Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
5204Arbitary File Upload Vulnerability in Google Nest (Write Up) Unrestricted file upload Stored XSS Google Evan Ricafort (@evanricafort) Bug Bounty2015-12-212023-06-13
5203Local File XSS Vulnerability in Wordpress.com (Write Up) XSS WordPress Evan Ricafort (@evanricafort) Bug Bounty2015-12-212023-06-13
5133XSS Vulnerability in Twitter [https://twitter.com] (Write Up) XSS Twitter Evan Ricafort (@evanricafort) Bug Bounty2016-09-262023-06-13
4853[RCE] Remote Code Execution in Wordpress iOS Application (version 9.3) RCE iOS WordPress Evan Ricafort (@evanricafort) Bug Bounty2018-02-212023-06-13
4661Blind-XSS in Chrome Experiments - Google (Write Up) Blind XSS Google Evan Ricafort (@evanricafort) Bug Bounty2018-08-032023-06-13
4659Blind-XSS in Chrome Experiments - Google (Write Up) Blind XSS Google Evan Ricafort (@evanricafort) Bug Bounty2018-08-032023-06-13
4022Not a fancy bug, just HTML Injection in Clause - clause.io (Write Up) HTML injection Clause Evan Ricafort (@evanricafort) Bug Bounty2019-07-212023-06-13
4017Disclose any main and 3rd party contributors email address and movie local path thru XML file in Plex TV - plex.tv (Write Up) Information disclosure Internal path disclosure Plex Evan Ricafort (@evanricafort) Bug Bounty2019-07-242023-06-13
3982Read other user support tickets in https://support..com (Write Up) IDOR NA Evan Ricafort (@evanricafort) Bug Bounty2019-08-092023-06-13
3980Application Level Denial of Service [DoS] using SVG file in https://[REDACTED].com (Write Up) Application-level DoS NA Evan Ricafort (@evanricafort) Bug Bounty2019-08-102023-06-13
3977SSRF Vulnerability in https://app.[REDACTED].com SSRF NA Evan Ricafort (@evanricafort) Bug Bounty2019-08-132023-06-13
3796HTML Injection to XSS bypass in [REDACTED.com] Reflected XSS NA Evan Ricafort (@evanricafort) Bug Bounty2019-12-072023-06-13
3677Popping Alerts in Mixmax Chrome Extension (Write Up) XSS Mixmax Evan Ricafort (@evanricafort) Bug Bounty2020-02-062023-06-13
3526XSS in Peerio 2 Windows Application (Write Up) XSS Peerio Evan Ricafort (@evanricafort) Bug Bounty2020-04-242023-06-13
2983[CVE-2019-17674 & CVE-2020-11025] Stored XSS through navigation menu item edited in Customizer in Wordpress (Write Up) Stored XSS WordPress Evan Ricafort (@evanricafort) Bug Bounty2020-12-062023-06-13
2811Changing other users Episode title & description - IDOR Vulnerability in [REDACTED] (Write Up) IDOR NA Evan Ricafort (@evanricafort) Bug Bounty2021-02-132023-06-13
2770Hijacking Reset Password Link in https://www.niteflirt.com/ via Host Header Poising (Write Up) Host header injection Account takeover Password reset Niteflirt Evan Ricafort (@evanricafort) Bug Bounty2021-02-252023-06-13
25652FA Verification Bypass in Shapeshift [shapeshift.com] (Write Up) MFA bypass Shapeshift Evan Ricafort (@evanricafort) Bug Bounty2021-05-102023-06-13
2492Unexpected IDOR Vulnerability in [REDACTED] - [redacted].net (Write Up) IDOR NA Evan Ricafort (@evanricafort) Bug Bounty2021-06-102023-06-13
2470HTML Injection and a dream in Google Chrome for Linux (Write Up) HTML injection Google Evan Ricafort (@evanricafort) Bug Bounty2021-06-172023-06-13
2457Generate online votes using Race Condition Vulnerability in Woobox Web Application (Write Up) Race condition Woobox Evan Ricafort (@evanricafort) Bug Bounty2021-06-232023-06-13
113IPv6 DNS Takeover via mitm6 (Write Up) MiTM IPv6 DNS takeover Misconfigured LDAP server Internal pentest NA Evan Ricafort (@evanricafort) Bug Bounty2023-05-082023-06-13