Writeups
Spotlight
Add Your Writeup
Blogs
Contact Us
Register
Login
Write-ups
Check The Published Writeups
Search
Reset
WDB
Title
Tags
Programs
Authors
Type
Publication
Added
3814
IDOR via Websockets
IDOR
NA
Shuaib Oladigbolu (@_sawzeeyy)
Bug Bounty
2019-11-23
2023-06-13
2809
IDOR via Websockets allow me to takeover any users account
IDOR
NA
Mohsin Khan (@tabaahi_)
Bug Bounty
2021-02-14
2023-06-13
2044
[socket.io] Cross-Site Websockets Hijacking
Cross-Site Websocket Hijacking (CSWH)
Node.js third-party modules
sh1yo (@sh1yo_)
Bug Bounty
2021-11-29
2023-06-13
1540
Gaining access through error-based SQLi using WebSockets
SQL injection
Websockets
Password reset
NA
Bitcrack (@bitcrack_cyber)
Bug Bounty
2022-01-12
2023-06-13
693
CVE-2021-43444 to 43449: Exploiting ONLYOFFICE Web Sockets for Unauthenticated Remote Code Execution
Websockets
RCE
Arbitrary file write
Path traversal
OnlyOffice
Iain Wallace (@strawp)
Bug Bounty
2022-12-14
2023-06-13
691
CVE-2021-43444 to 43449: Exploiting ONLYOFFICE Web Sockets for Unauthenticated Remote Code Execution
Websockets
XSS
RCE
Arbitrary file write
Path traversal
OnlyOffice
Iain Wallace (@strawp)
Bug Bounty
2022-12-14
2023-06-13
410
Decoding BlazorPack
Websockets
NA
Rogan Dawes (@RoganDawes)
Bug Bounty
2023-02-22
2023-06-13
371
Gitpod remote code execution 0-day vulnerability via WebSockets
RCE
Websockets
Cross-Site WebSocket Hijacking (CSWH)
Cloud
Samesite cookie bypass
Account takeover
Gitpod
Elliot Ward
Bug Bounty
2023-03-01
2023-06-13
293
CHECKMATE
Websockets
Logic flaw
Chess.com
Oded Vaanunu
Bug Bounty
2023-03-16
2023-06-13
101
Rendezvous with a Chatbot: Chaining Contextual Risk Vulnerabilities
Chatbot
Websockets
Cross-Site WebSocket Hijacking (CSWH)
Captcha bypass
NA
Abeer Banerjee (@bugasur)
Bug Bounty
2023-05-11
2023-06-13