bug-bounty622
facebook468
xss316
google162
microsoft106
rce105
apple69
csrf61
web354
account-takeover54
writeup51
exploit43
sqli41
cve37
ssrf35
dos33
cloudflare33
malware30
privilege-escalation29
defi28
smart-contract-vulnerability25
node24
idor24
subdomain-takeover24
smart-contract23
clickjacking23
ethereum23
access-control21
vulnerability-disclosure21
browser20
auth-bypass20
lfi19
aws19
remote-code-execution18
docker17
reverse-engineering17
react17
cloud17
oauth16
cors16
race-condition16
info-disclosure15
solidity14
authentication-bypass14
phishing13
supply-chain13
wordpress12
denial-of-service11
delegatecall11
sql-injection11
0
0
0
A researcher discovered a local file inclusion (LFI) vulnerability on Google's production servers at springboard.google.com through directory enumeration and authorization bypass, escalating from an initial auth bypass to full LFI with admin privileges, ultimately earning a $13,337 bounty from Google's Vulnerability Reward Program.
local-file-inclusion
lfi
authorization-bypass
authentication-bypass
directory-enumeration
bug-bounty
google-vrp
subdomain-enumeration
fuzzing
production-servers
google
springboard
privilege-escalation
web-security
vulnerability-disclosure
Omar Espino
omespino
Google
springboard.google.com
cloudsearch.google.com
Google VRP
wfuzz
domained
masscan
SecLists
ESCAL8
Intigriti
HackerOne
CVE-2024-1234
0
bug-bounty
0
0
0
security
0
vulnerability
0
vulnerability
0
vulnerability
0
vulnerability
0
vulnerability
0
vulnerability
0
vulnerability
0
vulnerability
0
vulnerability
0
vulnerability
0
vulnerability
0
0
vulnerability
0
vulnerability
0
vulnerability
0
vulnerability
0
vulnerability
0
vulnerability
0
0
vulnerability
0
vulnerability
0
vulnerability
0
vulnerability