Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
3921I Could Have Hacked All Uber Accounts- But I Chose to Report it Instead Information disclosure Uber Anand Prakash (@anandpraka_sh) Bug Bounty2019-09-132023-06-13
3920Race Condition that could Result to RCE - (A story with an App that temporary stored an uploaded file within 2 seconds before moving it to Amazon S3) Race condition RCE Unrestricted file upload NA YoKo Kho (@YokoAcc) Bug Bounty2019-09-142023-06-13
3919OTP Manipulation OTP bypass NA Kishan choudhary (@choudhary_1337) Bug Bounty2019-09-142023-06-13
3918How I found a simple and weird Account takeover bug Account takeover Missing authentication NA Bijan Murmu (@0xBijan) Bug Bounty2019-09-142023-06-13
3916Client, not client! LFI NA Tung Pun Bug Bounty2019-09-152023-06-13
3915RCE with Flask Jinja Template Injection SSTI RCE NA AkShAy KaTkAr (@AkShAy KaTkAr) Bug Bounty2019-09-172023-06-13
3914SSRF | Reading Local Files from DownNotifier server SSRF NA Dr.FarFar (@3XS0) Bug Bounty2019-09-182023-06-13
3911How I able to Takeover 10 subdomains in a Private Program ? Subdomain takeover NA Mohamed Haron (@m7mdharon) Bug Bounty2019-09-202023-06-13
3909Bug or Feature? GitHub Adventure #001 OAuth Open redirect NA Dominik Opyd (@oad_earth) Bug Bounty2019-09-212023-06-13
3908A Simple bypass of Registration Activation that Lead to many Bug - Information disclosure IDOR CSRF NA YoKo Kho (@YokoAcc) Bug Bounty2019-09-212023-06-13
3906[Case Study] OAuth Misconfiguration leads to Account Takeover OAuth Account takeover NA Gaurang Bhatnagar (@0xgaurang) Bug Bounty2019-09-212023-06-13
3905[Bug Bounty] Exploiting Cookie Based XSS by Finding RCE Information disclosure SQL injection Authentication bypass Unrestricted file upload RCE XSS NA Tomi (@noobe_io) Bug Bounty2019-09-222023-06-13
3904Broken Link Hijacking - s3 buckets Broken link hijacking Google Tutorgeeks (@tutorgeeks) Bug Bounty2019-09-222023-06-13
3903Fuzzing {{7*7}} Till {{P1}} SSTI NA Verneet (@err0rrrrr) Bug Bounty2019-09-232023-06-13
3901Information Disclosure at PayPal and Xoom (PayPal Acquisition) via Simple Google Dork - 1,000 USD Information disclosure Paypal YoKo Kho (@YokoAcc) Bug Bounty2019-09-242023-06-13
3900Analysis of CVE-2019-14994 – Jira Service Desk Path Traversal leads to Massive Information Disclosure Path traversal Atlassian Sam Curry (@samwcyo) Bug Bounty2019-09-252023-06-13
3898Stories Of IDOR IDOR NA Shivbihari Pandey (@ninja_pandit_) Bug Bounty2019-09-282023-06-13
3897Spear texting via parameter injection Parameter tampering NA Kyle (@B3nac) Bug Bounty2019-09-292023-06-13
3896Bug Hunting: Xss On Cookie Popup Warning Reflected XSS NA vict0ni (@vict0ni) Bug Bounty2019-09-302023-06-13
3895One Way to Find Hidden IDOR Vulnerability IDOR NA Vulkey_Chen (@Vulkey_Chen) Bug Bounty2019-10-012023-06-13
3894Stealing login credentials with Reflected XSS Reflected XSS NA mehulpanchal007 (@007_sharky) Bug Bounty2019-10-012023-06-13
3893How to get RCE on AEM instance without Java knowledge RCE NA byq (@ByQwert) Bug Bounty2019-10-012023-06-13
3892How a double-free bug in WhatsApp turns to RCE Memory corruption RCE Android Meta / Facebook Awakened Bug Bounty2019-10-022023-06-13
3891GraphQL Introspection leads to Sensitive Data Disclosure. Information disclosure NA Pranay Bafna Bug Bounty2019-10-022023-06-13
3890REST framework Admin Panel bypass and how I recon for this vulnerability Authentication bypass NA Aziz Hakim (@hackerb0y_) Bug Bounty2019-10-022023-06-13