Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
5048Escalating XSS in PhantomJS Image Rendering to SSRF/Local-File Read XSS SSRF LFI NA Brett Buerhaus (@bbuerhaus) Bug Bounty2017-06-292023-06-13
4839Stored XSS, and SSRF in Google using the Dataset Publishing Language Stored XSS SSRF Google Craig Arendt (@signalchaos) Bug Bounty2018-03-072023-06-13
4770Internet Safety for Kids & Families — Trend Micro Bypass DOM XSS DOM XSS Trend Micro Honc (@honcbb) Bug Bounty2018-05-082023-06-13
3863Illegal Rendered at Download Feature in Several Apps (including Opera Mini) that Lead to Extension Manipulation (with RTLO) RTLO Opera YoKo Kho (@YokoAcc) Bug Bounty2019-10-262023-06-13
3793Telegram (v4.9.155353) was rendering file:// links + opening them via NSWorkspace.open -> code execution. RCE Telegram Vladimir Metnew (@vladimir_metnew) Bug Bounty2019-12-082023-06-13
3789AirDoS: Remotely render any nearby iPhone or iPad unusable DoS Apple Kishan Bagaria (@KishanBagaria) Bug Bounty2019-12-102023-06-13
3661Plan Change Logic in Google Fiber (Webpass) Logic flaw Payment tampering Google Craig Arendt (@signalchaos) Bug Bounty2020-02-172023-06-13
3013Exploiting dynamic rendering engines to take control of web apps SSRF Open redirect NA Vasilii Ermilov (@ermil0v) Bug Bounty2020-11-192023-06-13
2966Download Filename Manipulation due to improper rendering of RTLO characters RTLO NA Jayateertha Guruprasad (@JayateerthaG) Bug Bounty2020-12-152023-06-13
2542SSRF in PDF Renderer using SVG SSRF NA pwn.vg / Tomi (@mastomii) Bug Bounty2021-05-192023-06-13
2320A Bug%27s Life: CVE-2021-21225 Browser hacking Google Brendon Tiszka (@btiszka) Bug Bounty2021-08-162023-06-13
1186But You Told Me You Were Safe: Attacking The Mozilla Firefox Renderer (Part 1) Browser hacking RCE Prototype pollution Mozilla Hossein Lotfi (@hosselot) Bug Bounty2022-08-232023-06-13
394Give me a browser, I’ll give you a Shell Local Privilege Escalation Kiosk hacking NA Rend Bug Bounty2023-02-252023-06-13
373Exfiltrating AWS Credentials via PDF Rendering of Unsanitized Input SSRF HTML injection XSS NA Cristi Vlad (@CristiVlad25) Bug Bounty2023-03-012023-06-13
101Rendezvous with a Chatbot: Chaining Contextual Risk Vulnerabilities Chatbot Websockets Cross-Site WebSocket Hijacking (CSWH) Captcha bypass NA Abeer Banerjee (@bugasur) Bug Bounty2023-05-112023-06-13
82LOLBINed — Finding “LOLBINs” In AV Uninstallers Local Privilege Escalation Kaspersky F-Secure Trend Micro McAfee Nasreddine Bencherchali (@nas_bench) Bug Bounty2023-05-172023-06-13