Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
5183ESEA Server-Side Request Forgery and Querying AWS Meta Data SSRF ESEA Brett Buerhaus (@bbuerhaus) Bug Bounty2016-04-182023-06-13
5093Ok Google, Give Me All Your Internal DNS Information! SSRF Google Julien Ahrens (@MrTuxracer) Bug Bounty2017-03-012023-06-13
5091Airbnb – Chaining Third-Party Open Redirect into Server-Side Request Forgery (SSRF) via LivePerson Chat Open redirect SSRF Path traversal Airbnb Brett Buerhaus (@bbuerhaus) Bug Bounty2017-03-092023-06-13
5074A pair of Plotly bugs: Stored XSS and AWS Metadata SSRF Stored XSS SSRF Plotly Yasin Soliman (@SecurityYasin) Bug Bounty2017-05-252023-06-13
5073Pivoting from blind SSRF to RCE with HashiCorp Consul Blind XSS RCE NA Peter Adkins (@darkarnium) Bug Bounty2017-05-292023-06-13
5053Yahoo Small Business (Luminate) and the Not-So-Secret Keys Blind SSRF Yahoo! / Verizon Media Tommy DeVoss / dawgyg (@thedawgyg) Bug Bounty2017-06-232023-06-13
5048Escalating XSS in PhantomJS Image Rendering to SSRF/Local-File Read XSS SSRF LFI NA Brett Buerhaus (@bbuerhaus) Bug Bounty2017-06-292023-06-13
5016Cracking the lens: targeting HTTP%27s hidden attack-surface Reflected XSS SSRF Yahoo! / Verizon Media BT New Relic James Kettle (@albinowax) Bug Bounty2017-07-272023-06-13
5015How I Chained 4 vulnerabilities on GitHub Enterprise, From SSRF Execution Chain to RCE! SSRF RCE CRLF injection Insecure deserialization GitHub Orange Tsai (@orange_8361) Bug Bounty2017-07-282023-06-13
4979Exploiting a Single Request for Multiple Vulnerabilities Stored XSS Reflected XSS SSRF OS command injection NA Osama Ansari (@AnsariOsama10) Bug Bounty2017-09-192023-06-13
4957Reading Internal Files using SSRF vulnerability SSRF NA Neeraj Sonaniya (@neeraj_sonaniya) Bug Bounty2017-10-162023-06-13
4953How i found an SSRF in Yahoo! Guesthouse (Recon Wins) SSRF Yahoo! / Verizon Media Th3G3nt3lman (@Th3G3nt3lman) Bug Bounty2017-10-202023-06-13
4942From SSRF to Local File Disclosure SSRF Local file disclosure (LFD) NA Tung Pun Bug Bounty2017-11-082023-06-13
4917Bug Bounty: Fastmail Blind SSRF Blind XXE Fastmail Brian Hyde (@0xHyde) Bug Bounty2017-12-082023-06-13
4913Hacking the Hackers: Leveraging an SSRF in HackerTarget SSRF HackerTarget Corben Leo (@hacker_) Bug Bounty2017-12-172023-06-13
4910P4 to P2 - The story of one blind SSRF Blind SSRF NA Mikhail Klyuchnikov (@__Mn1__) Bug Bounty2017-12-192023-06-13
4906How I found SSRF on TheFacebook.com SSRF Meta / Facebook Thunder Bug Bounty2017-12-272023-06-13
4839Stored XSS, and SSRF in Google using the Dataset Publishing Language Stored XSS SSRF Google Craig Arendt (@signalchaos) Bug Bounty2018-03-072023-06-13
4818Beyond XSS: Edge Side Include Injection ESI injection SSRF XSS Squid Varnish Louis Dion-Marcil (@ldionmarcil) Bug Bounty2018-04-032023-06-13
4814“Exploiting a Single Parameter” SSRF XSS NA Hisham Mir (@Hishammir1) Bug Bounty2018-04-062023-06-13
4811Piercing the veil: Server Side Request Forgery to NIPRNet access SSRF U.S. Dept Of Defense Alyssa Herrera (@Alyssa_Herrera_) Bug Bounty2018-04-092023-06-13
4758Getting read access on Edmodo Production Server by exploiting SSRF SSRF Edmodo Shawar Khan (@ShawarkOFFICIAL) Bug Bounty2018-05-212023-06-13
4743How i converted SSRF to XSS in Jira. SSRF XSS NA Ashish Kunwar (@D0rkerDevil) Bug Bounty2018-06-012023-06-13
4741How I Hacked Fotor & Got “Nothing” SSRF RFI Fotor Somdev Sangwan (s0md3v) Bug Bounty2018-06-012023-06-13
4735How I found XSS via SSRF vulnerability -Adesh Kolte SSRF XSS CERT-EU Motorola Stanford Adesh Nandkishor kolte (@AdeshKolte) Bug Bounty2018-06-072023-06-13