Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
3468Teradici and CVE-2020-10965: An issue of routing. Missing authentication Teradici Benjamin Heald (@heald_ben) Bug Bounty2020-05-182023-06-13
3467How I got 200$ in 5 minutes – Sensitive data leak Information disclosure NA Sanjay Verdu (@codersanjay) Bug Bounty2020-05-192023-06-13
3466Easy bounties with subdomain discovery - Using Project Sonar for bug bounty Broken access control Authorization flaw Bpost Torben Capiau (@TorbenCapiau) Bug Bounty2020-05-202023-06-13
3461Parsing the DOM elements of Other pages via XSS: A Bug Bounty Story XSS Information disclosure NA Mandeep Jadon (@1337tr0lls) Bug Bounty2020-05-222023-06-13
3460My First Bug Bounty — 2 Factor Authentication Bypass OTP bypass NA Talatmehmood Bug Bounty2020-05-222023-06-13
3459How Source code reading helped me find an IDOR IDOR Information disclosure NA Sanjay Verdu (@codersanjay) Bug Bounty2020-05-222023-06-13
3458Story About OTP Bypass To Stored XSS OTP bypass Stored XSS NA PJ Borah (@PJBorah1) Bug Bounty2020-05-232023-06-13
3456Chaining an IDOR with a business-logic error to achieve critical impact IDOR Logic flaw NA Julien Cretel (@jub0bs) Bug Bounty2020-05-262023-06-13
3451iOS Outlook Stored XSS Write-Up($3000) XSS Microsoft kminthein / weev3 (@kyawminthein99) Bug Bounty2020-05-282023-06-13
3450Clickjacking to Account Takeover Clickjacking NA Abhishek Yadav (@abhishake100) Bug Bounty2020-05-282023-06-13
3449A Long Overdue Write-up: How I got into the Oppo Hall of Fame Login screen bypass Authentication bypass oppo Shibin B. Shaji (@shibinbshaji06) Bug Bounty2020-05-282023-06-13
3447Bypassing WAF to perform XSS XSS NA Kleiton Kurti (@kleiton0x7e) Bug Bounty2020-05-282023-06-13
3444IDOR in session cookie leading to Mass Account Takeover IDOR Account takeover NA Zonduhackerone (@zonduu1) Bug Bounty2020-05-292023-06-13
3443My Expense Report resulted in a Server-Side Request Forgery (SSRF) on Lyft SSRF Lyft Ben Sadeghipour (@nahamsec) Bug Bounty2020-05-292023-06-13
3442Analysis and Discovery of CVE-2020-13693 Privilege escalation Security code review BBPress Raphael Karger (@pwnszn) Bug Bounty2020-05-292023-06-13
3441Weak Cryptography Leads To Open Redirect Open redirect NA DarkLotus (@darklotuskdb) Bug Bounty2020-05-302023-06-13
3439Zero-day in Sign in with Apple Account takeover Apple Bhavuk Jain (@bhavukjain1) Bug Bounty2020-05-302023-06-13
3438Cross-site scripting: The power of the hidden parameters. Reflected XSS Sony Kassih Mouhssine (@KassihMouhssine) Bug Bounty2020-05-302023-06-13
3436Weird “Subdomain Take Over” pattern of Amazon S3 Subdomain takeover NA Simgamsetti Manikanta (@zaheckmania) Bug Bounty2020-05-312023-06-13
3435Hunting on ASPX Application For P1%27s [Unauthenticated SOAP,RCE, Info Disclosure] RCE Information disclosure IDOR NA ElMahdi Mrhassel (@ElMrhassel) Bug Bounty2020-05-312023-06-13
3434h1{Error based XXE - bug bounty writeup} XXE NA f4d3 (@f4d3_cl) Bug Bounty2020-05-312023-06-13
3432How I leveraged an interesting CSRF vulnerability to turn self XSS into a persistent attack? Self-XSS CSRF NA Akash Methani (@0xAkash) Bug Bounty2020-06-012023-06-13
3429Double URL-encoded XSS Reflected XSS NA vict0ni (@vict0ni) Bug Bounty2020-06-022023-06-13
3427IP-in-IP protocol routes arbitrary traffic by default DoS Spoofing Internet Bug Bounty yannayl (@Yannayli) Bug Bounty2020-06-022023-06-13
3426From CRLF to Account Takeover CRLF injection HTTP response splitting Reflected XSS Account takeover NA Valeriy Shevchenko (@Krevetk0Valeriy) Bug Bounty2020-06-032023-06-13