Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
5112How I could have compromised any account on one of the biggest startup based in California Account takeover IDOR Password reset NA Prateek Tiwari (@prateek_0490) Bug Bounty2017-01-282023-06-13
4914Don%27t Trust the Host Header for Sending Password Reset Emails Password reset Account takeover Mavenlink Jack Cable (@jackhcable) Bug Bounty2017-12-132023-06-13
4835#BugBounty — “Let me reset your password and login into your account “-How I was able to Compromise any User Account via Reset Password Functionality Logic flaw Password reset Account takeover NA Avinash Jain (@logicbomb_1) Bug Bounty2018-03-142023-06-13
4763How i HACKED admin account via password reset IDOR function of one private currency exchanger site IDOR Account takeover Password reset NA Aayush Pokhrel (@aayushpok) Bug Bounty2018-05-192023-06-13
4755#BugBounty — "How I was able to hack any user account via password reset?" IDOR Account takeover Password reset NA Bikash Gupta (@BgxDoc) Bug Bounty2018-05-232023-06-13
4729Full account Takeover via reset password function IDOR Account takeover Password reset NA Khaled Hassan Bug Bounty2018-06-122023-06-13
4721[Responsible disclosure] How I could have booked movie tickets through other user accounts Password reset Account takeover Bruteforce OTP bypass AGS Cinemas Bharathvaj Ganesan Bug Bounty2018-06-182023-06-13
4712Account Take over via reset password Password reset Account takeover NA Yasser Gersy (@yassergersy) Bug Bounty2018-06-252023-06-13
4699#BugBounty - Compromising User Account- "How I was able to compromise user account via HTTP Parameter Pollution(HPP)" HTTP parameter pollution Password reset Account takeover NA Avinash Jain (@logicbomb_1) Bug Bounty2018-07-072023-06-13
4651From data leak to account takeover Account takeover Information disclosure Password reset NA Antony Garand (@AntoGarand) Bug Bounty2018-08-072023-06-13
4649My First Critical Report Password reset Account takeover NA Miguel Corral (@mcorral74) Bug Bounty2018-08-082023-06-13
4395Tokopedia Account Takeover Bug Worth 8 Million IDR Password reset Account takeover Tokopedia Mukul Lohar (@ironfisto) Bug Bounty2018-12-242023-06-13
4385Tale of a Misconfiguration in Password Reset Password reset NA Shuaib Oladigbolu (@_sawzeeyy) Bug Bounty2018-12-302023-06-13
4250User Account Takeover [Password Change]— Nice Catch! Account takeover Password reset NA Rohit kumar (@rohitcoder) Bug Bounty2019-03-142023-06-13
4080Password Reset Vulnerability — Full Account takeover (Insecure Direct Object Reference) Password reset IDOR Account takeover NA Muhammad Asim Shahzad (@protector47) Bug Bounty2019-06-222023-06-13
4032Account Takeover Vulnerability :) Password reset Account takeover NA Sumit Jain (@sumit_cfe) Bug Bounty2019-07-172023-06-13
4016How I found the most critical bug in live bug bounty event? Password reset Account takeover NA Lakshay (@inn0c3ntd3v1L) Bug Bounty2019-07-242023-06-13
4014Full Account Takeover via Changing Email And Password of any User through API Parameters IDOR Password reset Account takeover NA Adesh Nandkishor kolte (@AdeshKolte) Bug Bounty2019-07-262023-06-13
3970How I was able to earn 1000$ with just 10 minutes of bug bounty? Password reset NA Ninad Mathpati (@ninad_mathpati) Bug Bounty2019-08-172023-06-13
3954How I Hacked Instagram Again Password reset Account takeover Meta / Facebook Laxman Muthiyah (@LaxmanMuthiyah) Bug Bounty2019-08-262023-06-13
3941Readme.com Account Takeover Password reset Readme.com Ankush Goel (@0xankush) Bug Bounty2019-09-052023-06-13
3929Pwn Them All #BugBounty Host header injection Password reset NA Bilal Khan (@bilalmerokhel) Bug Bounty2019-09-112023-06-13
3770Account Takeover Through Password Reset Poisoning Password reset Account takeover NA Vishal Bharad Bug Bounty2019-12-192023-06-13
3723How I discovered an interesting account takeover flaw? Account takeover Password reset Lack of rate limiting NA Akash Methani (@0xAkash) Bug Bounty2020-01-142023-06-13
3712Password Reset Token Leak Via Referrer Password reset Information disclosure NA Shrey Shah (@ShreySh43332033) Bug Bounty2020-01-222023-06-13