Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
3512The Story of Blind SSRF leads to internal Host discovery. SSRF NA kaustubh padwad (@s3curityb3ast) Bug Bounty2020-05-012023-06-13
3505#BugBounty — Adding Money Using Response Modification Payment tampering Logic flaw NA Line_no 6 Bug Bounty2020-05-032023-06-13
3503Cool paste jacking attack earned me $$$ Paste jacking NA Aman Rawat (@theamanrawat) Bug Bounty2020-05-042023-06-13
3502G Suite - Device Management XSS XSS Google Rojan Rijal (@uraniumhacker) Bug Bounty2020-05-052023-06-13
3499A tale of verbose error message and a JWT token Information disclosure Authorization flaw NA Marek Geleta (@marek_geleta) Bug Bounty2020-05-052023-06-13
3497DOM XSS Walkthrough DOM XSS NA Youssef Lahouifi (@YLahouifi) Bug Bounty2020-05-062023-06-13
3496How we Hijacked 26+ Subdomains Subdomain takeover NA Aishwarya Kendle (@aish_kendle) Bug Bounty2020-05-072023-06-13
3495DOM-Based XSS at accounts.google.com by Google Voice Extension. DOM XSS Google missoum1307 (@missoum1307) Bug Bounty2020-05-072023-06-13
3492Pentesting Cisco SD-WAN Part 2: Breaking Routers OS command injection Security code review Cisco Julien Legras (@Julien_Legras) Bug Bounty2020-05-072023-06-13
3490How I made $10K in bug bounties from GitHub secret leaks Information disclosure NA Tillson Galloway (tillson_) Bug Bounty2020-05-102023-06-13
3488Magic of the Back Slash Path traversal NA Anil Tom (mr_4nk) Bug Bounty2020-05-112023-06-13
3486Lucky Bug Which Let Me Change Name of Every Accounts at a Single Click SQL injection NA Merbin Russel (e_23_e) Bug Bounty2020-05-132023-06-13
3485$3000 Bug Bounty Award from Mozilla for a successful targeted Credential Hunt Information disclosure NA Johann Rehberger (wunderwuzzi23) Bug Bounty2020-05-132023-06-13
3484Bug Bounty — Advanced Manual Penetration Testing Leading to Price Manipulation Vulnerability Payment tampering NA Talatmehmood Bug Bounty2020-05-142023-06-13
3483Weak Cryptography in Password Reset to Full Account Takeover Account takeover Password reset Cryptographic issues NA Harsh Bothra (@harshbothra_) Bug Bounty2020-05-152023-06-13
3481Password Reset Poisoning leading to Account Takeover Password reset Account takeover NA Swapnil Maurya (@swapmaurya20) Bug Bounty2020-05-162023-06-13
3480Chained Bugs [ Account TakeOver ] IDOR XSS Account takeover NA Bilal Khan (@bilalmerokhel) Bug Bounty2020-05-162023-06-13
3478Logical Bug which let me stop Users from Creating Ads at a Website Logic flaw DoS NA Merbin Russel (e_23_e) Bug Bounty2020-05-172023-06-13
3477One Param => $10k IDOR XSS Account takeover NA Bilal Khan (@bilalmerokhel) Bug Bounty2020-05-172023-06-13
3476Stored XSS Leads to Plaintext Password Disclosure Stored XSS Information disclosure Unrestricted file upload NA bad5ect0r (@bad5ect0r) Bug Bounty2020-05-172023-06-13
3475Tale of Account Takeovers (Part-2) Account takeover NA Vijaysimha Reddy Bathini (@fatratfatrat) Bug Bounty2020-05-172023-06-13
3474Cors Blimey: The power of chaining CORS CORS misconfiguration Stored XSS CSRF NA Hazana (@hazanasec) Bug Bounty2020-05-172023-06-13
3472My first 10k bdt bounty from an e-commerce site IDOR NA Md Saikat Bug Bounty2020-05-182023-06-13
3471Multiple flaws leads to Account Takeover within an Application Account takeover Password reset NA Harshit Sengar (@sengarharshit1) Bug Bounty2020-05-182023-06-13
3470CVE-2020–1088 — Yet another arbitrary delete EoP Local Privilege Escalation Windows Microsoft Søren Fritzbøger (@fritzboger) Bug Bounty2020-05-182023-06-13