Top reports from OLX program at HackerOne:
- XSS - main page - search[user_id] parameter to OLX - 135 upvotes, $0
- [Critical] Delete any account to OLX - 112 upvotes, $0
- SQL Injection on https://www.olx.co.id to OLX - 71 upvotes, $0
- web cache deception in https://tradus.com lead to name/user_id enumeration and other info to OLX - 59 upvotes, $0
- SQL Injection https://www.olx.co.id to OLX - 48 upvotes, $0
- Reflected XSS on https://www.olx.co.id/iklan/*.html via "ad_type" parameter to OLX - 35 upvotes, $0
- XSS inside HTML Link Tag to OLX - 29 upvotes, $0
- Public Vulnerable Version of Confluence https://confluence.olx.com to OLX - 29 upvotes, $0
- Reflected XSS in www.olx.co.id to OLX - 27 upvotes, $0
- Able to list user's public name, username, phone number, address, facebook ID... to OLX - 19 upvotes, $0
- Search Page Reflected XSS on sharjah.dubizzle.com through unencoded output of GET parameter in JavaScript to OLX - 18 upvotes, $0
- Updating and Deleting any Ads on OLX Philippines to OLX - 17 upvotes, $0
- Cross Site Scripting -> Reflected XSS to OLX - 17 upvotes, $0
- XSS Reflected at SEARCH >> to OLX - 17 upvotes, $0
- Subdomain Takeover (http://docs.olx.ph/ , http://calendar.olx.ph/, http://sites.olx.ph/) to OLX - 16 upvotes, $0
- Reflective XSS at olx.ph to OLX - 15 upvotes, $0
- XSS @ *.letgo.com to OLX - 14 upvotes, $0
- Bypass CSP frame-ancestors at olx.co.za, olx.com.gh to OLX - 13 upvotes, $0
- Combined attacks leading to stealing user's account to OLX - 12 upvotes, $0
- Reflected XSS on www.olx.co.id via ad_type parameter to OLX - 12 upvotes, $0
- Manipulating joinolx.com Job Vacancy alert subscription emails (HTML Injection / Script Injection) to OLX - 11 upvotes, $0
- stored XSS in olx.pl - ogloszenie TITLE element - moderator acc can be hacked to OLX - 11 upvotes, $0
- I found a way to instantly take over ads by other users and change them (IDOR) to OLX - 11 upvotes, $0
- XSS @ yaman.olx.ph to OLX - 10 upvotes, $0
- Arbitrary File Reading to OLX - 10 upvotes, $0
- Stored XSS in buy topup OLX Gold Credits to OLX - 10 upvotes, $0
- Reflected XSS on m.olx.co.id via ad_type parameter to OLX - 10 upvotes, $0
- Unauthorised access to olx.in user accounts. to OLX - 9 upvotes, $0
- Full Account Takeover to OLX - 9 upvotes, $0
- All Active user sessions should be destroyed when user change his password! to OLX - 9 upvotes, $0
- Bypass Rejected ads so user can view it as normal live ad. to OLX - 9 upvotes, $0
- load scripts DOS vulnerability to OLX - 9 upvotes, $0
- CSRF in account configuration leads to complete account compromise to OLX - 8 upvotes, $0
- Reflected XSS in www.olx.ph to OLX - 8 upvotes, $0
- Multiple vulnerabilities in http://blog.dubizzle.com/uae to OLX - 8 upvotes, $0
- Directory Listing of all the resource files of olx.com.eg to OLX - 7 upvotes, $0
- XSS on Meta Tag at https://m.olx.ph to OLX - 7 upvotes, $0
- blog.praca.olx.pl database credentials exposure to OLX - 7 upvotes, $0
- XSS @ *.olx.com.ar to OLX - 6 upvotes, $0
- Name, email, phone and more disclosure on user ID (API) to OLX - 6 upvotes, $0
- Reflected XSS in [olx.qa] to OLX - 6 upvotes, $0
- CSRF in delete advertisement on olx.com.eg to OLX - 6 upvotes, $0
- XSS in OLX.pl ("title" in new advertisement) to OLX - 6 upvotes, $0
- XSS yaman.olx.ph to OLX - 5 upvotes, $0
- XSS on Home page olx.com.ar via auto save search text to OLX - 5 upvotes, $0
- Stored XSS on contact name to OLX - 5 upvotes, $0
- Reflective XSS at m.olx.ph to OLX - 5 upvotes, $0
- yaman.olx.ph/wordpress is using a very vulnerable version of WordPress and contains directory listing to OLX - 5 upvotes, $0
- Reflected XSS at yaman.olx.ph to OLX - 4 upvotes, $0
- these are my old reports and still i have not receive any good replys, these all are Cross Site Scripting(XSS) issues: POC1: https://www.youtube.com/w to OLX - 4 upvotes, $0
- full path disclosure vulnerability at https://security.olx.com/* to OLX - 4 upvotes, $0
- Reflected XSS at m.olx.ph to OLX - 4 upvotes, $0
- Reflected XSS in OLX.in to OLX - 4 upvotes, $0
- REFLECTED CROSS SITE SCRIPTING IN OLX to OLX - 4 upvotes, $0
- Reflected XSS in olx.pt to OLX - 4 upvotes, $0
- Bypassing Phone Verification For Posting AD On OLX to OLX - 3 upvotes, $0
- cross-site scripting in get request to OLX - 3 upvotes, $0
- OLX is vulnerable to clickjaking to OLX - 3 upvotes, $0
- xss yaman.olx.ph to OLX - 2 upvotes, $0
- XSS and Open Redirect on https://jobs.dubizzle.com/ to OLX - 2 upvotes, $0
- XSS and HTML Injection https://sharjah.dubizzle.com/ to OLX - 2 upvotes, $0
- Full path disclosure vulnerability at http://corporate.olx.ph to OLX - 2 upvotes, $0
- Reflective XSS at dubai.dubizzle.com to OLX - 2 upvotes, $0
- olx.ph is vulnerable to POODLE attack to OLX - 2 upvotes, $0
- Server Version Of https://www.olx.ph/ to OLX - 2 upvotes, $0
- Reflected Cross Site scripting Attack (XSS) to OLX - 0 upvotes, $0