3409 | Cmd Hijack - a command/argument confusion with path traversal in cmd.exe |
OS command injection
Path traversal |
Microsoft |
Julian Horoszkiewicz |
Bug Bounty | 2020-06-10 | 2023-06-13 |
3371 | API Token Hijacking Through Clickjacking |
Clickjacking |
NA |
DarkLotus (@darklotuskdb) |
Bug Bounty | 2020-06-22 | 2023-06-13 |
3245 | Apache Example Servlet leads to $$$$ |
Clickjacking |
NA |
Debangshu Kundu (@debangshu_kundu) |
Bug Bounty | 2020-08-06 | 2023-06-13 |
3148 | You can’t stop me. MS Teams session hijacking and bypass |
Insecure storage of sensitive information |
Microsoft |
Bandit Pingu (@FlyingPhishy) |
Bug Bounty | 2020-09-20 | 2023-06-13 |
3130 | P1: Critical - Discovering and Foiling a Threat Actor |
Information disclosure |
NA |
Jackson Henry (@JacksonHHax) |
Bug Bounty | 2020-09-27 | 2023-06-13 |
3070 | Manual broken link monitoring |
Broken link hijacking |
NA |
GrumpinouT (@RVerwilghen) |
Bug Bounty | 2020-10-29 | 2023-06-13 |
2993 | Hacking — Always check out the Images |
Information disclosure |
GitLab |
Jack |
Bug Bounty | 2020-12-02 | 2023-06-13 |
2977 | Hacking — Tamper with the URL Parameters, especially if they modify the page |
HTTP parameter pollution |
NA |
Jack |
Bug Bounty | 2020-12-09 | 2023-06-13 |
2943 | [Google VRP] Hijacking Google Docs Screenshots |
postMessage
XSS |
Google |
Sreeram KL (@kl_sree) |
Bug Bounty | 2020-12-27 | 2023-06-13 |
2908 | UNEP Breached, 100K+ Employee Records Accessed |
Information disclosure |
United Nations |
Jackson Henry (@JacksonHHax) |
Bug Bounty | 2021-01-11 | 2023-06-13 |
2895 | How I hijacked the top-level domain of a sovereign state |
Domain takeover |
Internet Bug Bounty |
Fredrik N. Almroth (@Almroot) |
Bug Bounty | 2021-01-15 | 2023-06-13 |
2863 | Hijacking Google Drive Files (Documents, Photo & Video) Through Google Docs Sharing |
Clickjacking |
Google |
santuySec (@santuySec) |
Bug Bounty | 2021-01-27 | 2023-06-13 |
2814 | OAuth Misconfiguration Leads to Full Account takeover |
OAuth
Clickjacking
CSRF
Account takeover |
NA |
Yasser Mohammed (@boomneroli) |
Bug Bounty | 2021-02-13 | 2023-06-13 |
2773 | CVE-2021-23827: Sakura Samurai discover cleartext pictures in Keybase Desktop Client; Windows, macOS, Linux |
Unencrypted storage |
Keybase |
John Jackson (@johnjhacking) |
Bug Bounty | 2021-02-22 | 2023-06-13 |
2770 | Hijacking Reset Password Link in https://www.niteflirt.com/ via Host Header Poising (Write Up) |
Host header injection
Account takeover
Password reset |
Niteflirt |
Evan Ricafort (@evanricafort) |
Bug Bounty | 2021-02-25 | 2023-06-13 |
2726 | Chain of Low Level Bugs and Misconfigurations Leads to Account Takeover |
Reflected XSS
Clickjacking
Account takeover |
NA |
pleorqy (@pleorqy) |
Bug Bounty | 2021-03-10 | 2023-06-13 |
2673 | Play a game, get Subscribed to my channel - YouTube Clickjacking Bug | #GoogleVRP |
Clickjacking |
Google |
Sriram Kesavan (@sriramoffcl) |
Bug Bounty | 2021-04-02 | 2023-06-13 |
2551 | How i hijacked 12 Subdomains in one Program |
Subdomain takeover |
NA |
Naveen kumawat (@nvk0x) |
Bug Bounty | 2021-05-17 | 2023-06-13 |
2549 | Clickjacking in Nearby Devices Dashboard |
Clickjacking |
Google |
David Schütz (@xdavidhu) |
Bug Bounty | 2021-05-17 | 2023-06-13 |
2422 | Whose app are you downloading? Link hijacking Binance’s shortlinks through AppsFlyer |
Broken link hijacking |
Chess.com |
Sam Curry (@samwcyo) |
Bug Bounty | 2021-07-10 | 2023-06-13 |
2406 | Logical Flaw Resulting Path Hijacking |
Namespace attack |
NA |
Veshraj Ghimire (@GhimireVeshraj) |
Bug Bounty | 2021-07-16 | 2023-06-13 |
2351 | Detecting Jackson deserialization vulnerabilities with CodeQL |
Insecure deserialization |
GitHub |
Artem Smotrakov (@artem_smotrakov) |
Bug Bounty | 2021-08-02 | 2023-06-13 |
2335 | Multiple Vulnerabilities In cPanel/WHM |
XXE
Stored XSS
Privilege escalation
CSRF
Cross-Site WebSocket Hijacking (CSWH) |
cPanel |
Adrian Tiron (@adrian__t) |
Bug Bounty | 2021-08-10 | 2023-06-13 |
2322 | Second Order Subdomain Takeovers – They DO Exist! |
Subdomain takeover
Broken link hijacking |
Microsoft |
Alun Jones (@ftp_alun) |
Bug Bounty | 2021-08-15 | 2023-06-13 |
2292 | Websocket Hijacking’ to steal Session_ID of victim users |
Cross-Site WebSocket Hijacking (CSWH) |
NA |
Sunil Yedla (@sunilyedla2) |
Bug Bounty | 2021-08-25 | 2023-06-13 |