Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
3700Tale of a Misconfiguration in Password Reset Password reset Information disclosure NA Naveenroy Bug Bounty2020-01-272023-06-13
2830Reflected XSS on a Public Program Reflected XSS NA Naveen J (@thevillagehackr) Bug Bounty2021-02-082023-06-13
2782Account Take Over by Response Manipulation Authentication bypass Account takeover NA Naveen J (@thevillagehackr) Bug Bounty2021-02-172023-06-13
2721Finding keys under the door Stored XSS Unrestricted file upload Paytm Naveen Prakaasham K S V Bug Bounty2021-03-122023-06-13
2551How i hijacked 12 Subdomains in one Program Subdomain takeover NA Naveen kumawat (@nvk0x) Bug Bounty2021-05-172023-06-13
2543Time-Based SQL Injection to Dumping the Database SQL injection Android NA Naveen J (@thevillagehackr) Bug Bounty2021-05-192023-06-13
2312Disclose WhatsApp Number of Instagram Accounts Despite Setting Set to be Hidden Information disclosure Logic flaw Meta / Facebook Naveen (@NaveenHax) Bug Bounty2021-08-192023-06-13
2295Retrieve Archived Stories Of Any Public Instagram Account. IDOR GraphQL Meta / Facebook Naveen Bug Bounty2021-08-252023-06-13
2028Disclose Ad Accounts linked with Instagram Accounts Information disclosure Logic flaw GraphQL Meta / Facebook Naveen (@NaveenHax) Bug Bounty2021-12-022023-06-13
1711Broken session control leads to access private videos using the shared link even after revoking the access for specific time!! — #GoogleVRP Broken Access Control Google Naveenroy Bug Bounty2022-03-202023-06-13
1637Broken session control leads to access the admin panel even after revoking the access!! — #ZOHO Broken Access Control Zoho Naveenroy Bug Bounty2022-04-122023-06-13
1578Remotely permanent crash any Instagram user via permanent DoS in user DM%27s. DoS Meta / Facebook Naveen (@NaveenHax) Bug Bounty2022-05-042023-06-13
1411CVE-2022-28219: Unauthenticated XXE to RCE and Domain Compromise in ManageEngine ADAudit Plus XXE SSRF RCE Zoho Naveen Sunkavally Bug Bounty2022-06-292023-06-13
1329Permanent Crash Instagram Followers. DoS Meta / Facebook Naveen (@NaveenHax) Bug Bounty2022-07-222023-06-13
158CVE-2023-27524: Insecure Default Configuration in Apache Superset Leads to Remote Code Execution RCE Default Flask Secret Key Hardcoded credentials Apache Superset Naveen Sunkavally Bug Bounty2023-04-252023-06-13