Writeups
Spotlight
Add Your Writeup
Blogs
Contact Us
Register
Login
Write-ups
Check The Published Writeups
Search
Reset
WDB
Title
Tags
Programs
Authors
Type
Publication
Added
5096
One company: 262 bugs, 100% acceptance, 2.57 priority, millions of user details saved.
Stored XSS
Blind XSS
CSRF
Account takeover
IDOR
NA
Zseano (@zseano)
Bug Bounty
2017-02-25
2023-06-13
5035
Hey UserID x, what’s your secret token? Broken API enables me to leak/modify any users personal information
IDOR
Account takeover
NA
Zseano (@zseano)
Bug Bounty
2017-07-13
2023-06-13
4936
How signing up for an account with an @company.com email can have unexpected results
Logic flaw
NA
Zseano (@zseano)
Bug Bounty
2017-11-15
2023-06-13
4710
How re-signing up for an account lead to account takeover
Logic flaw
Account takeover
NA
Zseano (@zseano)
Bug Bounty
2018-06-26
2023-06-13
4507
Improper CSRF token handling leads to site-wide CSRF issue, chained with clickjacking = woot! Multiple sites vulnerable
CSRF
Clickjacking
NA
Zseano (@zseano)
Bug Bounty
2018-10-29
2023-06-13
4504
CSRF %27protection%27 bypass on xvideos
CSRF
xvideos
Zseano (@zseano)
Bug Bounty
2018-10-30
2023-06-13
4503
It’s all in the detail: Email leak & Account takeover thanks to WayBackMachine & extensive knowledge about the program
Information disclosure
Authentication bypass
Account takeover
NA
Zseano (@zseano)
Bug Bounty
2018-10-30
2023-06-13
4144
Leaking OpenID tokens with “ — the bug right infront of you
OpenID Connect
Open redirect
Token leak
NA
Zseano (@zseano)
Bug Bounty
2019-05-21
2023-06-13
3690
Easily leaking passenger information on an Airline
IDOR
NA
Zseano (@zseano)
Bug Bounty
2020-02-04
2023-06-13
3263
New features means new bugs
Logic flaw
Authorization flaw
Payment bypass
NA
Zseano (@zseano)
Bug Bounty
2020-07-30
2023-06-13
3262
Using XAMPP and Burp Intruder when scanning for subdomains to look for interesting behaviour & code
Information disclosure
NA
Zseano (@zseano)
Bug Bounty
2020-07-30
2023-06-13
3239
The feature works as intended, but what’s in the source?
Information disclosure
NA
Zseano (@zseano)
Bug Bounty
2020-08-08
2023-06-13
2055
Finding XSS on .apple.com and building a proof of concept to leak your PII information
XSS
Apple
Zseano (@zseano)
Bug Bounty
2021-11-23
2023-06-13