzlife1) |
Bug Bounty | 2020-03-03 | 2023-06-13 |
3630 | SOP Bypass |
SOP bypass |
NA |
Kenan (@kenanistaken) |
Bug Bounty | 2020-03-03 | 2023-06-13 |
3629 | SSRF vulnerability in Uppy, Detected by Shieldfy |
SSRF |
Node.js third-party modules |
Eslam Salem (@net_code) |
Bug Bounty | 2020-03-03 | 2023-06-13 |
3627 | Got *Bounty* with Account takeover (ATO ) Unicode-Case Mapping Collision ! |
Account takeover |
NA |
Shaurya Sharma (@ShauryaSharma05) |
Bug Bounty | 2020-03-05 | 2023-06-13 |
3625 | How I exploit the JSON CSRF with method override technique |
CSRF |
NA |
Simgamsetti Manikanta (@zaheckmania) |
Bug Bounty | 2020-03-07 | 2023-06-13 |
3624 | Google Ads Self-XSS & Html Injection $5000 |
Self-XSS
HTML injection |
Google |
Syahri Ramadan (@adonkidz7) |
Bug Bounty | 2020-03-07 | 2023-06-13 |
3623 | $5,005 worth vulnerability Duplicated, How I loose $5,005 in a day? Denial of Service - Billion LAUGH Attack (XXE) |
DoS
XXE |
NA |
Muhammad Asim Shahzad (@protector47) |
Bug Bounty | 2020-03-08 | 2023-06-13 |
3622 | Breaking the Competition (Bug Bounty Write-up) |
Race condition
DoS
Logic flaw
Session management issue |
NA |
George O (@georgeomnet) |
Bug Bounty | 2020-03-08 | 2023-06-13 |
3620 | Broke limited scope with a chain of bugs (tips for every rider CORS) |
CORS misconfiguration
RCE |
NA |
Valeriy Shevchenko (@Krevetk0Valeriy) |
Bug Bounty | 2020-03-09 | 2023-06-13 |
3619 | Vulnerable design leads to personal data leakage- yet another case of an inter-application vulnerability… |
Logic flaw |
NA |
Marcin Szydlowski (@SecurityKsl) |
Bug Bounty | 2020-03-09 | 2023-06-13 |
3618 | Got Easiest Bounty with HTML injection via email confirmation! |
HTML injection |
NA |
Shaurya Sharma (@ShauryaSharma05) |
Bug Bounty | 2020-03-11 | 2023-06-13 |
3617 | Finding a P1 in one minute with Shodan.io (RCE) |
RCE |
NA |
sw33tLie (@sw33tLie) |
Bug Bounty | 2020-03-11 | 2023-06-13 |
3616 | OTP Bypass - Developer’s Check |
OTP bypass |
NA |
Shrey Shah (@ShreySh43332033) |
Bug Bounty | 2020-03-11 | 2023-06-13 |
3615 | How I was able to bypass the current password? |
Account takeover
CSRF |
NA |
Ninad Mathpati (@ninad_mathpati) |
Bug Bounty | 2020-03-11 | 2023-06-13 |
3611 | [Bug Bounty] Email Content Injection |
Email content injection |
NA |
Navneet (@na5n33t) |
Bug Bounty | 2020-03-12 | 2023-06-13 |
3610 | How I got access to critical data of a Company in no time ? |
Information disclosure
Lack of rate limiting
Bruteforce |
NA |
Kaustubh Kale |
Bug Bounty | 2020-03-12 | 2023-06-13 |
3608 | API secret key Leakage leads to disclosure of Employee’s Information |
Information disclosure |
NA |
Ace Candelario (@phspades) |
Bug Bounty | 2020-03-13 | 2023-06-13 |
3607 | User%27s email disclosure via invalid password reset link [$250] |
Password reset
Information disclosure |
NA |
Myo Min Thu (@myominthu1337) |
Bug Bounty | 2020-03-13 | 2023-06-13 |
3603 | How I earned $800 for Host Header Injection Vulnerability |
Host header injection
Password reset |
NA |
Pethuraj (@Pethuraj) |
Bug Bounty | 2020-03-15 | 2023-06-13 |
3602 | Using Vulnerability Analytics Feature Like a Boss |
SSRF
Reflected XSS
Authentication bypass |
NA |
Ozgur Alp (@ozgur_bbh) |
Bug Bounty | 2020-03-15 | 2023-06-13 |
3598 | How I was able to verify any contact number for my account? |
OTP bypass
MFA bypass |
NA |
Paras Arora (@parasarora06) |
Bug Bounty | 2020-03-17 | 2023-06-13 |
3595 | Hacking — Always Check the Cross-domain Policy |
SOP bypass
CSRF |
Starbucks |
Jack |
Bug Bounty | 2020-03-19 | 2023-06-13 |