Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
5015How I Chained 4 vulnerabilities on GitHub Enterprise, From SSRF Execution Chain to RCE! SSRF RCE CRLF injection Insecure deserialization GitHub Orange Tsai (@orange_8361) Bug Bounty2017-07-282023-06-13
4946CRLF injection in blockchain.info CRLF injection Blockchain.info Shashank (@cyberboyIndia) Bug Bounty2017-11-052023-06-13
4857#BugBounty — Exploiting CRLF Injection can lands into a nice bounty CRLF injection NA Avinash Jain (@logicbomb_1) Bug Bounty2018-02-172023-06-13
4718Setting arbitrary request headers in Chromium via CRLF injection CRLF injection Google Michał Bentkowski (@SecurityMB) Bug Bounty2018-06-202023-06-13
4666CRLF Injection Into PHP’s cURL Options CRLF injection NA TomNomNom (@tomnomnom) Bug Bounty2018-08-012023-06-13
3987CRLF injection allow => cookie injection in root domain & xss CRLF injection Bukalapak Abdelhak Kharroubi Bug Bounty2019-08-062023-06-13
3457How dangerous is Request Splitting, a vulnerability in Golang or how we found the RCE in Portainer and hacked Uber HTTP request splitting SSRF CRLF injection RCE Uber Andrey Abakumov (@andrewaeva) Bug Bounty2020-05-252023-06-13
3426From CRLF to Account Takeover CRLF injection HTTP response splitting Reflected XSS Account takeover NA Valeriy Shevchenko (@Krevetk0Valeriy) Bug Bounty2020-06-032023-06-13
3326From . in regex to SSRF — part 3 SSRF CRLF injection NA Niemiec Marcin (@xvnpw) Bug Bounty2020-07-072023-06-13
2663Breaking GitHub Private Pages for $35k XSS CRLF injection Web cache poisoning GitHub Robert Chen (@NotDeGhost) Bug Bounty2021-04-042023-06-13
2519The beauty of chaining client-side bugs CRLF injection XSS CSP bypass DoS CSTI NA Master SEC (@MasterSEC_AR) Bug Bounty2021-05-292023-06-13
2512CVE-2021-29084: Exploiting CRLF Header Injection in Synology NAS for Unauthenticated File Downloads CRLF injection Synology Justin Taft Bug Bounty2021-06-012023-06-13
1467Zimbra Email - Stealing Clear-Text Credentials via Memcache injection Memcache injection CRLF injection Zimbra Sonar (@SonarSource) Bug Bounty2022-06-142023-06-13
1355CRLF to Account takeover (chaining bugs) CRLF injection XSS Account takeover NA MoSec (@moe1n1) Bug Bounty2022-07-162023-06-13
969$6000 with Microsoft Hall of Fame | Microsoft Firewall Bypass | CRLF to XSS | Microsoft Bug Bounty CRLF injection XSS Microsoft Neh Patel (@thecyberneh) Bug Bounty2022-10-122023-06-13
742Multiple Vulnerabilities in Proxmox VE & Proxmox Mail Gateway XSS CRLF injection SSRF LFI Local Privilege Escalation Arbitrary file read Proxmox JianTao Li (@cursered) Bug Bounty2022-12-022023-06-13
655CRLF Injection — xxx$ — How was it possible for me to earn a bounty with the Cloudflare WAF? CRLF injection NA Proviesec (@proviesec) Bug Bounty2022-12-242023-06-13
428Bypassing Akamai’s Web Application Firewall Using an Injected Content-Encoding Header WAF bypass CRLF injection XSS Akamai Adam Crosser Bug Bounty2023-02-212023-06-13
372Abusing Hop-by-Hop Header to Chain A CRLF Injection Vulnerability CRLF injection Hop-by-hop header XSS NA Simon Bräuer (@redshark1802) Bug Bounty2023-03-012023-06-13
194From payload to 300$ bounty: A story of CRLF injection and responsible disclosure on HackerOne CRLF injection NA Karthikeyan.V (@karthithehacker) Bug Bounty2023-04-162023-06-13
63CVE 2023 25690 - Proof of Concept HTTP Request Smuggling HTTP request splitting CRLF injection Apache HTTP Server dhmosfunk (@DSkfunk) Bug Bounty2023-05-222023-06-13