Skip to main

Acknowledgment of those who have helped us to secure Bosch Websites.

Websites Hall of Fame

Bosch PSIRT Hall of Fame Policy

Researchers who report vulnerabilities in Bosch products and websites, after proper validation of their finding, can choose to appear in the Bosch PSIRT Hall of Fame.

Information that can be displayed in the Hall of Fame:

  • Complete name
  • Alias or nickname
  • Link to personal social media page (e.g. Twitter, Facebook)
  • Link to personal professional social media page (e.g. LinkedIn, Xing)
  • Link to business social media page (e.g. Facebook, Twitter, LinkedIn, Xing)
  • Link to hacker’s communities sites (e.g. Bugcrowd)

Information that cannot be displayed in the Hall of Fame:

  • Links to personal websites
  • Links to company’s website
  • Links to any site with unknown terms and conditions or content moderation
  • E-mail addresses
  • Messaging services (e.g. Whatsapp, Telegram)

Please note that researchers can request to be removed from the Hall of Fame at any time. For this, they should send an email to PSIRT@bosch.com with the subject “Request of removal from HoF.”

Hall of Fame Bosch Websites

2023

yning12 (yning12)

Reflected Cross-Site Scripting

Chirag Saini (Chirag Saini)

Improper Authentication

Miguel Segovia Gil (Miguel Segovia Gil)

Cross-Site Scripting

Ahmad Alassaf (Ahmad Alassaf)

Improper Access Control

Bugoverflow (bugoverflow)

Improper Authentication

Arjith N R (Arjith N R)

Cross-Site Scripting

Muhammad Imran (Muhammad Imran)

Insufficiently Protected Credentials and Sensitive Data Exposure

Kasper Kyllönen

Subdomain Takeover

Ramkrishna Sawant (Ramkrishna Sawant)

Information Disclosure

Chirag Ketan Prajapati (Chirag Ketan Prajapati)

2x Cross-Site Scripting

Dawid Cieśla (Dawid Cieśla)

Cross-Site Scripting

Blakduk (Blakduk)

Information Disclosure

Rokkam Vamshi (Rokkam Vamshi)

3x Cross-Site Scripting

Suprit Sudheendra Pandurangi (Suprit Sudheendra Pandurangi)

Cross-Site Scripting

Naveen Kumar M (Naveen Kumar M,@naveensparks1)

Cross-Site Scripting

Vaibhav Kumar Srivastava (Vaibhav Kumar Srivastava)

Cross-Site Scripting

Yaswanth Sai Boligarla (Yaswanth Sai Boligarla)

Open Redirect

Patrick Lang (Patrick Lang)

Sensitive Data Exposure

Dinesh Kumar (Dinesh Kumar)

File Inclusion

Ahmed Salah Abdalhfaz (@Elsfa7110)

4x Cross-Site Scripting

Information Disclosure

4x Open Redirect

Rtwo Gatelie (@secrtwoa)

Cross-Site Scripting

Mallampati Sai Sashank (Mallampati Sai Sashank)

Unverified Password Change

VEYSEL (VEYSEL)

Subdomain Takeover

Ranjeet Jaiswal (Ranjeet Jaiswal)

Cross-Site Scripting

Krishna Agarwal (Kr1shna4garwal)

Expired SSL Certificate (Misconfiguration)

Deepak Kumar (@bug_vs_me)

Exposure of Sensitive Information to an Unauthorized Actor

Ori Levi (Ori Levi)

Subdomain Takeover

Yash kushwah (@cyberyash951)

Server-Side Injection (Parameter Pollution)

Ahmed Hassan (Ahmed Hassan)

Remote Code Execution

Josef Hassan (Josef Hassan)

Remote Code Execution

Rene Rehme (Rene Rehme)

Server Misconfiguration

Jaswanth132 (Jaswanth132)

Cross-Site Scripting

Corrie Sloot (Corrie Sloot)

Subdomain Takeover

2022

Courte66

Exposure of Sensitive Information to an Unauthorized Actor

Wouter de Droog (Wouter de Droog)

Subdomain Takeover

Yavuz Özdemir (Yavuz Özdemir, cybersec_art)

Cross-Site Scripting

Rene Rehme (@renereh1)

CWE-79: Improper Neutralization of Input During Web Page Generation

Satyam Singh (Satyam Singh)

Improperly Controlled Modification of Object Prototype Attributes

J. Francisco Bolivar (jfbolivar)

Insufficiently Protected Credentials

Keyur Maheta (Keyur Maheta)

4x Server Security Misconfiguration

Vulnerable and Outdated Components

Mahesh Raj (Mahesh Raj)

Sensitive Data Exposure

Sven Grossmann (Sven Grossmann, @svennergr)

Sensitive Data Exposure

Ahmed Salah Abdalhfaz (Elsfa7110)

2x Authentication Bypass

2x Sensitive Data Exposure

3x Cross-Site Scripting

Ishika Sharma (Chmodx1sh, @chmodx1sh)

Cross-Site Scripting

2x Open Redirect

Shreyash Khare (Shreyash Khare)

Vulnerable and Outdated Components

Mohit Kumar (Mohit Kumar)

Cross-Site Scripting

Krishna Agarwal (kr1shna4garwal)

Application-Level Denial-of-Service (DoS)

Ramansh Sharma (Ramansh Sharma)

Vulnerable and Outdated Components

Mustafa Jamal (Mustafa Jamal)

2x Server Security Misconfiguration

Kanhaiya Sharma (Kanhaiya Sharma)

Email Html Injection

Broken Authentication

Server-Side Request Forgery (SSRF)

Weak Password Requirements

Ahmed Hassan (Ahmed Hassan)

Clickjacking

Ritik Jangra (Ritik Jangra)

Improper Restriction of Excessive Authentication Attempts

Madhurendra Kumar (Madhurendra Kumar)

Full Path Disclosure

Gaurang Maheta (Gaurang Maheta)

Unauthorized Access to Services (API/ Endpoints)

VEYSEL (VEYSEL)

Server Security Misconfiguration

Haris Ahmed (@HarisAhmed95)

Clickjacking

Kunal Narsale (Kunal Narsale)

6x Clickjacking

Junting Zhu (@testert1ng)

Cross-Site Scripting

Saeed Kamranfar (Saeed Kamranfar)

Server-Side Request Forgery (SSRF)

Gaurish Kauthankar (Gaurish Kauthankar)

Sensitive Data Exposure

Max Raams (max-raams)

Path Traversal

Abhith Damodaran (Abhith Damodaran)

Content Injection

Shahid Ahmed (@ehsahid)

2x Sensitive Data Exposure

2021

Mohammed Fadhl Al-Barbari (@m4dm0e)

2x Sensitive Data Exposure

Ismail Tasdelen (Ismail Tasdelen)

5x Sensitive Data Exposure

Kunal Narsale

Sensitive Data Exposure

Harinder Singh (S1N6H) (Harinder S.)

Sensitive Data Exposure

Saeed Jaber Abugosh (@Saeedjabercyber)

Sensitive Data Exposure

Kanhaiya Sharma (Kanhaiya Sharma)

Sensitive Data Exposure

Abilash.V.L (Abilash.V.L)

Content Injection

Damodar Naik (Damodar alias Omkar Naik)

Account Takeover

ahmed Alassaf (ahmed Alassaf )

Broken access control

Gaurish Kauthankar (Gaurish Kauthankar)

2x Sensitive Data Exposure

Milan Katwal (Milan Katwal)

Account hickjack

Akshay Khilari (Akshay Khilari)

Sensitive Data Exposure

Junting Zhu (@testert1ng)

Broken link hijack

Sensitive Data Exposure

XSS

chmodx1sh (@chmodx1sh)

Broken Authentication

Chau Minh Khanh (@khanhchauminh) (Khanh Chau Minh)

Sensitive Data Exposure

Patrick Lang (Patrick Lang)

18x XSS

VIPIN K R (vipinvkr18 VIPIN K R)

Sensitive Data Exposure

Jebarson Immanuel (Jebarson Immanuel)

Sensitive Data Exposure

Akshay Ravi - copycat (Akshay Ravi)

Sensitive Data Exposure

Abdelrahman Khaled (Abdelrahman Khaled )

Remote Code Execution

Mohammed Adam (Mohammed Adam, @iam_amdadam)

Sensitive Data Exposure

SebastianP

Improper Access Control

Madamshetty Srinivas (Madamshetty Srinivas)

Improper Input Validation

Sina Kheirkhah (Sina Kheirkhah @Sin_Khe)

2x Sensitive Data Exposure

Veysel Oezer

XSS

Kanhaiya_sh (@Kanhaiya_sh4rma Kanhaiya Sharma)

Cache-Control for a Sensitive Page

Unprotected Transport of Credentials

Missing Rate Limit

Gaurang Maheta (Gaurang Maheta)

2x Sensitive Data Exposure

Oussama Kasmi (Oussama Kasmi)

XSS

N7 (@n7_sec)

XSS

Cankat Çakmak (Twitter Profile)

2x Sensitive Data Exposure

Subodh Kumar (SUBODH)

3x Sensitive Data Exposure

Thilo Mohri (Thilo Mohri)

6x Subdomain Takeover

Abhiraj Krishnan (@KrishnanAbhiraj, LinkedIn Profile)

2x Sensitive Data Exposure

Sensitive Data Exposure

shubhack319 (@shubhack319)

SQL Injection

abdilahrf @ Vantage Point Indonesia (@abdilahrf)

XSS

Path Traversal

Aditra Andri Laksana (Wayc0de)

Sensitive Data Exposure

Shahid Ahme (Shahid Ahme)

Improper Authentication

crazy_as_hell (crazy_as_hell)

Unprotected Transport of Credentials

Sensitive Data Exposure

Atul Sanjay Hadgal (Atul Hadgal)

SSRF

courte66 e4366eolywrgpidfbio (@Twitter_e4366eolywrgpidfbio)

2x Sensitive Data Exposure

3x XSS

2020

Gokul Raju

Weak Credentials

MustafaSky

Insufficient Anti-Automation

Thilo Mohri (Thilo Mohri)

2x Subdomain Takeover

Patrick Lang (Patrick Lang)

14x Sensitive Information Exposure

Denial of Service

3x XSS

Remote Code Execution

SQL injection

Vikas Srivastava, INDIA (@007vikaxh)

Sensitive Information Exposure

Tolgahan Demirayak (Tolgahan Demirayak)

Sensitive Information Exposure

Pam_sec

2x Sensitive Information Exposure

Mohammed Fadhl Al-Barbari (@m4dm0e)

Sensitive Information Exposure

Reflected XSS

SQL injection

courte66 e4366eolywrgpidfbio (@Twitter_e4366eolywrgpidfbio)

3x Sensitive Information Exposure

Remote Code Execution

Server Missconfiguration

Aravind Valugonda

Improper Access Control

Abhiraj Krishnan (@KrishnanAbhiraj, LinkedIn Profile)

Denial-of-Service (DoS)

3x Broken Link Hijacking

2x Sensitive Information Exposure

Arbitrary file upload

Tushar Balu Shinde (Tushar Shinde)

Clear Text Password Submission

Junting Zhu (@testert1ng)

6x Reflected XSS

2x Reflected XSS

2x Subdomain Takeover

Insecure Direct Object References (IDOR)

Application-wide CSRF

Open Redirect

Akash H.C (Akash H.C)

Sensitive Information Exposure

Hamid Rezaei @ ZharfPouyan Toos (Xer0Days)

Observable Response Discrepancy

Improper Authentication

2x Insecure Direct Object Reference

Sensitive Information Exposure

Ismail Tasdelen (Ismail Tasdelen)

Improper Authentication

Reflected XSS

Unauthorized Access to Services (API/ Endpoints)

Sensitive Information Exposure

Husain Murabbi (@husain-murabbi-cyberhumans) Mansoor Rangwala (@mansoor-rangwala-cyberhumans)

Subdomain Takeover

Srikar V (@exp1o1t9r)

Sensitive Information Exposure

MelarDev (@melardev)

Subdomain Takeover

Lu William Hanugra @ Vantage Point Indonesia (hanugra)

2x Server Side injection

Diwakar Kumar (Diwakar Kumar)

Insufficient Anti-Automation

Steve Nyan Lin (Steve Nyan Lin)

SQL injection

Mariano Carrasco (@8marianoD)

Open Redirect

Robbie Wiggins (@Random_Robbie)

Remote Code Execution

Yunus YILDIRIM (@Th3Gundy)

Remote Code Execution

delta0ne @ Vantage Point Singapore (delta0ne)

6x Reflected XSS

Remote Code Execution

Improper Authentication

SQL injection

Improper Authorization

Priyanshu Parihar ( @priyanshu_xo )

3 x Subdomain Takeover

pop404 Vantage Point Singapore (pop404)

Sensitive Information Exposure

Kirtikumar Anandrao Ramchandani (Kirtikumar Anandrao Ramchandani)

Uncontrolled Resource Consumption

abdilahrf @ Vantage Point Indonesia (@abdilahrf)

Open Redirect Vulnerability

Reflected XSS

2x Sensitive Information Exposure

CSRF / Account Takeover

ashlyn @ Vantage Point Singapore (Ashlyn Lau)

Sensitive Information Exposure

External SSRF

Geethu Sivakumar, PaceHitech (Geethu Sivakumar, Geethu Sivakumar)

Server Missconfiguration

Muhammad Talha - Hamza Asif - Sarim Jamil - Syed Maaz Anwer

Text Injection

Jeffrey Hoekema (Jeffrey Hoekema)

3x Reflected XSS

Wasim Shaikh (@Wa_sim_sim)

Sensitive Information Exposure

Aishwarya Sanjay Kendle (Aishwarya Kendle)

Subdomain Takeover

Patrick Davidson Tremblay (Patrick Davidson Tremblay)

Cleartext Transmission of sensitive information

Chi Tran (Chi Tran)

9x Remote Code Execution

3x Proxy bypass

Nathan Lee Grant (nathanleegrant)

2x Reflected XSS

XSSi Vulnerability

2x SQL injection

Blind SQL injection

Anh_thanh_nien - Security Researcher at VNPT ISC

Remote Code Execution

Aditya Shende (@ADITYASHENDE17)

Sensitive Information Exposure

Hoang Quoc Thinh (@g4mm4 of CyberJutsu.IO)

Web cache poisoning

SQL injection

Remote Code Execution

Sourajeet Majumder (@sourajeet__)

Server Missconfiguration

Rahul M (Rahul M)

Insufficient Anti-Automation

Aziz Hakim

Stored XSS

Vishnuraj K V (Vishnuraj KV)

2x Information Exposure

Pankaj Kumar Thakur

Reflected XSS

Severus (Severus)

Sensitive Information Exposure

Sadir Mehdi

Information Exposure

Nitish Shah (@IamNitishShah)

Unauthorized Access to Services (API/ Endpoints)

Alex Chepovetsky (Alex Chepovetsky)

Reflected XSS

Sourav Newatia (Sourav Newatia)

Broken Authentication and Session Management

Shoeb Patel (@0xCaptainFreak)

Server Side Injection

Remote Code Execution

Shubham Maheshwari (Shubham Maheshwari)

2x Reflected XSS

SQL injection

2018

Aamir Usman Khan

Server Misconfiguration

Tijo Davis (Tijo Davis)

Clickjacking

Alberto Perez Agudo

SQL Injection

Niraj Gautam (Niraj Gautam)

Information Exposure

Pyae Phyoe Thu (Pyae Phyoe Thu)

Reflected XSS

Hein Thant Zin

Stored XSS

दानिश इनामदार (दानिश इनामदार)

Clickjacking

Aman Bhardwaj (Aman Bhardwaj)

Error Message Information Disclosure

Dan Niño I. Fabro

CSRF

Stored XSS

2 X Clickjacking

Mohammed Azharuddin (Mohammed Azharuddin)

Text Injection

Prathamesh Joshi (Prathamesh Joshi)

Information Disclosure Vulnerability

Artur Kiefel

XSS in Cookie

Murtada Kamil (Murtada Kamil)

Information Exposure

Salman Sajid Khan

Information Exposure

Clickjacking

Nikhil Sahoo (Nikhil Sahoo)

4 x Clickjacking

Chinthala Srinivas (Chinthala Srinivas)

Host Header Attack

Information Exposure

Rajatkumar Karmarkar (Rajatkumar Karmarkar)

Content Injection

Ashish Gautam Kamble

Reflected XSS

Abhishek Misal (Abhishek Misal)

Host Header Attack

Clickjacking

Subodh Kumar

HSTS

Youssef A. Mohamed

DOS

Prayas Roshan Biswal (Prayas Roshan Biswal)

Information Exposure Through Error Message

Shiram Datar (Shiram Datar)

Information Exposure

Abhishek Tiwari (Abhishek Tiwari)

2 x Clickjacking

Raghav Rao

Information Exposure

Dzianis Skliar (Dzianis Skliar)

3 x Information Exposure

Information Exposure Through Error Message

Shubham Deshpande (Shubham Deshpande)

Reflected XSS

Dipen Patel (Dipen Patel)

Stored XSS

Ashish Chhatani

Clickjacking

Kunal Bahl (@Kunal Bahl)

HTML Injection

Arjun Singh

Reflected XSS

B.Dhiyaneshwaran (B.Dhiyaneshwaran)

Improper Control of Interaction Frequency

Chirag Gupta (Chirag Gupta)

Improper Access Control

Mohammed Al-Barbari

Information Disclosure vulnerability

Authentication Bypass

Murat Kaya

Reflected XSS

Abhishek Sidharthan (Abhishek Sidharthan)

Server Misconfiguration

Pranshu Tiwari (Pranshu Tiwari)

Server Misconfiguration

Adesh Nandkishor Kolte (@AdeshKolte)

XSS via SSRF

Mohd Arif (Mohd Arif)

Persistent XSS

Mayank BIT Mesra (Mayank BIT Mesra)

Missing Authentication for Critical Function

2 x Error Message Information Disclosure

Mukesh Kumar (Mukesh Kumar)

Host based Web Cache Poisoning

Azam (Azam)

Reflected XSS

Samet Sahin

Reflected XSS

Orkhan Yolchuyev (Orkhan Yolchuyev)

Unrestricted Upload of File with Dangerous Type

Improper Input Validation

Sean Melia (@seanmeals)

Code Execution

Information Exposure

Mehmet Tuncer (Mehmet Tuncer)

Information Exposure

Path Traversal

File Inclusion

Saransh Rana (Saransh Rana)

Information Exposure

Samuel Eng (Samuel Eng)

Information Exposure

Berk Imran (@berk_imran)

Reflected XSS

Bill Ben Haim (Bill Ben Haim)

Information Exposure

Unrestricted Upload of File with Dangerous Type

Sahil Mehra (Sahil Mehra)

Host Header Attack

Islam Uddin (Islam Uddin)

2 x Information Exposure

Arne Ramos

6 x Clickjacking

Agametov Rustam (@AgametovRustam)

Server-Side Request Forgery and XSS

Arcot Krishna Manjunath (Arcot Manju)

Cleartext Transmission of Sensitive Information

Cross Origin Resource Sharing

Shivankar Madaan (@shivankarmadaan)

Cleartext Transmission of Sensitive Information

Wai Yan Aung (@waiyanaun9)

4 x Reflected XSS

Kirtikumar Anandrao Ramchandani (Kirtikumar Anandrao Ramchandani)

HSTS

DOS

Rony Gigi (Rony Gigi)

CSRF

Wen Bin KONG (Wen Bin KONG)

Reflected XSS

Sanyam Chawla (Sanyam Chawla, bugcrowd.com/infosecsanyam)

Reflected XSS

Shubham Maheshwari (Shubham Maheshwari)

Reflected XSS

Miguel Santareno (Miguel Santareno)

Reflected XSS

Mindset Software Technologies (MISTS)

Improper Access Control

qwacsawd (hackerone.com/qwacsawd)

Reflected XSS

Error Message Information Disclosure

Niklas Tanskanen (Niklas Tanskanen)

Use of Insufficiently Random Values

Sam Eizad (Sam Eizad)

Header Injection

Athul Jayaram

Content Injection

Sreedeep.Ck Alavil (Sreedeep.Ck)

Improper Input Validation (CVE-2017-9065)

Sarath Kumar (kadavul)

Reflected XSS

Peled Eldan (Peled Eldan)

5 x Reflected XSS

Yash Mehta (Yasf Mehta)

Reflected XSS

Mitesh Patil (Mitesh Patil)

Reflected XSS

Dawood Ansar (Dawood Ansar)

Reflected XSS

Shanmukh D

Reflected XSS

Thrivikram Gujarathi

Reflected XSS

Vikash Chaudhary

Reflected XSS

Ari Apridana (Ari Apridana)

Reflected XSS

Yusuf Furkan (Yusuf Furkan)

HSTS

James Herrick (@mushicious)

Reflected XSS

Blake Rand

2 x Clickjacking

Remesh Ramachandran

Improper Input Validation (CVE-2017-9065)

Anant Mudgal (@anantmudgal)

Use of Hard-coded Credentials

Missing Custom Error Page

Information Disclosure

Chris Green (@chris_t_green)

SQL Injection

Ashish Kunwar (@D0rkerDevil)

Clickjacking

Ipsita Subhadarshan Sahoo

4 x Clickjacking

Steven Hampton (@Steven)

2 x Clickjacking

Ismail Tasdelen (Ismail Tasdelen)

Overly Permissive Cross-domain Whitelist

4 x Clickjacking

Sensitive Cookie Without ‘HttpOnly’ Flag

Rate Limit Bypass

Information Exposure Through an Error Message

7 x Improper Control of Interaction Frequency

6 x Cleartext Transmission of Sensitive Information

7 x Information Exposure

Nainsi Gupta (Nainsi Gupta)

Open Directory Listing

Suru Santhosh (Suru Santhosh)

Reflected XSS

Clickjacking

Mehmet Kelepçe (Mehmet Kelepçe)

Reflected XSS

2017

Himanshu Rahi (Himanshu Rahi)

Stored XSS

Ravela Pramod Kumar

3 x Improper Restriction of Excessive Authentication Attempts

Mohammed Azeem k

3 x Clickjacking

Akshay Bhardwaj (GreyArt) (Akshay Bhardwaj)

2 x Clickjacking

José Manuel Aparicio González, Juan Francisco Acevedo Carles (@Odbk_sec)

3 x Reflected XSS

SQL Injection

Ahmet Mersin

HTML Injection

Suyog Palav (Suyog Palav)

HTML Injection

3 x Clickjacking

Faiz Ahmed Zaidi (Faiz Ahmed Zaidi)

2 x Clickjacking

Kamran Saifullah

Vasim Shaikh (vasim-shaikh)

Md Sameull Soykot (@s0yk0t)

Clickjacking

Nathan Lee Grant (@nathanleegrant)

2 x Reflected XSS

Stored XSS

HTML Injection

Pankaj Rane (@Panckaz_Rane)

Aayush Babbar

Clickjacking

Tansel ÇETİN

Reflected XSS

Lars Peeters

3 x Reflected XSS

Jose Carlos Exposito Bueno

3 x Reflected XSS

Secuninja (@secuninja)

6 x Reflected XSS

Matthew Mawby (@updat3d)

Subdomain Takeover

GAİS (Güvenlik Açığı İstihbarat Servisi)

Reflected XSS

Shuvamoy Roy (shuvamoy.roy.3)

Eliran Itzhak (eliran-itzhak)

4 x Reflected XSS

Florian Kunushevci (florianx00)

Reflected XSS

Shwetabh Suman

HTML Injection

Hagay Sason (grseecon.com)

3 x Reflected XSS

Stored XSS

Umesh Jore

Clickjacking

Max Derrick

Reflected XSS

Bharath Kumar (BharathKumarMV)

Improper Input Validation (CVE-2017-5638)

Mario Sahertian (mario-sahertian)

Error Message Information Disclosure

Yasin Soliman (@SecurityYasin)

Reflected XSS

Information Disclosure

Muhammad Mudassar Yamin (mudassaryamin)

Cross Site Tracing

Windows Short File Name

M.L (@SonnySpooks)

2 x Error Message Information Disclosure

4 x Reflected XSS

Suhas Sunil Gaikwad (SuhasGaikwad, @iamSuhasGaikwad)

Reflected XSS

Sam Sanoop (@snoopysecurity)

5 x Reflected XSS

Amine Hm

SQL Injection

Kenan Genç

Reflected XSS

Ketankumar B. Godhani (@KBGodhani)

Clickjacking

Ed (@EdOverflow)

Reverse Tabnabbing

3 x Reflected XSS

2 x Insufficient Session Management

Open Redirect

CSRF

DOS

Pedro Cardoso (@tvmpt)

Reflected XSS

Vipin Chaudhary(vipin-chaudhary, @vipinxsec)

Resource Injection

2 x Reflected XSS

Michał Praszmo (@nazywam)

Open Redirect

Waseem Ullah Siddiqui

Open Redirect

Reflected XSS

Sadik Shaikh

Clickjacking

Mateusz Szymaniec (@RevToJa)

Reflected XSS

2016

Nassim Bouali

2 x Reflected XSS

SQL Injection

Serge Lacroute

3 x Reflected XSS

2 x External service interaction

Open Redirect

Sandeep Singh Jadon

User enumeration

Илья Селезнёв

2 x Path Traversal

2 x Remote File Inclusion

Kenan GÜMÜŞ

XSS across many sites

João Pina (@tomahock)

2 x Reflected XSS

2 x Stored XSS

File Enumeration

Elarbi Dafrouillah

2 x Path Traversal

Search our S/MIME key here
Fingerprint: 87:F1:6F:70:60:D2:94:83:82:AC:69:F5:46:86:7C:80:7F:86:1D:F0

Find our PGP Key here
Fingerprint: F40C 0FE3 E919 B082 B2DD 75E5 929D 3AFD 217E 21D7