Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
4704The $12,000 Intersection between Clickjacking, XSS, and Denial of Service Clickjacking XSS DoS Bustabit Sam Curry (@samwcyo) Bug Bounty2018-07-042023-06-13
4407Reading ASP secrets for $17,000 Local file disclosure (LFD) NA Sam Curry (@samwcyo) Bug Bounty2018-12-162023-06-13
4044Cracking my windshield and earning $10,000 on the Tesla Bug Bounty Program Blind XSS Tesla Sam Curry (@samwcyo) Bug Bounty2019-07-142023-06-13
3900Analysis of CVE-2019-14994 – Jira Service Desk Path Traversal leads to Massive Information Disclosure Path traversal Atlassian Sam Curry (@samwcyo) Bug Bounty2019-09-252023-06-13
3853Filling in the Blanks: Exploiting Null Byte Buffer Overflow for a $40,000 Bounty Null byte buffer overflow Memory corruption NA Sam Curry (@samwcyo) Bug Bounty2019-11-012023-06-13
3539Abusing HTTP Path Normalization and Cache Poisoning to steal Rocket League accounts HTTP cache poisoning Open redirect Rocket League Sam Curry (@samwcyo) Bug Bounty2020-04-192023-06-13
3377Hacking Starbucks and Accessing Nearly 100 Million Customer Records Path traversal Starbucks Sam Curry (@samwcyo) Bug Bounty2020-06-202023-06-13
3109We Hacked Apple for 3 Months: Here’s What We Found RCE Authentication bypass Authorization bypass SSRF XXE Blind XSS IDOR OS command injection SQL injection Apple Sam Curry (@samwcyo) Bug Bounty2020-10-072023-06-13
2818Hacking Chess.com and Accessing 50 Million Customer Records Reflected XSS Information disclosure Account takeover Chess.com Sam Curry (@samwcyo) Bug Bounty2021-02-112023-06-13
2422Whose app are you downloading? Link hijacking Binance’s shortlinks through AppsFlyer Broken link hijacking Chess.com Sam Curry (@samwcyo) Bug Bounty2021-07-102023-06-13
1052Exploiting Web3’s Hidden Attack Surface: Universal XSS on Netlify’s Next.js Library Universal XSS SSRF Open redirect Web cache poisoning Netlify Gemini PancakeSwap Docusign Moonpay Celo Sam Curry (@samwcyo) Bug Bounty2022-09-212023-06-13
621Web Hackers vs. The Auto Industry: Critical Vulnerabilities in Ferrari, BMW, Rolls Royce, Porsche, and More Account takeover SSO RCE Authorization bypass SQL injection Mass assignment Information disclosure Kia Honda Infiniti Nissan Acura Mercedes-Benz Hyundai Genesis BMW Rolls Royce Ferrari Spireon Ford Reviver Porsche Toyota Jaguar Land Rover SiriusXM Sam Curry (@samwcyo) Bug Bounty2023-01-032023-06-13