Worldwide Server-side Cache Poisoning on All Akamai Edge Nodes ($50K+ Bounty Earned) |
|
|
|
Airbnb : Steal Earning of Airbnb hosts by Adding Bank Account/Payment Method (IDOR) |
|
|
|
Account takeover on Airbnb acquisition | An Unusual Bug Part-2 🐛 |
|
|
|
OAuth authentication bypass on Airbnb acquisition using 1-char Open Redirect |
|
|
|
Authentication bypass on Airbnb via OAuth tokens theft |
|
|
|
Airbnb – Web to App Phone Notification IDOR to view Everyone’s Airbnb Messages |
|
|
|
Airbnb – Ruby on Rails String Interpolation led to Remote Code Execution |
|
|
|
Airbnb – Chaining Third-Party Open Redirect into Server-Side Request Forgery (SSRF) via LivePerson Chat |
|
|
|
Airbnb – When Bypassing JSON Encoding, XSS Filter, WAF, CSP, and Auditor turns into Eight Vulnerabilities |
|
|
|