Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
2594How I was able to Retrieve your Personal Documents using the Wayback Machine! Privacy issue Information disclosure NA Savir Suda (@savxiety) Bug Bounty2021-04-302023-06-13
2593My first OOB XXE exploitation XXE NA Joshua Martinelle (@J0_mart) Bug Bounty2021-04-302023-06-13
2592Facebook account takeover due to unsafe redirects after the OAuth flow OAuth Open redirect Account takeover Meta / Facebook Youssef Sammouda (@samm0uda) Bug Bounty2021-04-302023-06-13
2591Password reset code brute-force vulnerability in AWS Cognito Password reset Bruteforce Rate limiting bypass Account takeover AWS Pentagrid (@pentagridsec) Bug Bounty2021-04-302023-06-13
2590How I got $400 for my first SSRF bug? SSRF NA Usama Varikkottil (@usama_dev) Bug Bounty2021-05-012023-06-13
2589How I found my first RCE? RCE NA ipanda (@ipanda915) Bug Bounty2021-05-012023-06-13
2588SSRF Through PDF Generation SSRF NA Joshua Martinelle (@J0_mart) Bug Bounty2021-05-012023-06-13
2587Chaining CSRF with XSS to deactivate Mass user accounts by single click CSRF XSS NA Santosh Kumar Sha (@killmongar1996) Bug Bounty2021-05-022023-06-13
2586Basic recon to RCE Insecure deserialization RCE NA Joshua Martinelle (@J0_mart) Bug Bounty2021-05-022023-06-13
2585IDOR Leads To Leak Any Uber Eats Restaurant Analytics IDOR Uber Prial Islam Khan (@prial261) Bug Bounty2021-05-022023-06-13
2584Finding known exploits for bugbounties. RCE NA ipanda (@ipanda915) Bug Bounty2021-05-032023-06-13
2583Deep Dive into Open Source Bug Bounty CSRF NA Ritik Sahni (@ritiksahni22) Bug Bounty2021-05-032023-06-13
2582Exploiting the Source Engine (Part 2) - Full-Chain Client RCE in Source using Frida RCE Valve Geebz (@Gbps111) Bug Bounty2021-05-042023-06-13
2581ExifTool CVE-2021-22204 - Arbitrary Code Execution RCE GitLab William Bowling / vakzz (@wcbowling) Bug Bounty2021-05-042023-06-13
2580XSS Through Parameter Pollution XSS HTTP parameter pollution NA Saajan Bhujel (@saajanbhujel) Bug Bounty2021-05-052023-06-13
2579Injecting Punycode URL Within the Arbitrary Text via Comment Box In Google Photo Sharing Option HTML injection Google Divyanshu Shukla (@justm0rph3u5) Bug Bounty2021-05-052023-06-13
2578XSS Through Parameter Pollution Open redirect XSS HTTP parameter pollution NA Saajan Bhujel (@saajanbhujel11) Bug Bounty2021-05-052023-06-13
2577How I Found Sql Injection on intensedebate.com (h1) in 5 minute $350 SQL injection Automattic Ahmad A Abdulla (@lu3ky13) Bug Bounty2021-05-052023-06-13
2575How I Hacked Google App Engine: Anatomy of a Java Bytecode Exploit RCE Google - Bug Bounty2021-05-052023-06-13
2574CVE-2021-1815 – MacOS Local Privilege Escalation Via Preferences Local Privilege Escalation Apple Offensive Security (@offsectraining) Bug Bounty2021-05-062023-06-13
2572Apple Bug bounty writeups XSS(2021) XSS Apple Takashi Suzuki Bug Bounty2021-05-072023-06-13
2571Workplace by Facebook | Unauthorized access to companies environment — $27,5k Authorization flaw Logic flaw IDOR Meta / Facebook Marcos Ferreira (@mvinni_) Bug Bounty2021-05-072023-06-13
2570Microsoft bug bounty writeup Information disclosure Microsoft th3.d1p4k (@DipakPanchal05) Bug Bounty2021-05-082023-06-13
2569Unauthorized access to Django Admin Dashboard by endpoint leaked on GitHub Missing authentication Forced browsing NA Santosh Kumar Sha (@killmongar1996) Bug Bounty2021-05-102023-06-13
2568Exploiting Activity in medium android app Insecure intent Android Medium Raju kumar (@MrCyberwarrior) Bug Bounty2021-05-102023-06-13