Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
5046OpenProject Session Management Security Vulnerability aka CVE-2017-11667 Session management issue OpenProject Mohamed A. Baset Bug Bounty2017-06-302023-06-13
4995Luminate Store Basics defacement and potential takeover CSRF Session management issue Yahoo! / Verizon Media Rojan Rijal (@uraniumhacker) Bug Bounty2017-08-302023-06-13
4691CVE-2018-13784: PrestaShop 1.6.x Privilege Escalation Privilege escalation Session management issue PrestaShop Charles Fol (@cfreal_) Bug Bounty2018-07-162023-06-13
4445Broken Authentication — Bug Bounty Session management issue NA Vulnerables Bug Bounty2018-11-282023-06-13
3811CORS Misconfiguration to Account TakeOver [Out of scope to grab items In-Scope] CORS misconfiguration Open redirect Reflected XSS Session management issue NA Mashoud1122 (@mashoud1122) Bug Bounty2019-11-242023-06-13
3795Reusing Cookies Session management issue NA Ricardo Iramar dos Santos Bug Bounty2019-12-072023-06-13
3786A $25 Easy Bug. Session management issue NA Navneet (@na5n33t) Bug Bounty2019-12-122023-06-13
3622Breaking the Competition (Bug Bounty Write-up) Race condition DoS Logic flaw Session management issue NA George O (@georgeomnet) Bug Bounty2020-03-082023-06-13
3601Weak session validation bug let you login even after changing the session IDs and logging out from the accounts Logic flaw Session management issue viator.com Manasjha (@manas_hunter) Bug Bounty2020-03-162023-06-13
3545[Writeup][Bug Bounty][Instagram] Instagram Still Send New DMs and Video Calls to Device After Logout [ID][EN] Session management issue Meta / Facebook Muhammad Thomas Fadhila Yahya (@fadhilthomas) Bug Bounty2020-04-162023-06-13
2480Exploiting outdated Apache Airflow instances Session management issue NA Ian Carroll (@iangcarroll) Bug Bounty2021-06-142023-06-13
2423Account Takeovers — Believe the Unbelievable Account takeover Session management issue Weak credentials Components with known vulnerabilities Password reset NA Nikhil (niks) (@niksthehacker) Bug Bounty2021-07-092023-06-13
1936Exploiting Redash instances with CVE-2021-41192 Privilege escalation Session management issue SSRF NA Ian Carroll (@iangcarroll) Bug Bounty2022-01-062023-06-13
1929Pre-Auth RCE in Moodle Part II - Session Hijack in Moodle%27s Shibboleth Session hijacking Session management issue Account takeover RCE Moodle Johannes Moritz Bug Bounty2022-01-102023-06-13
1677Pwning a Cisco RV340 with a 4 bug chain exploit Local Privilege Escalation OS command injection RCE Session management issue Cisco Liv (@terminatorLM) Bug Bounty2022-04-012023-06-13
677Cengage LTI Session Management Leakage SSO Session management issue Cengage Tony Porterfield Bug Bounty2022-12-202023-06-13
316[Netflix][Smart TV] — Chaining Self-XSS with Session poisoning. Self-XSS Cookie injection Session management issue Netflix Lyubomir Tsirkov (@lyubo_tsirkov) Bug Bounty2023-03-112023-06-13