Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
5044Making an XSS triggered by CSP bypass on Twitter. XSS CSP bypass Twitter tbmnull Bug Bounty2017-07-062023-06-13
5043WhatsApp — DoS Vulnerability In iOS & Android DoS Meta / Facebook Vishnuraj Bug Bounty2017-07-072023-06-13
5042Managed Apps and Music: a tale of two XSSes in Google Play XSS Google Yasin Soliman (@SecurityYasin) Bug Bounty2017-07-072023-06-13
5041Medium Content Spoofing Leads to XSS Content spoofing Stored XSS Medium Abdullah Hussam (@Abdulahhusam) Bug Bounty2017-07-082023-06-13
5040Coinbase AngularJS DOM XSS via Kiteworks DOM XSS Coinbase Paulos Yibelo (@PaulosYibelo) Bug Bounty2017-07-082023-06-13
5039How a simple IDOR become a $4K User Impersonation vulnerability IDOR NA Shahmeer Amir (@Shahmeer_Amir) Bug Bounty2017-07-082023-06-13
5038XSS by tossing cookies XSS Cookie tossing Microsoft Twitter WeSecureApp (@wesecureapp) Bug Bounty2017-07-102023-06-13
5037How we tookover shopify accounts with one single click Stored XSS Shopify WeSecureApp (@wesecureapp) Bug Bounty2017-07-102023-06-13
5036Fabric.io API permission apocalypse – Privilege Escalations Authorization flaw Account takeover Twitter WeSecureApp (@wesecureapp) Bug Bounty2017-07-102023-06-13
5035Hey UserID x, what’s your secret token? Broken API enables me to leak/modify any users personal information IDOR Account takeover NA Zseano (@zseano) Bug Bounty2017-07-132023-06-13
5034How to find internal subdomains? YQL, Yahoo! and bug bounty. Information disclosure Yahoo! / Verizon Media Wojciech Bug Bounty2017-07-162023-06-13
5033ctrl+c & ctrl+v to Steal SESSIONID Clickjacking NA Arbaz Hussain (@ArbazKiraak) Bug Bounty2017-07-182023-06-13
5032IDOR While Connecting Social Account in Hackster.io IDOR Hackster.io Arbaz Hussain (@ArbazKiraak) Bug Bounty2017-07-182023-06-13
5031Stealing Access Token of One-drive Integration By Chaining CSRF Vulnerability OAuth CSRF NA Arbaz Hussain (@ArbazKiraak) Bug Bounty2017-07-182023-06-13
5030Exploiting Misconfigured CORS on popular BTC Site CORS misconfiguration NA Arbaz Hussain (@ArbazKiraak) Bug Bounty2017-07-192023-06-13
5029Xss using dynamically generated js file XSS NA Arbaz Hussain (@ArbazKiraak) Bug Bounty2017-07-192023-06-13
5028That Escalated Quickly : From partial CSRF to reflected XSS to complete CSRF to Stored XSS CSRF Reflected XSS Stored XSS NA Mandeep Jadon (@1337tr0lls) Bug Bounty2017-07-192023-06-13
5027Business Logic Vulnerabilities Series: A brief on Abusing Invitation Systems Logic flaw Meta / Facebook Ali Kabeel Bug Bounty2017-07-192023-06-13
5026Self XSS to Good XSS Clickjacking XSS Clickjacking NA Arbaz Hussain (@ArbazKiraak) Bug Bounty2017-07-202023-06-13
5025Race Condition bypassing team limit Race condition NA Arbaz Hussain (@ArbazKiraak) Bug Bounty2017-07-202023-06-13
5024Missing Authorization check in Facebook Pages Manager Authorization flaw Meta / Facebook Arbaz Hussain (@ArbazKiraak) Bug Bounty2017-07-202023-06-13
5023How i was able to bypass strong xss protection in well known website. (imgur.com) XSS Imgur Armaan Pathan (@armaancrockroax) Bug Bounty2017-07-212023-06-13
5022May the Shells be with You - A Star Wars RCE Adventure! RCE NA Andy Gill (@ZephrFish) Bug Bounty2017-07-222023-06-13
5021pen Redirect In Flock | My First Swag pack Open redirect Flock Noman Shaikh (@nomanali181) Bug Bounty2017-07-242023-06-13
5020Stored XSS on Rockstar Game XSS Rockstar Games Arbaz Hussain (@ArbazKiraak) Bug Bounty2017-07-262023-06-13