Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
5286Google.com cross site scripting and privilege escalation in Consumer Surveys Stored XSS Authorization flaw Google Josip Franjkovic (@josipfranjkovic) Bug Bounty2013-01-032023-06-13
5275How I found my way into Instagram%27s Ganglia, and a bug with Facebook likes. Reflected XSS IDOR Meta / Facebook Josip Franjkovic (@josipfranjkovic) Bug Bounty2013-07-232023-06-13
5274SQL injections in Nokia sites. SQL injection Nokia Josip Franjkovic (@josipfranjkovic) Bug Bounty2013-07-302023-06-13
5269Facebook CSRF leading to full account takeover (fixed) CSRF Account takeover Meta / Facebook Josip Franjkovic (@josipfranjkovic) Bug Bounty2013-10-182023-06-13
5267Facebook bug bounty: secondary damage (one report that leads to more bugs), fairness, and why I really like reporting to Facebook CSRF Meta / Facebook Josip Franjkovic (@josipfranjkovic) Bug Bounty2013-10-212023-06-13
5241Step-by-step: exploiting SQL injection(s) in Oculus%27 website. SQL injection Meta / Facebook Josip Franjkovic (@josipfranjkovic) Bug Bounty2014-09-052023-06-13
5233Reading local files from Facebook%27s server (fixed) LFI Unrestricted file upload Meta / Facebook Josip Franjkovic (@josipfranjkovic) Bug Bounty2014-12-062023-06-13
5219Race conditions on Facebook, DigitalOcean and others (fixed) Race condition Meta / Facebook DigitalOcean LastPass Josip Franjkovic (@josipfranjkovic) Bug Bounty2015-04-272023-06-13
5216The easiest bug bounties I have ever won IDOR Meta / Facebook Josip Franjkovic (@josipfranjkovic) Bug Bounty2015-07-132023-06-13
5161Race conditions on the web Race condition Cobalt.io Meta / Facebook MEGA Keybase Josip Franjkovic (@josipfranjkovic) Bug Bounty2016-07-122023-06-13
5159Stealing Facebook access_tokens using CSRF in device login flow CSRF OAuth Information disclosure Meta / Facebook Josip Franjkovic (@josipfranjkovic) Bug Bounty2016-07-192023-06-13
4895Hacking Facebook accounts using CSRF in Oculus-Facebook integration CSRF Meta / Facebook Josip Franjkovic (@josipfranjkovic) Bug Bounty2018-01-152023-06-13
4865Taking over Facebook accounts using Free Basics partner portal Information disclosure IDOR Meta / Facebook Josip Franjkovic (@josipfranjkovic) Bug Bounty2018-02-072023-06-13
4838Getting any Facebook user%27s friend list and partial payment card details Information disclosure IDOR Meta / Facebook Josip Franjkovic (@josipfranjkovic) Bug Bounty2018-03-092023-06-13