Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
2177Privilege Escalation to stored XSS Privilege escalation HTTP response manipulation Stored XSS NA Rohit Kumar (Rohit_443) Bug Bounty2021-10-012023-06-13
2014Another Admin panel HTTP response manipulation Authentication bypass NA Rizwan_siddiqui (@Rizwan_SiDdiqu1) Bug Bounty2021-12-082023-06-13
1483My first CVE-2022–31289 Authentication bypass 403 bypass HTTP response manipulation Sonatype Praveen Mali (@pmmali_) Bug Bounty2022-06-112023-06-13
1472500$ Account Takeover Account takeover Information disclosure HTTP response manipulation Xsolla Hemant Kumar Bug Bounty2022-06-142023-06-13
1403Vertical Privilege Escalation: The user can takeover an admin account via response manipulation Privilege escalation HTTP response manipulation NA Jan Muhammad Zaidi (@hasanakajan) Bug Bounty2022-07-022023-06-13
1390Account Takeover via Response Manipulation Authentication bypass Account takeover MFA bypass HTTP response manipulation NA BUG HUNTER Bug Bounty2022-07-082023-06-13
1281Hijacking email with Cloudflare Email Routing HTTP response manipulation Privilege escalation NA Albert Pedersen (@AlbertSPedersen) Bug Bounty2022-08-032023-06-13
1004My First And Second Bugs Are — 2FA Bypass MFA bypass HTTP response manipulation Information disclosure NA Jai Niresh J Bug Bounty2022-10-032023-06-13
650Authentication Bypass in Nexus manager (version 3.37.3–02) Components with known vulnerabilities Authentication bypass HTTP response manipulation NA SHARAN.K Bug Bounty2022-12-262023-06-13
648How I found multiple critical bugs in Red Bull Authentication bypass HTTP response manipulation Path traversal LFI XSS SQL injection RCE Unrestricted file upload RFI Security code review Red Bull Bartłomiej Bergier (@_bergee_) Bug Bounty2022-12-262023-06-13
390The Tale of a Command Injection by Changing the Logo RCE OS command injection Unrestricted file upload Directory listing HTTP response manipulation NA 0xrz (@omidxrz) Bug Bounty2023-02-262023-06-13
361Upgrade plan from Free to Paid via Response Manipulation Payment bypass HTTP response manipulation NA Ibrahim Radi (@ibraradi9) Bug Bounty2023-03-032023-06-13
336[Account Takeover] Don’t Send a Message to anyone Before Reading This [External Audit] HTTP response manipulation Authentication bypass Account takeover NA Vipul Sahu Bug Bounty2023-03-072023-06-13
320Improper Authentication in Android App Logic flaw Authentication flaw HTTP response manipulation NA oXnoOneXo Bug Bounty2023-03-102023-06-13
290How I chained multiple High-impact vulnerabilities to create a critical one. Account takeover IDOR OTP bypass HTTP response manipulation NA Vinay Jagetiya (@princej_76) Bug Bounty2023-03-172023-06-13