Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
3420Story of Blind SQL with a typo error. SQL injection NA Amyrahm (@Amyrahm11) Bug Bounty2020-06-052023-06-13
3419Local file read via XSS using PDF generate functionality XSS LFI NA Sanjay Singh Jhala (@lordjerry0x01) Bug Bounty2020-06-052023-06-13
3418Account takeover via postMessage Account takeover postMessage NA socket (@yxw21) Bug Bounty2020-06-052023-06-13
3417Multiple Information exposed due to misconfigured Service-now ITSM instances Missing authentication Information disclosure NA Th3G3nt3lman (@Th3G3nt3lman) Bug Bounty2020-06-052023-06-13
3416From 3,99 to 1,650 USD (Part I) – Simple Vertical Privilege Escalation by Changing HTTP Response Privilege escalation NA YoKo Kho (@YokoAcc) Bug Bounty2020-06-062023-06-13
3415XSS to Database Credential Leakage & Database Access — Story of total luck! Reflected XSS Information disclosure NA Harsh Bothra (@harshbothra_) Bug Bounty2020-06-062023-06-13
3413Different host header injection worth 2k Host header injection NA Imran Nissar (@Imrannissar3) Bug Bounty2020-06-072023-06-13
3412This is fine 🐶 Information disclosure NA Ricardo Iramar dos Santos (@ricardo_iramar) Bug Bounty2020-06-082023-06-13
3410The Accidental RCE Unrestricted file upload NA Mr. Beast (@__mr_beast__) Bug Bounty2020-06-092023-06-13
3409Cmd Hijack - a command/argument confusion with path traversal in cmd.exe OS command injection Path traversal Microsoft Julian Horoszkiewicz Bug Bounty2020-06-102023-06-13
3407The “P5” Link Injection Story Hyperlink injection NA Silent Bronco (@silentbronco) Bug Bounty2020-06-102023-06-13
3406Utilizing Lockdown: Blind Sqli leads to Account Takeover & Data Extraction Blind SQL injection Account takeover NA Shakti Mohanty (@3ncryptSaan) Bug Bounty2020-06-102023-06-13
3405Privilege Escalation by Changing HTTP Response (Admin Access) Privilege escalation NA Bachrudin Ashari Pujakusuma (@Bachrudinashari) Bug Bounty2020-06-102023-06-13
3404Guest Blog: From File Upload to RCE Unrestricted file upload RCE NA Lukasz Wierzbicki (@v13rs8a) Bug Bounty2020-06-102023-06-13
3403The Frustrating XSS XSS NA Mr. Beast (@__mr_beast__) Bug Bounty2020-06-112023-06-13
3402HUNT for SQL Injection- The Smart Way! SQL injection NA Mudassir Sharief Bug Bounty2020-06-112023-06-13
3401Race Conditions - Exploring the Possibilities Race condition Reddit Milind Purswani (@MilindPurswani) Bug Bounty2020-06-112023-06-13
3400Let’s Bypass CSRF Protection & Password Confirmation to Takeover Victim Accounts :D CSRF NA Harsh Bothra (@harshbothra_) Bug Bounty2020-06-122023-06-13
3399DoS and BugBounties :A series of DoS attacks on HackerOne DoS NA Ninad Mishra (@iamr000t) Bug Bounty2020-06-122023-06-13
3398Account Takeover via OTP Bruteforce (Apigee API) OTP bypass Bruteforce Lack of rate limiting NA Vishnuraj Bug Bounty2020-06-132023-06-13
3397RACE Condition vulnerability found in bug-bounty program Race condition NA Pravinrp Bug Bounty2020-06-132023-06-13
3392How to Secure AWS ServerLess Lambda from ReDoS(Regular Expression Denial-of-Service) & Resultant Financial Impact ReDoS NA Ddigvijay (@itsdig) Bug Bounty2020-06-142023-06-13
3390Business logic flaw in the invitation system allows to Takeover any account at a private company Account takeover IDOR NA Daniel V. (@d4niel_v) Bug Bounty2020-06-152023-06-13
3389Reflected User Input == XSS! Reflected XSS NA Silent Bronco (@silentbronco) Bug Bounty2020-06-152023-06-13
3386How I was able to buy t-shirt for €1 — Payment Price Manipulation Payment tampering NA Muztahidul Tanim (@TheMuztahidul) Bug Bounty2020-06-162023-06-13