Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
4628Liking GitHub repositories on behalf of other users — Stored XSS in WebComponents.org Stored XSS Webcomponents.org Thomas Orlita (@ThomasOrlita) Bug Bounty2018-08-232023-06-13
4601Reflected XSS in Google Code Jam Reflected XSS Google Thomas Orlita (@ThomasOrlita) Bug Bounty2018-09-082023-06-13
4573Bypassing Firebase authorization to create custom goo.gl subdomains Logic flaw IDOR Google Thomas Orlita (@ThomasOrlita) Bug Bounty2018-09-212023-06-13
4412XSSing Google Code-in thanks to improperly escaped JSON data XSS Google Thomas Orlita (@ThomasOrlita) Bug Bounty2018-12-142023-06-13
4334Unsecured access to personal data of a million Leo Express users Authorization flaw XSS Leo Express Thomas Orlita (@ThomasOrlita) Bug Bounty2019-01-292023-06-13
4260Inserting malware into anyone’s Google Earth Projects Archive IDOR XSS Authorization flaw Google Thomas Orlita (@ThomasOrlita) Bug Bounty2019-03-102023-06-13
4106XSSing Google Employees — Blind XSS on googleplex.com Blind XSS Google Thomas Orlita (@ThomasOrlita) Bug Bounty2019-06-152023-06-13
3979Clickjacking DOM XSS on Google.org Clickjacking DOM XSS Google Thomas Orlita (@ThomasOrlita) Bug Bounty2019-08-122023-06-13
3554Listing all registered email addresses on Google’s Crisis Map thanks to IDOR and incremental IDs IDOR Google Thomas Orlita (@ThomasOrlita) Bug Bounty2020-04-072023-06-13
3128Public Bucket Allowed Access to Images on Upcoming Google Cloud Blog Posts GCP bucket misconfiguration Information disclosure Cloud Google Thomas Orlita (@ThomasOrlita) Bug Bounty2020-09-292023-06-13
22435 Different Vulnerabilities in Google’s Threadit DOM XSS Clickjacking Privilege escalation Information disclosure Google Thomas Orlita (@ThomasOrlita) Bug Bounty2021-09-072023-06-13