Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
4678Finding hidden gems vol. 1: forging OAuth tokens using discovered client id and client secret Information disclosure NA Mateusz Olejarka (@molejarka) Bug Bounty2018-07-232023-06-13
4676Exploitation of Server Side Template Injection with Craft CMS plugin SEOmatic <=3.1.3 [CVE-2018-14716] SSTI SEOmatic CMS plugin Sebastian (ha.cker.info) Bug Bounty2018-07-242023-06-13
4675SQL Injection and A silly WAF SQL injection NA Mahmoud Gamal (@Zombiehelp54) Bug Bounty2018-07-252023-06-13
4674Exfiltration via CSS Injection CSS injection NA d0nut (@d0nutptr) Bug Bounty2018-07-252023-06-13
4671Making a Blind SQL Injection a Little Less Blind SQL injection NA TomNomNom (@tomnomnom) Bug Bounty2018-07-282023-06-13
4667How I could access your internal servers, steal and modify your image repository RCE NA thehackerish (@thehackerish) Bug Bounty2018-07-312023-06-13
4666CRLF Injection Into PHP’s cURL Options CRLF injection NA TomNomNom (@tomnomnom) Bug Bounty2018-08-012023-06-13
4663Discovering and Exploiting a Vulnerability in Android’s Personal Dictionary (CVE-2018-9375) Privilege escalation Android Google Daniel Kachakil (@Kachakil) Bug Bounty2018-08-012023-06-13
4661Blind-XSS in Chrome Experiments - Google (Write Up) Blind XSS Google Evan Ricafort (@evanricafort) Bug Bounty2018-08-032023-06-13
4659Blind-XSS in Chrome Experiments - Google (Write Up) Blind XSS Google Evan Ricafort (@evanricafort) Bug Bounty2018-08-032023-06-13
4656Self XSS leads to blind XSS and reflected XSS. Blind XSS Reflected XSS NA Friendly (@SkeletorKeys) Bug Bounty2018-08-062023-06-13
4653Sending out phishing e-mails from @microsoft.com HTML injection Microsoft SI9INT (@si9int) Bug Bounty2018-08-072023-06-13
4651From data leak to account takeover Account takeover Information disclosure Password reset NA Antony Garand (@AntoGarand) Bug Bounty2018-08-072023-06-13
4650How I hacked a Crypto Exchange (Bug Bounty Writeup) IDOR NA Muhammad Abdullah Bug Bounty2018-08-072023-06-13
4649My First Critical Report Password reset Account takeover NA Miguel Corral (@mcorral74) Bug Bounty2018-08-082023-06-13
4648This is how can I spoof ANY Sentry.Io log infinitely and create fake error-logs Content spoofing HackerOne Sentry Carlos Daniel Giovanella Bug Bounty2018-08-092023-06-13
4646From TOMCAT to NT AUTHORITYSYSTEM Default credentials NA Rahul R Bug Bounty2018-08-092023-06-13
4642Misconfigured JIRA setting - Apigee Information disclosure Google Atlassian Tutorgeeks Bug Bounty2018-08-102023-06-13
4641Adminer Script Results to Pwning Server?, Private Bug Bounty Program Authentication bypass NA Yashar Shahinzadeh (@YShahinzadeh) Bug Bounty2018-08-112023-06-13
4634IDOR leads to account takeover IDOR NA s0cket7 (@s0cket7) Bug Bounty2018-08-162023-06-13
4632YAHOO IDOR -elimination of any comment IDOR Yahoo! / Verizon Media Bada Diaz (@bada77) Bug Bounty2018-08-172023-06-13
4630https://www.updatelap.com/2018/08/privileged-escalation-in-facebook-rooms.html Authorization flaw Privilege escalation Meta / Facebook Jafar Abo Nada (@Jafar_Abo_Nada) Bug Bounty2018-08-182023-06-13
4629API key: The real goldmine Information disclosure NA Yumi Bug Bounty2018-08-192023-06-13
4624My first valid xss(@Hackerone) XSS NA Jatin Aesthetic (@techyfreakk) Bug Bounty2018-08-252023-06-13
4623Traversing the Path to RCE Path traversal RCE NA hawkinsecurity Bug Bounty2018-08-272023-06-13