3385 | How I managed to Escalate privilege as admin |
Lack of rate limiting
Bruteforce
Weak credentials |
NA |
Abisheik Magesh (@AbisheikMagesh) |
Bug Bounty | 2020-06-16 | 2023-06-13 |
3384 | How I made more than $30K with Jolokia CVEs |
Reflected XSS
RCE
Information disclosure |
NA |
Patrik Fehrenbach (@ITSecurityguard) |
Bug Bounty | 2020-06-16 | 2023-06-13 |
3382 | A subtle stored-XSS in WordPress core |
Stored XSS
RCE |
WordPress |
Sam Thomas (@_s_n_t) |
Bug Bounty | 2020-06-17 | 2023-06-13 |
3378 | From Recon to Bypassing MFA Implementation in OWA by Using EWS Misconfiguration |
Information disclosure
MFA bypass |
NA |
YoKo Kho (@YokoAcc) |
Bug Bounty | 2020-06-19 | 2023-06-13 |
3376 | How did i find information Disclosure on Facebook-Writeup |
Information disclosure |
Meta / Facebook |
Alaa Abdulridha (@Madrid89001310) |
Bug Bounty | 2020-06-20 | 2023-06-13 |
3375 | Bypass 2FA like a Boss |
Lack of rate limiting
Bruteforce |
NA |
Seqrity (@seQrity) |
Bug Bounty | 2020-06-20 | 2023-06-13 |
3372 | How i was able to chain bugs and gain access to internal okta instance |
Missing authentication |
NA |
Mmohammed Eldeeb (@malcolmx0x) |
Bug Bounty | 2020-06-22 | 2023-06-13 |
3371 | API Token Hijacking Through Clickjacking |
Clickjacking |
NA |
DarkLotus (@darklotuskdb) |
Bug Bounty | 2020-06-22 | 2023-06-13 |
3370 | Leveraging an SSRF to leak a secret API key |
SSRF |
NA |
Julien Cretel (@jub0bs) |
Bug Bounty | 2020-06-22 | 2023-06-13 |
3369 | A tale of my first ever full SSRF bug |
SSRF |
NA |
Jadek Mark (@mase289) |
Bug Bounty | 2020-06-22 | 2023-06-13 |
3367 | All About Getting First Bounty with IDOR |
IDOR |
NA |
Mukul Trivedi (@M0hn1sh) |
Bug Bounty | 2020-06-23 | 2023-06-13 |
3366 | Bug Bounty in Lockdown (SQLi and Business Logic) |
SQL injection
Logic flaw |
NA |
Abhishek Yadav (@abhishake100) |
Bug Bounty | 2020-06-24 | 2023-06-13 |
3361 | An attempt to escalate a low-impact hidden input XSS |
XSS |
NA |
Ayush Ojha (@officialaimm) |
Bug Bounty | 2020-06-28 | 2023-06-13 |
3360 | How I was able to take over any account via the Password Reset Functionality. |
Password reset
Account takeover |
NA |
Firas Fatnassi (@Fatnass1F1ras) |
Bug Bounty | 2020-06-28 | 2023-06-13 |
3359 | How I hacked a bank their application using it for hacking another bank company — 10K XSS |
XSS |
NA |
hg_real (@hgreal1) |
Bug Bounty | 2020-06-28 | 2023-06-13 |
3357 | API Endpoint leads to Account Takeover In Android Application |
Exposed token generation endpoint
Information disclosure |
NA |
Adesh Nandkishor kolte (@AdeshKolte) |
Bug Bounty | 2020-06-28 | 2023-06-13 |
3355 | Using Inspect Element to Bypass Security restrictions | Bug Bounty POC |
Client-side enforcement of server-side security |
NA |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2020-06-30 | 2023-06-13 |
3352 | Stored XSS with Password Recovery Page |
Stored XSS |
NA |
Lütfü Mert Ceylan (@lutfumertceylan) |
Bug Bounty | 2020-07-01 | 2023-06-13 |
3348 | Misconfigured S3 Bucket Access Controls to Critical Vulnerability |
AWS misconfiguration |
NA |
Harsh Bothra (@harshbothra_) |
Bug Bounty | 2020-07-02 | 2023-06-13 |
3347 | How I made $1500 dollars using base64 decoder :) |
Information disclosure |
NA |
Dilip (@dilip_spartn) |
Bug Bounty | 2020-07-02 | 2023-06-13 |
3344 | Price Tampering due to Improper checks on applying Coupon |
Payment tampering
Logic flaw |
NA |
Vaibhav Joshi (@vj0shii) |
Bug Bounty | 2020-07-03 | 2023-06-13 |
3343 | How i got 200$ with an out of the box open redirect vulnerability |
Open redirect
Token leak |
NA |
Tarek Galleze |
Bug Bounty | 2020-07-03 | 2023-06-13 |
3342 | Breaking Business Logic via Coupons — The Story of my 1st Valid Bug Bounty |
Payment tampering
Logic flaw |
NA |
Dominic Ifediri (@Edi4all) |
Bug Bounty | 2020-07-03 | 2023-06-13 |
3340 | Bug bounty write-up: From SSRF to $4000 |
SSRF
RCE |
NA |
thehackerish (@thehackerish) |
Bug Bounty | 2020-07-03 | 2023-06-13 |
3339 | CSRF Attack!!! |
CSRF |
NA |
Bala Praneeth (@Begin_hunt) |
Bug Bounty | 2020-07-04 | 2023-06-13 |