Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
5298Resources for Application Security Application Security N/A Ishaq Mohammed CheatSheet2018-08-272024-01-31
5296Resources for Application Security Application Security N/A Ishaq Mohammed CheatSheet2018-08-272024-01-31
5290Facebook XSS via Cross-Origin Resource Sharing XSS Meta / Facebook Matt Austin (@mattaustin) Bug Bounty2010-07-062023-06-13
5253GitHub RCE Writeup RCE GitHub joernchen (@joernchen) Bug Bounty2014-02-222023-06-13
5248Magix Bug Bounty: magix.com (RCE, SQLi) and xara.com (LFI, XSS) RCE SQL injection LFI XSS Magix Julien Ahrens (@MrTuxracer) Bug Bounty2014-04-262023-06-13
5242Popping a shell on the Oculus developer portal SQL injection CSRF RCE IDOR Meta / Facebook Bitquark (@bitquark) Bug Bounty2014-08-312023-06-13
5224Flickr API Explorer – Force users to execute any API request. CSRF Flickr Brett Buerhaus (@bbuerhaus) Bug Bounty2015-02-032023-06-13
5210XSS to RCE in ... XSS RCE NA Neil Hakuna Matatall (@ndm) Bug Bounty2015-09-082023-06-13
5207XSS to RCE in Atlassian Hipchat XSS RCE Atlassian Matt Austin (@mattaustin) Bug Bounty2015-11-152023-06-13
5205How To Hack PayU – And Buy 10x More For The Same Price RCE PayU Rick Harris (@codel10n) Bug Bounty2015-12-182023-06-13
5202Instagram%27s Million Dollar Bug RCE Meta / Facebook Wesley Wineberg Bug Bounty2015-12-272023-06-13
5199[manager.paypal.com] Remote Code Execution Vulnerability RCE Paypal Michael Stepankin (@artsploit) Bug Bounty2016-01-252023-06-13
5192Hacking Magento eCommerce For Fun And 17.000 USD Information disclosure LFI RFI Adobe Egidio Romano / EgiX Bug Bounty2016-03-032023-06-13
5170InstaBrute: Two Ways to Brute-force Instagram Account Credentials Bruteforce Username enumeration Meta / Facebook Arne Swinnen (@ArneSwinnen) Bug Bounty2016-05-192023-06-13
5163Uber Hacking: How we found out who you are, where you are and where you went Bruteforce Information disclosure Logic flaw IDOR Uber Vitor “r0t” Oliveira (@r0t1v) Bug Bounty2016-06-242023-06-13
5158Blind XSS in Spotify%27s Salesforce Integration Blind XSS Salesforce Spotify Mohammed Diaa (@mhmdiaa) Bug Bounty2016-07-192023-06-13
5157Twitter%27s Vine Source code dump - $10080 Source code disclosure Information disclosure Twitter avicoder (@avicoder) Bug Bounty2016-07-222023-06-13
5156How we broke PHP, hacked Pornhub and earned $20,000 RCE Memory corruption Use-After-Free PornHub Ruslan Habalov (@evonide) Bug Bounty2016-07-232023-06-13
5155Remote Code Execution (RCE) on Microsoft%27s %27signout.live.com%27 RCE Microsoft Peter Adkins (@darkarnium) Bug Bounty2016-07-242023-06-13
5147[demo.paypal.com] Node.js code injection (RCE) RCE Paypal Michael Stepankin (@artsploit) Bug Bounty2016-08-192023-06-13
5143RCE In AddThis RCE AddThis whitehatnepal Bug Bounty2016-09-042023-06-13
5127Hacking JasperReports – The Hidden Shell Feature RCE NA Steve Breen (@breenmachine) Bug Bounty2016-10-142023-06-13
5119Atom.io Misconfiguration Allowed Code Execution on Untrusted Networks RCE GitHub Adam Baldwin (@adam_baldwin) Bug Bounty2016-11-302023-06-13
5110Spring Boot RCE RCE SpEL injection Spring Boot NA Tushar (@0xdeadpool) Bug Bounty2017-02-022023-06-13
5100How I was able to remove your Instagram Phone number Bruteforce Meta / Facebook Neeraj Sonaniya (@neeraj_sonaniya) Bug Bounty2017-02-202023-06-13