Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
5250Facebook – Send Notifications to any User Exploit Logic flaw Meta / Facebook Brett Buerhaus (@bbuerhaus) Bug Bounty2014-04-072023-06-13
5244Facebook – Stored Cross-Site Scripting (XSS) – Badges Stored XSS Meta / Facebook Brett Buerhaus (@bbuerhaus) Bug Bounty2014-06-162023-06-13
5227Yahoo – Root Access SQL Injection – tw.yahoo.com SQL injection Yahoo! / Verizon Media Brett Buerhaus (@bbuerhaus) Bug Bounty2015-01-152023-06-13
5225admin.google.com Reflected Cross-Site Scripting (XSS) Reflected XSS Google Brett Buerhaus (@bbuerhaus) Bug Bounty2015-01-212023-06-13
5224Flickr API Explorer – Force users to execute any API request. CSRF Flickr Brett Buerhaus (@bbuerhaus) Bug Bounty2015-02-032023-06-13
5223Google.com – Mobile Feedback URL Redirect Regex/Validation Flaw Open redirect Google Brett Buerhaus (@bbuerhaus) Bug Bounty2015-02-032023-06-13
5184Yahoo Login Protection Seal – Stored CSS Injection CSS injection Yahoo! / Verizon Media Brett Buerhaus (@bbuerhaus) Bug Bounty2016-04-182023-06-13
5183ESEA Server-Side Request Forgery and Querying AWS Meta Data SSRF ESEA Brett Buerhaus (@bbuerhaus) Bug Bounty2016-04-182023-06-13
5092Airbnb – When Bypassing JSON Encoding, XSS Filter, WAF, CSP, and Auditor turns into Eight Vulnerabilities XSS CSP bypass Airbnb Brett Buerhaus (@bbuerhaus) Bug Bounty2017-03-082023-06-13
5091Airbnb – Chaining Third-Party Open Redirect into Server-Side Request Forgery (SSRF) via LivePerson Chat Open redirect SSRF Path traversal Airbnb Brett Buerhaus (@bbuerhaus) Bug Bounty2017-03-092023-06-13
5088Airbnb – Ruby on Rails String Interpolation led to Remote Code Execution RCE Airbnb Brett Buerhaus (@bbuerhaus) Bug Bounty2017-03-132023-06-13
5082Airbnb – Web to App Phone Notification IDOR to view Everyone’s Airbnb Messages IDOR Airbnb Brett Buerhaus (@bbuerhaus) Bug Bounty2017-03-312023-06-13
5048Escalating XSS in PhantomJS Image Rendering to SSRF/Local-File Read XSS SSRF LFI NA Brett Buerhaus (@bbuerhaus) Bug Bounty2017-06-292023-06-13
3875A Tale of Exploitation in Spreadsheet File Conversions Local file disclosure (LFD) SSRF Slack Brett Buerhaus (@bbuerhaus) Bug Bounty2019-10-182023-06-13