Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
2515Escalating SSRF to Accessing all user PII information by aws metadata SSRF NA Santosh Kumar Sha (@killmongar1996) Bug Bounty2021-05-312023-06-13
2514AppCache%27s forgotten tales Browser hacking Google (Chrome) Luan Herrera (@lbherrera_) Bug Bounty2021-05-312023-06-13
2513Facebook Page Admin Disclosure Information disclosure Meta / Facebook Kunjan Nayak (@kunjannayak5) Bug Bounty2021-05-312023-06-13
2512CVE-2021-29084: Exploiting CRLF Header Injection in Synology NAS for Unauthenticated File Downloads CRLF injection Synology Justin Taft Bug Bounty2021-06-012023-06-13
2511Escalating SSRF to Accessing all user PII information by aws metadata SSRF NA Santosh Kumar Sha (@killmongar1996) Bug Bounty2021-06-012023-06-13
2510Admin Panel? Pwned! Information disclosure Hardcoded credentials NA Splintersec (@splint3rsec) Bug Bounty2021-06-022023-06-13
2509Huawei LTE USB Stick E3372: From File Overwrite to Code Execution Local Privilege Escalation Huawei Martin Rakhmanov (@mrakhmanov) Bug Bounty2021-06-022023-06-13
2508Exploiting Open Redirect - Whitelist Bypass Using Salesforce Environment Open redirect Token theft Salesforce NA Gaurav Nayak (@4auvar) Bug Bounty2021-06-022023-06-13
2507XSS in the AWS Console XSS CSP bypass CSTI AWS Nick Frichette (@frichette_n) Bug Bounty2021-06-022023-06-13
2506Bypassing LFI (Local File Inclusion) LFI NA Abhishek (@abhishake21) Bug Bounty2021-06-032023-06-13
2505Server Side Request Forgery - A Forged Document SSRF File upload NA Jerry Shah (@Jerry) Bug Bounty2021-06-032023-06-13
2504Android: Exploring vulnerabilities in WebResourceResponse Arbitrary file read Android Amazon Oversecured (@OversecuredInc) Bug Bounty2021-06-032023-06-13
2503How I was able to see likes and dislikes count even though is hidden by victim | YouTube #3 Broken Access Control Google R ando (@Rando02355205) Bug Bounty2021-06-042023-06-13
2502403 Forbidden Bypass OTP bypass Exposed registration page XSS NA th3.d1p4k (@DipakPanchal05) Bug Bounty2021-06-042023-06-13
2501Executing CSRF With Phone Validation CSRF NA Greg Gibson Bug Bounty2021-06-042023-06-13
2500Pop-Ups in a good-world XSS Imgur Guilherme Keerok (@k33r0k) Bug Bounty2021-06-042023-06-13
2499Shopify Multipass Misconfiguration Authentication flaw Logic flaw NA Ahmed A. Sherif Bug Bounty2021-06-052023-06-13
2498How Github recon help me to find NINE FULL SSRF Vulnerability with AWS metadata access SSRF NA Santosh Kumar Sha (@killmongar1996) Bug Bounty2021-06-062023-06-13
2497How I could have accessed all your private videos/photos saved inside your device without even unlocking it? Authorization flaw Logic flaw Meta / Facebook Samip Aryal (@samiparyal_) Bug Bounty2021-06-062023-06-13
2496Story of my first cash bounty on hackerone. SSRF XSS NA Vedant Tekale (@_justYnot) Bug Bounty2021-06-072023-06-13
2495Joomla Password Reset Vulnerability And A Stored XSS For Full Compromise Password reset Stored XSS Privilege escalation RCE Security code review NA Adrian Tiron (@Adrian__T) Bug Bounty2021-06-072023-06-13
2494How i was able to bypass parental pin of showmax Authorization flaw Showmax abdulsec (@moodiAbdoul) Bug Bounty2021-06-092023-06-13
2493Author spoofing in Google Colaboratory Logic flaw Google Zohar Shachar Bug Bounty2021-06-092023-06-13
2492Unexpected IDOR Vulnerability in [REDACTED] - [redacted].net (Write Up) IDOR NA Evan Ricafort (@evanricafort) Bug Bounty2021-06-102023-06-13
2491Second Order Race Condition Race condition NA Prasoon Gupta (@0xdekster) Bug Bounty2021-06-102023-06-13