bug-bounty625
facebook443
xss316
google119
rce106
microsoft66
csrf60
web355
account-takeover55
writeup50
malware43
sqli41
apple41
exploit40
ssrf35
cve34
privilege-escalation34
dos34
cloudflare29
defi28
phishing25
smart-contract-vulnerability25
access-control25
ethereum24
smart-contract24
clickjacking24
idor24
subdomain-takeover24
vulnerability-disclosure23
remote-code-execution21
auth-bypass19
lfi18
race-condition16
cloud15
authentication-bypass15
cors15
solidity15
node15
aws14
reverse-engineering13
oauth13
web-security12
sql-injection12
supply-chain12
denial-of-service11
info-disclosure11
browser11
delegatecall11
web-application-security11
vulnerability10
0
0
0
vulnerability
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
vulnerability
0
0
0
6/10
A security researcher discovered a rate-limiting vulnerability in Microsoft's password reset flow that could be exploited via concurrent requests to brute-force 7-digit security codes, bypassing encryption and rate limits to enable account takeover even on accounts with 2FA enabled. Microsoft patched the vulnerability and awarded a $50,000 bounty.
account-takeover
password-reset
rate-limiting-bypass
concurrent-requests
mfa-bypass
encryption-bypass
brute-force
microsoft
bug-bounty
authentication
Laxman Muthiyah
Microsoft
MSRC
HackerOne
Instagram
0
vulnerability
Article discussing two remote code execution vulnerabilities in Microsoft SharePoint. The content appears to be a blog index or archive page listing various security research posts by the author.
Soroush Dalili
SharePoint
0
0
security
0
vulnerability
0
0
vulnerability
0
vulnerability
CVE-2017-8514