Writeups
Spotlight
Add Your Writeup
Blogs
Contact Us
Register
Login
Write-ups
Check The Published Writeups
Search
Reset
WDB
Title
Tags
Programs
Authors
Type
Publication
Added
5209
XSS vulnerability in Google image search
XSS
Google
Mahmoud Gamal (@Zombiehelp54)
Bug Bounty
2015-09-18
2023-06-13
5102
SQL injection in an UPDATE query - a bug bounty story!
SQL injection
NA
Mahmoud Gamal (@Zombiehelp54)
Bug Bounty
2017-02-17
2023-06-13
5060
Let’s steal some tokens!
CSRF
XSS
Account takeover
Google
Shopify
Mahmoud Gamal (@Zombiehelp54)
Bug Bounty
2017-06-11
2023-06-13
4675
SQL Injection and A silly WAF
SQL injection
NA
Mahmoud Gamal (@Zombiehelp54)
Bug Bounty
2018-07-25
2023-06-13
4220
Handlebars template injection and RCE in a Shopify app
SSTI
RCE
Shopify
Mahmoud Gamal (@Zombiehelp54)
Bug Bounty
2019-04-04
2023-06-13
3989
Exploiting Out Of Band XXE using internal network and php wrappers
XXE
NA
Mahmoud Gamal (@Zombiehelp54)
Bug Bounty
2019-08-06
2023-06-13
2909
Weblogic Remote Code Execution (Exploiting CVE-2019-2725)
RCE
NA
Mahmoud Gamal (@Zombiehelp54)
Bug Bounty
2021-01-10
2023-06-13
454
SQL Injection: Utilizing XML Functions in Oracle and PostgreSQL to bypass WAFs
SQL injection
WAF bypass
NA
Mahmoud Gamal (@Zombiehelp54)
Bug Bounty
2023-02-13
2023-06-13
166
Exploits Explained: Permission misconfiguration within Salesforce JavaScript Remoting tokens used for Apex Controllers
Salesforce
Security misconfiguration
Broken Access Control
NA
Mahmoud Gamal (@Zombiehelp54)
Bug Bounty
2023-04-21
2023-06-13