Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
3187Accessing the website directly through its IP address, a case of a poorly hidden sql injection SQL injection NA Vuk Ivanovic Bug Bounty2020-08-272023-06-13
3184The Importance of keeping up to date, or how I found an interesting bug thanks to a tweet Stored XSS NA Vuk Ivanovic Bug Bounty2020-08-292023-06-13
3183Unhiding the hidden Client-side enforcement of server-side security Authorization flaw CSRF NA I am Broot Bug Bounty2020-08-312023-06-13
3181Stop scratching the surface, and hack the dependencies Stored XSS NA Rotem Reiss (@rotem_reiss) Bug Bounty2020-08-312023-06-13
3178CVE-2020-6519 - Chromium 83 Zero Day Full CSP Bypass Cross Platforms CSP bypass Google (Chrome & Chromium) Gal Weizman (@WeizmanGal) Bug Bounty2022-09-022023-06-13
3177My Story With XSS XSS NA Soufiane Habti (@wld_basha) Bug Bounty2020-09-032023-06-13
3176Account Takeover via IDOR IDOR Account takeover NA Roma Ramazanoff (@r0hack) Bug Bounty2020-09-042023-06-13
3175How_i_was_able_to_pawned_website_via_escilating_webcache deception to rce Web cache deception SSRF RCE NA mohit (@mohit29295572) Bug Bounty2020-09-052023-06-13
3174XSS that can pay your Bills :) Reflected XSS NA Smile Hacker (@_smile_hacker_) Bug Bounty2020-09-052023-06-13
3173Never Give Up, The Story Behind a Dupe-To-Triaged XSS OAuth Account takeover NA Alan Brian (@soyelmago) Bug Bounty2020-09-062023-06-13
3172How response Manipulation got me a little, but sweet Bounty MFA bypass NA Tommaso De Ponti (@heytdep) Bug Bounty2020-09-072023-06-13
3170From Android Static Analysis to RCE on Prod RCE Directory listing Missing authentication NA Aditya Dixit (@zombie007o) Bug Bounty2020-09-072023-06-13
3169XSS->Fix->Bypass: 10000$ bounty in Google Maps XSS Google Zohar Shachar Bug Bounty2020-09-072023-06-13
3168CVE-2020-8150 – Remote Code Execution as SYSTEM/root via Backblaze RCE Local Privilege Escalation Backblaze Jason Geffner (@JasonGeffner) Bug Bounty2020-09-092023-06-13
3166Unintended Behaviour of domain got me P4 Logic flaw NA Takester (@dhiraj_ramteke) Bug Bounty2020-09-102023-06-13
3165Universal XSS in Android WebView (CVE-2020-6506) Universal XSS Google Microsoft Twitter Alesandro Ortiz (@AlesandroOrtizR) Bug Bounty2020-09-102023-06-13
3163How I hacked redbus [An online bus-ticketing application] LFI SSRF redBus Sangeetha Rajesh S (@rajesh_sangi12) Bug Bounty2020-09-122023-06-13
3162SQL Injection & Remote Code Execution - Double P1 SQL injection RCE NA Shrey Shah (@ShreySh43332033) Bug Bounty2020-09-132023-06-13
3161Business logic vulnerabilities — Low-level logic flaw Logic flaw NA Harry D Bug Bounty2020-09-132023-06-13
3160Account takeover by OTP bypass OTP bypass NA Bhavarth Kandoria Bug Bounty2020-09-132023-06-13
3157Exploiting a "Useless" Cookie-Based XSS and Making it Useful XSS NA Daniel Thatcher (@_danielthatcher) Bug Bounty2020-09-162023-06-13
3156Res-block: Extension Resources Block Attack on Chrome’s Incognito Mode Browser hacking Google Piyush Raj (@0x48piraj) Bug Bounty2020-09-162023-06-13
3152Privilege Escalation via Account Takeover on NodeBB Forum Software — Bug Bounty (512$) — CVE-2020–15149 IDOR Account takeover NodeBB Muhammed Eren Uygun (@erenuyguun) Bug Bounty2020-09-192023-06-13
3151CVE-2020-9964 - An iOS infoleak iOS Memory initialisation issue Apple Muirey03 (@Muirey03) Bug Bounty2020-09-192023-06-13
3150Emoji error handling SQL injection NA shesha sai_c (@Cyb3r_4ss4s1n) Bug Bounty2020-09-192023-06-13