Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
2281ATO of WordPress Website “4 digits €€€€ Bounty in 5 Minute!” Exposed registration page Account takeover NA Ritesh Gohil (@RiteshG37659480) Bug Bounty2021-08-292023-06-13
2280What would you do if Oracle’s mailing server sent you this? HTML injection Oracle I am Broot Bug Bounty2021-08-292023-06-13
2279Hunting for XSS with CodeQL XSS GitLab Daniel Santos (@bananabr) Bug Bounty2021-08-292023-06-13
2278How MarkMonitor left >60,000 domains for the taking Subdomain takeover NA Ian Carroll (@iangcarroll) Bug Bounty2021-08-292023-06-13
2277Two account takeover bugs worth $4300 🎁 Account takeover Privilege escalation 403 bypass IDOR NA Usama Varikkottil (@usama_dev) Bug Bounty2021-08-292023-06-13
2276I owe your Request | HTTP Request Smuggling leads to Full Accounts takeover HTTP Request Smuggling NA Muhammad Adel (@ItsFadinG_) Bug Bounty2021-08-302023-06-13
2275Proxytoken: An Authentication Bypass In Microsoft Exchange Server Authentication bypass Microsoft Xuan Tuyen Bug Bounty2021-08-302023-06-13
2274CVE-2021-39165: A Bug Bounty Journey from a Laravel SQL Injection Vulnerability SQL injection NA Xuan Tuyen Bug Bounty2021-08-302023-06-13
2273Broken Access Control Leads To Change Of Admin Details Privilege escalation Client-side enforcement of server-side security NA V3D (@v3d_bug) Bug Bounty2021-08-312023-06-13
2272Bypassing 2-Factor Authentication for Facebook Business Manager (Bounty: 1000 USD) MFA bypass Meta / Facebook Shubham Bhamare (@theshubh77) Bug Bounty2021-08-312023-06-13
2271Dropping root shell in a Crypto Exchange for Fun and Profitn%27t RCE ChangeNOW Nirmal Thapa (@tnirmalz) Bug Bounty2021-08-312023-06-13
2270Full PoC | Metasploit Pro Trial License Request Limit Bypass Privilege escalation Logic flaw Rapid7 ChooK Bug Bounty2021-08-312023-06-13
2269Now Patched Vulnerability in WhatsApp could have led to data exposure of users Memory corruption Meta / Facebook Dikla Barda Bug Bounty2021-09-012023-06-13
2268SQL injection in harvard subdomain SQL injection Harvard University Brandon Roldan (@tomorrowisnew_) Bug Bounty2021-09-012023-06-13
2267CVE-2021-2429: A Heap-based Buffer Overflow Bug In The Mysql Innodb Memcached Plugin Memory corruption Oracle (MySQL) - Bug Bounty2021-09-022023-06-13
2266Hacking Dutch Government For a lousy T-shirt IDOR Information disclosure Dutch Government Veshraj Ghimire (@GhimireVeshraj) Bug Bounty2021-09-022023-06-13
2265How I Found Multiple XSS in Hidden Legacy Pages XSS NA Marx Chryz Bug Bounty2021-09-022023-06-13
2264chaining bugs from self XSS to account takeover Self-XSS WAF bypass CSRF Account takeover NA Behnam Yazdanpanah (@abhiunix) Bug Bounty2021-09-022023-06-13
2263Breaking Application’s Logic to DOS Attack IDOR DoS NA Abhijeet Singh (@abhiunix) Bug Bounty2021-09-022023-06-13
2262SQL injection in harvard subdomain XSS SQL injection Harvard University Brandon Roldan (@tomorrowisnew_) Bug Bounty2021-09-022023-06-13
2261Your Vulnerability Is In Another OEM! Memory corruption RCE Western Digital Lucas Georges Bug Bounty2021-09-022023-06-13
2259RCE By Code Injection | Perl Reverse Shell RCE Code injection NA Abdulrahman-Kamel Bug Bounty2021-09-022023-06-13
2258Play the music and bypass TCC aka CVE-2020-29621 Privacy issue MacOS Apple Wojciech Reguła (@_r3ggi) Bug Bounty2021-09-022023-06-13
2257Google Cloud Build — under the hood gRPC Google Imre Rad (@ImreRad) Bug Bounty2021-09-022023-06-13
2256IDOR Vulnerability In GraphQL Api On Website IDOR GraphQL NA Aidil Arief Bug Bounty2021-09-032023-06-13