Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
4829#BugBounty — Rewarded by securing vulnerabilities in Bookmyshow (India’s largest online movie & event booking portal) Host header injection IDOR BookMyShow Avinash Jain (@logicbomb_1) Bug Bounty2018-03-252023-06-13
4441Love Story Of A Account Takeover (Chaining Host Header Injection To Takeover Someones Account) Host header injection NA Logical Bimboo Bug Bounty2018-11-302023-06-13
3929Pwn Them All #BugBounty Host header injection Password reset NA Bilal Khan (@bilalmerokhel) Bug Bounty2019-09-112023-06-13
3784Multiple Host Header Attacks after bypassing protection with… a Header Attack Host header injection NA vict0ni (@vict0ni) Bug Bounty2019-12-122023-06-13
3709How I was able to take over any users account with host header injection Host header injection NA Ajay Gautam (@evilboyajay) Bug Bounty2020-01-232023-06-13
3603How I earned $800 for Host Header Injection Vulnerability Host header injection Password reset NA Pethuraj (@Pethuraj) Bug Bounty2020-03-152023-06-13
3413Different host header injection worth 2k Host header injection NA Imran Nissar (@Imrannissar3) Bug Bounty2020-06-072023-06-13
3334From Host Header injection to SQL injection Host header injection SQL injection NA Daoud Youssef / smacker dodi (@daoud_youssef) Bug Bounty2020-07-052023-06-13
3203Fun with header and forget password, with a twist: Password reset Host header injection NA Vuk Ivanovic Bug Bounty2020-08-182023-06-13
3107ATO via Host Header Poisoning Host header injection Account takeover Password reset NA Shivam Kamboj Dattana (@sechunt3r) Bug Bounty2020-10-082023-06-13
2770Hijacking Reset Password Link in https://www.niteflirt.com/ via Host Header Poising (Write Up) Host header injection Account takeover Password reset Niteflirt Evan Ricafort (@evanricafort) Bug Bounty2021-02-252023-06-13
2767Password Reset Token Leak via X-Forwarded-Host Host header injection Account takeover Password reset NA Saajan Bhujel (@saajanbhujel) Bug Bounty2021-02-262023-06-13
2547Drupal Insecure Default Leads To Password Reset Poisoning Password reset Host header injection Drupal Bogdan Tiron (@Bogdan___T) Bug Bounty2021-05-292023-06-13
2380You’ve Got (a Reset) Mail: A Security Analysis of Email-Based Password Reset Procedures Password reset Host header injection CSRF Account takeover NA Tommaso Innocenti (@innotommy) Bug Bounty2021-07-262023-06-13
2037HTTP Header Injection In Citrix ADC And Citrix Gateway (CVE-2020-8300, CVE-2021-22927) Host header injection XSS Citrix Systems Wolfgang Ettlinger Bug Bounty2021-11-302023-06-13
1932Host Header Injection Lead To Account Takeovers Host header injection Password reset Account takeover NA M7.Arman (@ArmanSecurity) Bug Bounty2022-01-092023-06-13
1875XSS via X-Forwarded-Host header XSS Host header injection Omise Abhijeet Biswas (@abhijeetbiswas_) Bug Bounty2022-01-302023-06-13
1402($$$) Origin ip to account takeover WAF bypass Password reset Host header injection Account takeover NA Hemant Kumar Bug Bounty2022-07-022023-06-13
1308CVE-2022-31813: Forwarding Addresses Is Hard Host header injection DoS IP address spoofing Internet Bug Bounty (Apache HTTPD) Gaetan Ferry (@_mabote_) Bug Bounty2022-07-262023-06-13
1236UN United Nations Host Header Injection leads to any Full Account Takeover (ATO) Host header injection Password reset Account takeover United Nations Ahmed Hassan Bug Bounty2022-08-132023-06-13
504Host Header Injection to Complete Organization takeover SSRF Host header injection Privilege escalation NA Muhammad Umer Adeem Bug Bounty2023-02-022023-06-13