Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
5287My Experience with the PayPal Bug Bounty Programme CSRF Paypal Jack Whitton (@fin1te) Bug Bounty2012-10-122023-06-13
5281Stealing Facebook Access Tokens with a Double Submit CSRF OAuth Meta / Facebook Jack Whitton (@fin1te) Bug Bounty2013-04-132023-06-13
5269Facebook CSRF leading to full account takeover (fixed) CSRF Account takeover Meta / Facebook Josip Franjkovic (@josipfranjkovic) Bug Bounty2013-10-182023-06-13
5267Facebook bug bounty: secondary damage (one report that leads to more bugs), fairness, and why I really like reporting to Facebook CSRF Meta / Facebook Josip Franjkovic (@josipfranjkovic) Bug Bounty2013-10-212023-06-13
5264Instagram%27s One-Click Privacy Switch CSRF Meta / Facebook Jack Whitton (@fin1te) Bug Bounty2013-10-312023-06-13
5242Popping a shell on the Oculus developer portal SQL injection CSRF RCE IDOR Meta / Facebook Bitquark (@bitquark) Bug Bounty2014-08-312023-06-13
5224Flickr API Explorer – Force users to execute any API request. CSRF Flickr Brett Buerhaus (@bbuerhaus) Bug Bounty2015-02-032023-06-13
5220How I bypassed Facebook CSRF Protection CSRF Meta / Facebook Pouya Darabi (@Pouyadarabi) Bug Bounty2015-09-042023-06-13
5193Ubiquiti Bug Bounty: UniFi v3.2.10 Generic CSRF Protection Bypass CSRF Ubiquity Networks Julien Ahrens (@MrTuxracer) Bug Bounty2016-02-232023-06-13
5186Obtaining Login Tokens for an Outlook, Office or Azure Account CSRF Microsoft Jack Whitton (@fin1te) Bug Bounty2016-04-032023-06-13
5176Fiverr.com Full Accounts Takeover – A Vulnerability Puts $50 Million Company At Risk CSRF Fiverr Mohamed A. Baset Bug Bounty2016-05-132023-06-13
5174How I bypassed Facebook CSRF once again! CSRF Meta / Facebook Pouya Darabi (@Pouyadarabi) Bug Bounty2016-05-172023-06-13
5169RunKeeper Stored XSS Vulnerability – Where worms are able to run too! Stored XSS CSRF RunKeeper Mohamed A. Baset Bug Bounty2016-06-062023-06-13
5166Two vulnerabilities makes an Exploit!! (XSS and CSRF in Bing) XSS CSRF Microsoft Sai Krishna Kothapalli (@kmskrishna) Bug Bounty2016-06-102023-06-13
5162TopCoder.com Vulnerabilities – A tail of site-wide bugs leads to accounts compromise & payments hijacking CSRF Account takeover Topcoder.com Mohamed A. Baset Bug Bounty2016-06-282023-06-13
5159Stealing Facebook access_tokens using CSRF in device login flow CSRF OAuth Information disclosure Meta / Facebook Josip Franjkovic (@josipfranjkovic) Bug Bounty2016-07-192023-06-13
5154BMW Vulnerabilities – Hijack Cars ConnectedDrive™ Service! Clickjacking CSRF BMW Mohamed A. Baset Bug Bounty2016-07-242023-06-13
5153Messenger.com Site-Wide CSRF CSRF Meta / Facebook Jack Whitton (@fin1te) Bug Bounty2016-07-262023-06-13
5137CSRF in partners.facebook.com CSRF Meta / Facebook Prashanth Varma (@cymtrick) Bug Bounty2016-09-202023-06-13
5109Cross Site Request Forgery in Facebook CSRF Meta / Facebook Zahid Ali Bug Bounty2017-02-042023-06-13
5096One company: 262 bugs, 100% acceptance, 2.57 priority, millions of user details saved. Stored XSS Blind XSS CSRF Account takeover IDOR NA Zseano (@zseano) Bug Bounty2017-02-252023-06-13
5065Stored XSS, CSRF And Clickjacking Vulnerabilities in Opera Stored XSS CSRF Clickjacking Opera Rafay Baloch (@rafaybaloch) Bug Bounty2017-06-012023-06-13
5060Let’s steal some tokens! CSRF XSS Account takeover Google Shopify Mahmoud Gamal (@Zombiehelp54) Bug Bounty2017-06-112023-06-13
5058Vulnerability in Metasploit Project aka CVE-2017-5244 CSRF Rapid7 Mohamed A. Baset Bug Bounty2017-06-122023-06-13
5055Authentication bypass on Airbnb via OAuth tokens theft OAuth Login CSRF Open redirect Authentication bypass Airbnb Arne Swinnen (@ArneSwinnen) Bug Bounty2017-06-222023-06-13