Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
2567Simple logical Bug turned into a bounty Logic flaw Meta / Facebook Sndp Giri Bug Bounty2021-05-102023-06-13
2566Stored XSS to Organisation Takeover Stored XSS NA Zaid Bhat (@zaidozaid) Bug Bounty2021-05-102023-06-13
25652FA Verification Bypass in Shapeshift [shapeshift.com] (Write Up) MFA bypass Shapeshift Evan Ricafort (@evanricafort) Bug Bounty2021-05-102023-06-13
2564CVE-2021-27075: Microsoft Azure Vulnerability Allows Privilege Escalation and Leak of Private Data Privilege escalation Microsoft Intezer Bug Bounty2021-05-112023-06-13
2563CVE-2020-35580 LFI NA hateshape (@hateshaped) Bug Bounty2021-05-112023-06-13
2562My story of hacking Dutch Government XSS Dutch Government Tuhin Bose (@tuhin1729_) Bug Bounty2021-05-122023-06-13
2561How I find my first Stored XSS Stored XSS NA Filipe Azevedo (@filipaze_) Bug Bounty2021-05-132023-06-13
2560Counter-Strike Global Offsets: reliable remote code execution RCE Valve brymko (@brymko) Bug Bounty2021-05-132023-06-13
2559Blind XSS on Google Internal System Blind XSS Google Kailash (@Corrupted_brain) Bug Bounty2021-05-132023-06-13
2557Mass Assignment exploitation in the wild - Escalating privileges in style Mass assignment Privilege escalation NA Gal Nagli (@naglinagli) Bug Bounty2021-05-142023-06-13
25562FA Bypass via Forced Browsing MFA bypass NA Akhil Bug Bounty2021-05-152023-06-13
2555How to prevent more than 200 million users from using Google services Logic flaw Google Omar Hashem (@OmarHashem666) Bug Bounty2021-05-162023-06-13
2554Edmodo Bug Bounty Writeup XSS Edmodo Pethuraj (@Pethuraj) Bug Bounty2021-05-162023-06-13
2553MSSQL Injection In JSON Request SQL injection NA Kailash (@Corrupted_brain) Bug Bounty2021-05-162023-06-13
2552Auth Bypass in https://nearbydevices-pa.googleapis.com Broken Access Control Google David Schütz (@xdavidhu) Bug Bounty2021-05-162023-06-13
2551How i hijacked 12 Subdomains in one Program Subdomain takeover NA Naveen kumawat (@nvk0x) Bug Bounty2021-05-172023-06-13
2550My Fourth Account takeover through password reset Account takeover Password reset NA Omar Hamdy (@seaman00o) Bug Bounty2021-05-172023-06-13
2549Clickjacking in Nearby Devices Dashboard Clickjacking Google David Schütz (@xdavidhu) Bug Bounty2021-05-172023-06-13
2548Just Gopher It: Escalating a Blind SSRF to RCE for $15k SSRF RCE NA SirLeeroyJenkins (@SirLeeroyJenkin) Bug Bounty2021-05-172023-06-13
2547Drupal Insecure Default Leads To Password Reset Poisoning Password reset Host header injection Drupal Bogdan Tiron (@Bogdan___T) Bug Bounty2021-05-292023-06-13
2546Path Traversal in MobileSafari Path traversal Apple David Schütz (@xdavidhu) Bug Bounty2021-05-182023-06-13
2545Finding my First Critical Web Cache Poisoning Web cache poisoning NA Yasser Khan (@N3T_hunt3r) Bug Bounty2021-05-182023-06-13
2544DOS & Stored HTML Injection Bug Bounty Writeup DoS HTML injection NA RiotSecurityTeam (@RiotSecTeam) Bug Bounty2021-05-192023-06-13
2543Time-Based SQL Injection to Dumping the Database SQL injection Android NA Naveen J (@thevillagehackr) Bug Bounty2021-05-192023-06-13
2542SSRF in PDF Renderer using SVG SSRF NA pwn.vg / Tomi (@mastomii) Bug Bounty2021-05-192023-06-13