Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
3018Server Side Misconfigurartion - A Funny Fix Information disclosure Basecamp Jerry Shah (@Jerry) Bug Bounty2020-11-182023-06-13
2984RCE via LFI Log Poisoning - The Death Potion RCE LFI Log poisoning NA Jerry Shah (@Jerry) Bug Bounty2020-12-062023-06-13
2904CSRF with IDOR - A Deadly Combo CSRF IDOR NA Jerry Shah (@Jerry) Bug Bounty2021-01-122023-06-13
2828Duplicate Registration - The Twinning Twins Account takeover Authentication flaw NA Jerry Shah (@Jerry) Bug Bounty2021-02-082023-06-13
2766Account Takeover - Smoking with null’ Account takeover Authentication flaw NA Jerry Shah (@Jerry) Bug Bounty2021-02-262023-06-13
2700Cross Site Port Attack - A Stranger’s Call XSPA NA Jerry Shah (@Jerry) Bug Bounty2021-03-212023-06-13
2633XSS via Exif Data - The P2 Elevator Stored XSS NA Jerry Shah (@Jerry) Bug Bounty2021-04-182023-06-13
2505Server Side Request Forgery - A Forged Document SSRF File upload NA Jerry Shah (@Jerry) Bug Bounty2021-06-032023-06-13
2482Blind Command Injection - It hurts Command injection RCE NA Jerry Shah (@Jerry) Bug Bounty2021-06-142023-06-13
2450PII Leakage - Revealing Secrets Information disclosure NA Jerry Shah (@Jerry) Bug Bounty2021-06-252023-06-13
2403RCE via WebDav - Power Of PUT Default credentials RCE NA Jerry Shah (@Jerry) Bug Bounty2021-07-182023-06-13
2251Business Logic Errors - Must Vote Logic flaw NA Jerry Shah (@Jerry) Bug Bounty2021-09-052023-06-13
2144Business Logic Errors - A Logic Destruction Logic flaw NA Jerry Shah (@Jerry) Bug Bounty2021-10-172023-06-13
2003Open Redirection - QR Code Magic Open redirect NA Jerry Shah (@Jerry) Bug Bounty2021-12-112023-06-13
1942SQL Injection - The File Upload Playground Unrestricted file upload SQL injection NA Jerry Shah (@Jerry) Bug Bounty2022-01-042023-06-13
1824Broken Link Hijacking - Mr. User-Agent Broken link hijacking NA Jerry Shah (@Jerry) Bug Bounty2022-02-132023-06-13
1722Parameter Pollution - Zero Day HTTP parameter pollution Discourse Jerry Shah (@Jerry) Bug Bounty2022-03-172023-06-13
1636XSS - The LocalStorage Robbery XSS NA Jerry Shah (@Jerry) Bug Bounty2022-04-122023-06-13
1579Business Logic Errors - Art of Testing Cards Payment bypass Logic flaw NA Jerry Shah (@Jerry) Bug Bounty2022-05-042023-06-13
1307HTTP Parameter Pollution - It’s Contaminated Again HTTP parameter pollution Rate limiting bypass NA Jerry Shah (@Jerry) Bug Bounty2022-07-262023-06-13
735Account Takeover - Inside The Tenant Account takeover Information disclosure NA Jerry Shah (@Jerry) Bug Bounty2022-12-032023-06-13
570API Misconfiguration - No Swag of SwaggerUI Security misconfiguration Privilege escalation NA Jerry Shah (@Jerry) Bug Bounty2023-01-192023-06-13
505IDOR - Inside the Session Storage IDOR NA Jerry Shah (@Jerry) Bug Bounty2023-02-022023-06-13
297LFI - An Interesting Tweak LFI NA Jerry Shah (@Jerry) Bug Bounty2023-03-152023-06-13
217SQL Wildcard DoS - Hang Till Death DoS File upload NA Jerry Shah (@Jerry) Bug Bounty2023-04-082023-06-13