Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
3841Bug Bounty: Broken API Authorization Authorization flaw NA Th3hidd3nmist (@th3_hidd3n_mist) Bug Bounty2019-11-122023-06-13
3839Mass XS-Search using Cache Attack XS-Search Google Terjanq (@terjanq) Bug Bounty2019-11-122023-06-13
3837[Server Side Request Forgery] Blind SSRF due to Sentry Misconfiguration SSRF NA Kent Bayron (@bayronkentoy) Bug Bounty2019-11-142023-06-13
3835Chains on Chains!! Chaining several IDOR’s into Account Takeover(PART ONE) IDOR NA Daniel Marte (@DanielM59720745) Bug Bounty2019-11-152023-06-13
3834Authenticated CORS with Access-Control-Allow-Origin: * Caching issue Browser hacking Google (Chromium) BitK (@BitK_) Bug Bounty2019-11-152023-06-13
3831LDAP Admin Account Bypassed :) LDAP injection Authentication bypass NA Himanshu Pdy (@himanshu_pdy) Bug Bounty2019-11-162023-06-13
3830Privilege Escalation with simple recon Privilege escalation Blind XSS NA Mayur Gupta (@RisingHunter_) Bug Bounty2019-11-162023-06-13
3828My First Bug ($500) No valid SPF records NA Abhishek Yadav (@abhishake100) Bug Bounty2019-11-182023-06-13
3827This is How I was able to hunt a rare bug in a private program Missing authentication Privilege escalation NA Abida Fahd Bug Bounty2019-11-182023-06-13
3825Million Users PII Leak Data Leak Information disclosure Blind XSS NA Shivbihari Pandey (@ninja_pandit_) Bug Bounty2019-11-182023-06-13
3821Subdomain Takeover via Campaignmonitor.com Subdomain takeover NA Mohamed Haron (@m7mdharon) Bug Bounty2019-11-202023-06-13
3820How I paid 2$ for a 1054$ XSS bug + 20 chars blind XSS payloads XSS NA Mohamed Daher (@DaherMohamed4) Bug Bounty2019-11-202023-06-13
3817700$ Denial of Service(DoS) vulnerability in script-loader.php (CVE-2018-6389) DoS NA Pankaj Thakur (@Nep_1337_1998) Bug Bounty2019-11-212023-06-13
3815Stories Of IDOR-Part 2 IDOR NA Shivbihari Pandey (@ninja_pandit_) Bug Bounty2019-11-212023-06-13
3814IDOR via Websockets IDOR NA Shuaib Oladigbolu (@_sawzeeyy) Bug Bounty2019-11-232023-06-13
3813Exploiting padding oracles with fixed IVs Padding oracle attack Account takeover NA Teddy Katz (@not_aardvark) Bug Bounty2019-11-232023-06-13
3812The AccountTakeOver Killing Chain Account takeover CSRF Self-XSS NA أنس روبي (@xhzeem) Bug Bounty2019-11-232023-06-13
3811CORS Misconfiguration to Account TakeOver [Out of scope to grab items In-Scope] CORS misconfiguration Open redirect Reflected XSS Session management issue NA Mashoud1122 (@mashoud1122) Bug Bounty2019-11-242023-06-13
3809How Did Tons of People Like Me on Tinder? HTTP request smuggling NA Mustafa iran (@Mustafaran) Bug Bounty2019-11-252023-06-13
3808Getting access to disabled/hidden features with the help of Burpsuite Match and Replace settings Authorization flaw NA Johns Simon (@Johnssimon22) Bug Bounty2019-11-272023-06-13
3803How I turned Self XSS to Stored via CSRF Self-XSS CSRF NA Abhishek Yadav (@abhishake100) Bug Bounty2019-11-292023-06-13
3802My first RCE: a tale of good ideas and good friends RCE ImageTragick NA rez0 (@rez0__) Bug Bounty2019-11-292023-06-13
3801Dank Writeup On Broken Access Control On An Indian Startup Unrestricted file upload Authorization flaw NA Divyanshu Shukla (@justm0rph3u5) Bug Bounty2019-11-302023-06-13
3800XSS like a Pro XSS NA Anas Mahmood (@AnasIsHere) Bug Bounty2019-12-052023-06-13
3799HTTP Request Smuggling + IDOR HTTP request smuggling IDOR NA hipotermia (@_hipotermia_) Bug Bounty2019-12-052023-06-13