Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
4565Arbitrary File Read in one of the largest CRMs LFI NA Richard Clifford (@MantisSTS) Bug Bounty2018-09-262023-06-13
4123Chaining multiple low-impact bugs to arbitrary file read in GitLab Path traversal GitLab Li Rongxi (@nyan_gawa) Bug Bounty2019-06-042023-06-13
3668CVE-2019-18426 - WhatsApp Vulnerabilities Disclosure - Open Redirect + CSP Bypass + Persistent XSS + FS read permissions + potential for RCE RCE Stored XSS CSP bypass Arbitrary file read Open redirect Security code review Meta / Facebook (WhatsApp) Gal Weizman (@WeizmanGal) Bug Bounty2020-02-142023-06-13
3022Firefox: How a website could steal all your cookies Arbitrary file read Mozilla Pedro Oliveira (@kanytu) Bug Bounty2020-11-162023-06-13
3020OpenEMR 5.0.1.3 Arbitrary File Actions Arbitrary file write Arbitrary file read Security code review OpenEMR Josh Fam (@Pullerze) Bug Bounty2020-11-172023-06-13
2834Facebook Messenger Desktop App Arbitrary File Read Arbitrary file read Meta / Facebook Renwa (@RenwaX23) Bug Bounty2021-02-042023-06-13
2614Brave — Stealing your cookies remotely Arbitrary file read Brave Software Pedro Oliveira (@kanytu) Bug Bounty2021-04-222023-06-13
2525GitLab Arbitrary File Read & Write through Kroki - CVE-2021-22203 Arbitrary file read NA Anh Duc Nguyen (@ledz1996) Bug Bounty2021-05-252023-06-13
2504Android: Exploring vulnerabilities in WebResourceResponse Arbitrary file read Android Amazon Oversecured (@OversecuredInc) Bug Bounty2021-06-032023-06-13
2444Escalating XSS to Arbitrary File Read XSS LFI NA Pethuraj (@Pethuraj) Bug Bounty2021-06-272023-06-13
2334OVE-20210809-0001 Visual Studio Code .ipynb Jupyter Notebook XSS (Arbitrary File Read) XSS Arbitrary file read Microsoft Justin Steven (@justinsteven) Bug Bounty2021-08-112023-06-13
2318Two weeks of securing Samsung devices: Part 2 Arbitrary file write Arbitrary file read Vulnerable Android content provider Android Samsung Oversecured (@OversecuredInc) Bug Bounty2021-08-162023-06-13
2069Write Up – Apple N/A: PII Information, Full Contact List, Main Phone No. And Main Icloud Email Extracted; Bug Patched: Arbitrary Local File Read Via Zip File And Symlinks On Ios Files App. Arbitrary file read Apple Omar Espino (@omespino) Bug Bounty2021-11-172023-06-13
2040NodeBB 1.18.4 - Remote Code Execution With One Shot RCE XSS Authentication bypass Arbitrary file read NodeBB Sonar (@SonarSource) Bug Bounty2021-11-302023-06-13
2038VMware vCenter earlier versions (7.0.2.00100) has unauthorized arbitrary file read + ssrf + xss vulnerability LFI SSRF XSS Arbitrary file read VMware Khoa Dinh (@_l0gg) Bug Bounty2021-11-302023-06-13
1832How I hacked Google to read files from their servers for free! Arbitrary file read Google Harish SG (@CoderHarish) Bug Bounty2022-02-092023-06-13
1698Finding bugs to trigger Unauthenticated Command Injection in a NETGEAR router (PSV-2022–0044) XSS Arbitrary file read Authentication bypass OS command injection RCE Netgear stypr (@stereotype32) Bug Bounty2022-03-252023-06-13
1436CVE-2022-31749: WatchGuard Authenticated Arbitrary File Read/Write (Fixed) Argument injection WatchGuard Jake Baines (@Junior_Baines) Bug Bounty2022-06-232023-06-13
1268From Shodan to RCE: That one time I hacked a Fortune 500 company. Missing authentication Arbitrary file read RCE Exposed Jenkins instance NA vimanari_ (@vimanari_) Bug Bounty2022-08-082023-06-13
1177Chaining Telegram bugs to steal session-related files. Arbitrary file read Android Telegram Sayed Abdelhafiz (@dPhoeniixx) Bug Bounty2022-08-252023-06-13
1100Riding The Inforail To Exploit Ivanti Avalanche Part 2 RCE Insecure deserialization Path traversal Authentication bypass Unrestricted file upload Arbitrary file write Arbitrary file read Ivanti Piotr Bazydło (@chudyPB) Bug Bounty2021-09-082023-06-13
1046Exploiting Distroless Images Command injection Arbitrary file read Arbitrary file write Container escape Google Daniel Teixeira (@TheRedOperator) Bug Bounty2022-09-222023-06-13
933Second Order XXE Exploitation XXE Arbitrary file read NA Kuldeep Pandya (@kuldeepdotexe) Bug Bounty2022-10-192023-06-13
906GL.iNET GL-MT300N-V2 Router Vulnerabilities and Hardware Teardown OS command injection Arbitrary file read Information disclosure Account takeover Stored XSS Lack of rate limiting Weak credentials Password policy bypass GL.iNet Olivier Laflamme (@olivier_boschko) Bug Bounty2022-10-262023-06-13
895Visual Studio Code Jupyter Notebook RCE RCE XSS Arbitrary file read Electron Microsoft Luca Carettoni (@lucacarettoni) Bug Bounty2022-10-272023-06-13