Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
5316Stored Cross-Site Scripting (XSS) via DNS Record Poisoning XSS Stored XSS Rengine Touhid M Shaikh Bug Bounty2024-08-232024-08-27
5299OWASP TOP 10-2021: ARRIVAL OF NEW RISKS Web Application Security OWASP Aswin Govind CheatSheet2021-10-052024-01-31
5297PWK/PEN-200 OSCP Preparation Roadmap OSCP OSCP Ishaq Mohammed Certification Journey Writeup2018-06-042024-01-31
5290Facebook XSS via Cross-Origin Resource Sharing XSS Meta / Facebook Matt Austin (@mattaustin) Bug Bounty2010-07-062023-06-13
5284Framing, Part 1: Click-Jacking Etsy Clickjacking Etsy Jack Whitton (@fin1te) Bug Bounty2013-02-052023-06-13
5277Amazon packaging feedback cross-site scripting vulnerability XSS Amazon Bitquark (@bitquark) Bug Bounty2013-07-032023-06-13
5276Admob creative image cross-site scripting vulnerability XSS Google Bitquark (@bitquark) Bug Bounty2013-07-192023-06-13
5272Delete any Photo from Facebook by Exploiting Support Dashboard - $12,500 Bug IDOR Meta / Facebook Arul Kumar (@ArulVaiyapuri) Bug Bounty2013-09-012023-06-13
5270PayPal Bug Bounty: PayPaltech.com E-Mail Injection Email injection Paypal Julien Ahrens (@MrTuxracer) Bug Bounty2013-09-262023-06-13
5264Instagram%27s One-Click Privacy Switch CSRF Meta / Facebook Jack Whitton (@fin1te) Bug Bounty2013-10-312023-06-13
5244Facebook – Stored Cross-Site Scripting (XSS) – Badges Stored XSS Meta / Facebook Brett Buerhaus (@bbuerhaus) Bug Bounty2014-06-162023-06-13
5241Step-by-step: exploiting SQL injection(s) in Oculus%27 website. SQL injection Meta / Facebook Josip Franjkovic (@josipfranjkovic) Bug Bounty2014-09-052023-06-13
5232AliExpress XSS vulnerability - take over any seller account XSS Alibaba Barak Tawily (@quitten11) Bug Bounty2014-12-102023-06-13
5225admin.google.com Reflected Cross-Site Scripting (XSS) Reflected XSS Google Brett Buerhaus (@bbuerhaus) Bug Bounty2015-01-212023-06-13
5221Telegram App Store Secret-Chat Messages in Plain-Text Database Privacy issue Information disclosure Telegram Jon Paterson (@shellprompt) Bug Bounty2015-02-232023-06-13
5211CVE-2014-7216: A Journey Through Yahoo’s Bug Bounty Program Buffer Overflow Memory corruption Yahoo! / Verizon Media Julien Ahrens (@MrTuxracer) Bug Bounty2015-09-032023-06-13
5210XSS to RCE in ... XSS RCE NA Neil Hakuna Matatall (@ndm) Bug Bounty2015-09-082023-06-13
5197XSS without HTML: Client-Side Template Injection with AngularJS CSTI XSS Google Gareth Heyes (@garethheyes) Bug Bounty2016-01-272023-06-13
5196How I got access to millions of [redacted] accounts RFI NA Bitquark (@bitquark) Bug Bounty2016-02-092023-06-13
5189Uber Bug Bounty: Turning Self-XSS into Good-XSS XSS Uber Jack Whitton (@fin1te) Bug Bounty2016-03-222023-06-13
5183ESEA Server-Side Request Forgery and Querying AWS Meta Data SSRF ESEA Brett Buerhaus (@bbuerhaus) Bug Bounty2016-04-182023-06-13
5170InstaBrute: Two Ways to Brute-force Instagram Account Credentials Bruteforce Username enumeration Meta / Facebook Arne Swinnen (@ArneSwinnen) Bug Bounty2016-05-192023-06-13
5162TopCoder.com Vulnerabilities – A tail of site-wide bugs leads to accounts compromise & payments hijacking CSRF Account takeover Topcoder.com Mohamed A. Baset Bug Bounty2016-06-282023-06-13
5157Twitter%27s Vine Source code dump - $10080 Source code disclosure Information disclosure Twitter avicoder (@avicoder) Bug Bounty2016-07-222023-06-13
5156How we broke PHP, hacked Pornhub and earned $20,000 RCE Memory corruption Use-After-Free PornHub Ruslan Habalov (@evonide) Bug Bounty2016-07-232023-06-13