Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
3338EN | Account Takeover and Sensitive Data Leakage via CORS Misconfiguration CORS misconfiguration CSRF Account takeover NA Lütfü Mert Ceylan (@lutfumertceylan) Bug Bounty2020-07-042023-06-13
3336BBC Bug Bounty Write-up | XSS Vulnerability Reflected XSS BBC Pethuraj (@Pethuraj) Bug Bounty2020-07-052023-06-13
3335Why I paid 3.5K to become a TLD registrar reseller when doing bug bounty XXE NA hg_real (@hgreal1) Bug Bounty2020-07-052023-06-13
3334From Host Header injection to SQL injection Host header injection SQL injection NA Daoud Youssef / smacker dodi (@daoud_youssef) Bug Bounty2020-07-052023-06-13
3332Case Study I - Browser Anomaly with Facebook Apps -1500$ Authorization flaw Meta / Facebook easySIEM (@easySIEM) Bug Bounty2020-07-052023-06-13
3331RCE via image upload functionality Unrestricted file upload RCE NA Adwaith KS Bug Bounty2020-07-052023-06-13
3330My First Bug: Blind SSRF Through Profile Picture Upload SSRF NA swaysthinking (@swaysThinking) Bug Bounty2020-07-052023-06-13
3327How i was able to bypass Email Confirm — P4 Information disclosure NA Mohammed Ehssan (@alone_Wwolf) Bug Bounty2020-07-062023-06-13
3326From . in regex to SSRF — part 3 SSRF CRLF injection NA Niemiec Marcin (@xvnpw) Bug Bounty2020-07-072023-06-13
3323How I found 10 Remote Code Execution in 10 minutes CVE-2020–5902 RCE NA Saransh Srivastav (@malfuncti0n_) Bug Bounty2020-07-072023-06-13
3322Journey from low to critical bug $$$ IDOR NA Dheeraj Madhukar (@Dheerajmadhukar) Bug Bounty2020-07-092023-06-13
3320Global grant uri in Android 8.0-9.0 (2018 year) Authorization flaw Google Dzmitry Lukyanenka (@vulnano) Bug Bounty2020-07-092023-06-13
3319Exploiting Application Logic to Referral Code Disclosure Logic flaw Information disclosure NA Vaibhav Joshi (@vj0shii) Bug Bounty2020-07-092023-06-13
3318Remote Denial-of-Service with Chrome DoS Google Dan Lyton Bug Bounty2020-07-092023-06-13
3315Don’t stop at one bug $$$$ Open redirect XSS LFI NA Dheeraj Madhukar (@Dheerajmadhukar) Bug Bounty2020-07-102023-06-13
3314Phone number validation bypass through url path manipulation . OTP bypass NA ben aymen (@ben_aymen_182) Bug Bounty2020-07-102023-06-13
3313A tale of critical account take over Account takeover Exposed JWT generation endpoint JWT NA Shivam Pandey (@shivam31200) Bug Bounty2020-07-102023-06-13
3312How I hacked into a Telecom Network RCE Security misconfiguration JBoss NA Harpreet Singh Bug Bounty2020-07-112023-06-13
3311How I was able to change victim’s password using IDN Homograph Attack IDN homograph attack NA Abhishek Karle (@AbhishekKarle3) Bug Bounty2020-07-112023-06-13
3310Bug Bounty Experience: Unvalidated Redirection Vulnerability Open redirect NA Simply Secure Bug Bounty2020-07-122023-06-13
3309Self stored xss to full account takeover XSS Account takeover NA Jatin Aesthetic (@techyfreakk) Bug Bounty2020-07-122023-06-13
3308How An API Misconfiguration Can Lead To Your Internal Company Data Information disclosure NA Me9187 (@Me9187) Bug Bounty2020-07-122023-06-13
3307SSRF in import file function SSRF NA Rafael Silva Bug Bounty2020-07-142023-06-13
3306Exploiting Imported Libraries to Bypass WAF Reflected XSS NA Greg Gibson Bug Bounty2020-07-142023-06-13
3305Hunting postMessage Vulnerabilities postMessage DOM XSS Apple Google (Youtube) Adobe Gary O%27Leary-Steele (@garyoleary) Bug Bounty2020-07-142023-06-13