Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
2174A short story of Content Spoofing to HTML Injection in Apple using Dangling Markup Injection HTML injection Dangling Markup Injection Apple Rishu Ranjan (@tweetit_rrj) Bug Bounty2021-10-032023-06-13
2172Bypassing 403 Protection To Get Pagespeed Admin Access 403 bypass NA Prajit Sindhkar (@PrajitSindhkar) Bug Bounty2021-10-042023-06-13
2171CVE-2021-43136 – FormaLMS – The evil default value that leads to Authentication Bypass Authentication bypass Security code review Forma LMS Cristian Giustini Bug Bounty2021-10-052023-06-13
2170CVE-2021-26084 RCE Atlassian snowyyowl (@bennyyjacob) Bug Bounty2021-10-052023-06-13
2169How I got access to many PIIs through a source code leak Information disclosure NA Supras (@LdrTom) Bug Bounty2021-10-052023-06-13
2168[EN] Stored XSS in the administrator’s panel due to misuse of MarkupSafe Stored XSS pass Culture Aethlios (@AethliosIK) Bug Bounty2021-10-062023-06-13
2167CSRF to one tray Red-bull CSRF Redbull Mohammed Saneem Bug Bounty2021-10-062023-06-13
2166Hacking Netflix Eureka! SSRF XSS Netflix Maxim Tyukov (@maxtyukov) Bug Bounty2021-10-062023-06-13
2165CVE-2021-26420: Remote Code Execution In Sharepoint Via Workflow Compilation RCE Microsoft - Bug Bounty2021-10-062023-06-13
2164Accessing Apple’s internal UAT Slackbot for fun and non-profit Authorization flaw Apple Shail Patel (@shail_official) Bug Bounty2021-10-072023-06-13
2163Request Smuggling In Major Crypto Site — road to disappointment HTTP Header Smuggling NA CeloIme Prezime Bug Bounty2021-10-092023-06-13
2162Power of Your Own Wordlist — Fuzz for Log File Leads to Information Leakage Information disclosure NA MikeChan Bug Bounty2021-10-092023-06-13
2161Auth Bypass in Google Assistant Insecure deeplink Google David Schütz (@xdavidhu) Bug Bounty2021-10-102023-06-13
2160Account Takeover — Story of 2 same issues in a single program but different sub-domains. Account takeover NA Himanshu Pdy (@himanshu_pdy) Bug Bounty2021-10-102023-06-13
2159Stumbling across a DOM XSS on google.com DOM XSS Google tkiela (@svennergr) Bug Bounty2021-10-102023-06-13
2158How I got $500 with Open redirect Open redirect NA khan mamun (@mamunwhh) Bug Bounty2021-10-102023-06-13
2157How I Hacked Billion Android Users Social And 3rd Party Account | A Story About 5000$ Bug Android Google Karthikeyan.V (@karthithehacker) Bug Bounty2021-10-102023-06-13
2156Exploiting HTML-to-PDF Converters through HTML Imports XSS LFI NA Mohammed Diaa (@mhmdiaa) Bug Bounty2021-10-102023-06-13
2155Hacking YouTube With MP4 Logic flaw DoS Google KeyboardWarrior (@Keyb0ardWarr10r) Bug Bounty2021-10-112023-06-13
2154Pulse Secure version number disclosure in error messages Information disclosure Pulse Secure Mehdi Alouache Bug Bounty2021-10-122023-06-13
2153ESET Endpoint Security credentials theft Credentials sent over unencrypted channel MiTM ESET Mehdi Alouache Bug Bounty2021-10-122023-06-13
2152Stealing all your secrets using IPFS Mounts Web3 hacking Local Privilege Escalation Filecoin Security Joran Honig (@joranhonig) Bug Bounty2021-10-122023-06-13
2151Bypassing required reviews using GitHub Actions Privilege escalation Logic flaw GitHub Omer Gil (@omer_gil) Bug Bounty2021-10-122023-06-13
2150ESET Endpoint Security credentials theft Credentials sent over unencrypted channel ESET Mehdi Alouache Bug Bounty2021-10-122023-06-13
2149Abusing Slack’s file-sharing functionality to de-anonymise fellow workspace members XSLeaks Slack Julien Cretel (@jub0bs) Bug Bounty2021-10-122023-06-13