Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
4245Should you be concerned about LastPass uploading your passwords to its server? Information disclosure Logic flaw LastPass Wladimir Palant (@WPalant) Bug Bounty2019-03-182023-06-13
3965Kaspersky in the Middle – what could possibly go wrong? Clickjacking Universal XSS MiTM Kaspersky Wladimir Palant (@WPalant) Bug Bounty2019-08-192023-06-13
3724Pwning Avast Secure Browser for fun and profit RCE Command injection Avast Wladimir Palant (@WPalant) Bug Bounty2020-01-132023-06-13
3368Exploiting Bitdefender Antivirus: RCE from any website RCE Information disclosure Bitdefender Wladimir Palant (@WPalant) Bug Bounty2020-06-222023-06-13
1989Yes, fun browser extensions can have vulnerabilities too! XSS Browser extension hacking postMessage Meow Wladimir Palant (@WPalant) Bug Bounty2021-12-202023-06-13
1773Skype extension: All functionality broken? Still exploitable! Information disclosure Privacy issue Microsoft Wladimir Palant (@WPalant) Bug Bounty2022-03-012023-06-13
1739Party time: Injecting code into Teleparty extension HTML injection Open redirect Browser extension hacking Teleparty Wladimir Palant (@WPalant) Bug Bounty2022-03-142023-06-13
1611Adobe Acrobat hollowing out same-origin policy XSS SOP bypass Open redirect postMessage Adobe Wladimir Palant (@WPalant) Bug Bounty2022-04-192023-06-13
1439Exploiting Bitdefender Antivirus: RCE from any website RCE Command injection Bitdefender Wladimir Palant (@WPalant) Bug Bounty2022-06-222023-06-13