Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
5196How I got access to millions of [redacted] accounts RFI NA Bitquark (@bitquark) Bug Bounty2016-02-092023-06-13
5192Hacking Magento eCommerce For Fun And 17.000 USD Information disclosure LFI RFI Adobe Egidio Romano / EgiX Bug Bounty2016-03-032023-06-13
5168Popping the Pornhub Cherry Information disclosure PornHub Andy Gill (@ZephrFish) Bug Bounty2016-06-072023-06-13
5152CSV Injection -> Meterpreter on Pornhub CSV injection PornHub Andy Gill (@ZephrFish) Bug Bounty2016-07-292023-06-13
5134Persisting on Pornhub Stored XSS PornHub Andy Gill (@ZephrFish) Bug Bounty2016-09-232023-06-13
5132gif it time it%27ll come to you - Finding More Holes in The Hub XSS PornHub Andy Gill (@ZephrFish) Bug Bounty2016-10-012023-06-13
5022May the Shells be with You - A Star Wars RCE Adventure! RCE NA Andy Gill (@ZephrFish) Bug Bounty2017-07-222023-06-13
4741How I Hacked Fotor & Got “Nothing” SSRF RFI Fotor Somdev Sangwan (s0md3v) Bug Bounty2018-06-012023-06-13
4126The Unusual Case of Status code- 301 Redirection to AWS Security Credentials Compromise SSRF RFI NA Avinash Jain (@logicbomb_1) Bug Bounty2019-06-022023-06-13
4065How I escalated RFI into LFI RFI LFI NA Hassan Khan Yusufzai (@Splint3r7) Bug Bounty2019-07-012023-06-13
3111Research: The mass CSRFing of *.google.com/* products. CSRF Google Missoum Said (@missoum1307) Bug Bounty2020-10-072023-06-13
1225URL filter bypass, RFI and XSS Stored XSS RFI NA Bartłomiej Bergier (@_bergee_) Bug Bounty2022-08-142023-06-13
1053Tarfile: Exploiting the World With a 15-Year-Old Vulnerability Path traversal Python Kasimir Schulz (@Abraxus7331) Bug Bounty2022-09-212023-06-13
1050Tarfile: Exploiting the World With a 15-Year-Old Vulnerability Path traversal Python Kasimir Schulz (@Abraxus7331) Bug Bounty2022-09-212023-06-13
701CVE-2022-20942: It%27s not old functionality, it%27s vintage Information disclosure Cisco Silver Security (@SugarFiendSec) Bug Bounty2022-12-132023-06-13
677Cengage LTI Session Management Leakage SSO Session management issue Cengage Tony Porterfield Bug Bounty2022-12-202023-06-13
648How I found multiple critical bugs in Red Bull Authentication bypass HTTP response manipulation Path traversal LFI XSS SQL injection RCE Unrestricted file upload RFI Security code review Red Bull Bartłomiej Bergier (@_bergee_) Bug Bounty2022-12-262023-06-13
286Remote code execution in BIRT Viewer ≤ 4.12.0 (CVE-2023-0100) RCE RFI URL validation bypass Security code review Eclipse Foundation Louis Wolfers (@TG91aXMK) Bug Bounty2023-03-172023-06-13
267Hacking AI: System and Cloud Takeover via MLflow Exploit LFI RFI RCE MLflow Dan McInerney (@DanHMcInerney) Bug Bounty2023-03-252023-06-13