Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
5069Paypal Mobile Verification And Payment Restrictions Bypass Logic flaw Paypal Rafay Baloch (@rafaybaloch) Bug Bounty2017-06-012023-06-13
5068DOM Based XSS In Microsoft DOM XSS Microsoft Rafay Baloch (@rafaybaloch) Bug Bounty2017-06-012023-06-13
5067Android Browser Same Origin Policy Bypass < 4.4 - CVE-2014-6041 SOP bypass Google Rafay Baloch (@rafaybaloch) Bug Bounty2017-06-012023-06-13
5066A Tale Of Another SOP Bypass In Android Browser < 4.4 SOP bypass Google Rafay Baloch (@rafaybaloch) Bug Bounty2017-06-012023-06-13
5065Stored XSS, CSRF And Clickjacking Vulnerabilities in Opera Stored XSS CSRF Clickjacking Opera Rafay Baloch (@rafaybaloch) Bug Bounty2017-06-012023-06-13
5064Django Privilege Escalation – Zero To Superuser Privilege escalation NA Sean Melia (@seanmeals) Bug Bounty2017-06-012023-06-13
5063How I got 5500$ from Yahoo for RCE RCE Yahoo! / Verizon Media Th3G3nt3lman (@Th3G3nt3lman) Bug Bounty2017-06-042023-06-13
5062From JS to another JS files lead to authentication bypass Authentication bypass NA yappare (@yappare) Bug Bounty2017-06-062023-06-13
5061WhatsApp — Dos Vulnerability In iOS & Android DoS Meta / Facebook Vishnu Prasad P G (@vishnuprasadnta) Bug Bounty2017-06-072023-06-13
5060Let’s steal some tokens! CSRF XSS Account takeover Google Shopify Mahmoud Gamal (@Zombiehelp54) Bug Bounty2017-06-112023-06-13
5059Godaddy XSS affects parked domains redirector/processor! Reflected XSS GoDaddy Mohamed A. Baset Bug Bounty2017-06-112023-06-13
5058Vulnerability in Metasploit Project aka CVE-2017-5244 CSRF Rapid7 Mohamed A. Baset Bug Bounty2017-06-122023-06-13
5057XSS on Bugcrowd and so many other website’s main Domain Reflected XSS Bugcrowd Bull (@v0sx9b) Bug Bounty2017-06-142023-06-13
5056How I hacked 23.900.000 tumblr domains at once :) IDOR Automattic Ak1T4 (@akita_zen) Bug Bounty2017-06-192023-06-13
5055Authentication bypass on Airbnb via OAuth tokens theft OAuth Login CSRF Open redirect Authentication bypass Airbnb Arne Swinnen (@ArneSwinnen) Bug Bounty2017-06-222023-06-13
5054How I Built An XSS Worm On Atmail XSS Atmail Jake Miller Bug Bounty2017-06-232023-06-13
5053Yahoo Small Business (Luminate) and the Not-So-Secret Keys Blind SSRF Yahoo! / Verizon Media Tommy DeVoss / dawgyg (@thedawgyg) Bug Bounty2017-06-232023-06-13
5052Stored XSS in the heart of the Russian email provider giant (Mail.ru) Stored XSS Mail.ru Seif Elsallamy (@seifelsallamy) Bug Bounty2017-06-242023-06-13
5051Authentication bypass on Uber’s Single Sign-On via subdomain takeover Subdomain takeover Authentication bypass Uber Arne Swinnen (@ArneSwinnen) Bug Bounty2017-06-252023-06-13
5050Road to (unauthenticated) recovery: downloading GitHub SSO bypass codes Authorization flaw GitHub Yasin Soliman (@SecurityYasin) Bug Bounty2017-06-252023-06-13
5049CVE-2017-10711: Reflected XSS vulnerability in SimpleRisk – Open Source Risk Management System Reflected XSS SimpleRisk Mohamed A. Baset Bug Bounty2017-06-282023-06-13
5048Escalating XSS in PhantomJS Image Rendering to SSRF/Local-File Read XSS SSRF LFI NA Brett Buerhaus (@bbuerhaus) Bug Bounty2017-06-292023-06-13
5047Posting on groups as people whenever their email was known by an attacker Authorization flaw Meta / Facebook Zahid Ali Bug Bounty2017-06-292023-06-13
5046OpenProject Session Management Security Vulnerability aka CVE-2017-11667 Session management issue OpenProject Mohamed A. Baset Bug Bounty2017-06-302023-06-13
5045Stored XSS in Bandcamp Stored XSS Bandcamp Corben Leo (@hacker_) Bug Bounty2017-06-302023-06-13