Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
4444Story of Stored Xss XSS NA Walid Hossain (@NoobWalid) Bug Bounty2018-11-282023-06-13
4443Exploiting post message to steal and replace user’s cookies postMessage NA Yasser Gersy (@yassergersy) Bug Bounty2018-11-302023-06-13
4441Love Story Of A Account Takeover (Chaining Host Header Injection To Takeover Someones Account) Host header injection NA Logical Bimboo Bug Bounty2018-11-302023-06-13
4435Taking over Google calendar of a company Subdomain takeover NA Daniel V. (@d4niel_v) Bug Bounty2018-12-042023-06-13
4433XSS to XXE in Prince v10 and below (CVE-2018-19858) XSS XXE NA Corben Leo (@hacker_) Bug Bounty2018-12-052023-06-13
4429How I was Able To Bypass Email Verification Information disclosure NA Muzammil Kayani (@muzammilabbas2) Bug Bounty2018-12-082023-06-13
4427Change Anyone’s profile picture-Exploiting IDOR IDOR NA Rupika Luhach (@Rup_Ki_Rani) Bug Bounty2018-12-092023-06-13
4425Token Brute-Force to Account Take-over to Privilege Escalation to Organization Take-Over Account takeover Privilege escalation Bruteforce NA Plenum (@plenumlab) Bug Bounty2018-12-102023-06-13
4421How i was able to pwned application by Bypassing Cloudflare WAF WAF bypass NA gujjuboy10x00 (@vis_hacker) Bug Bounty2018-12-122023-06-13
4418[Open redirect] Developers are lazy(or maybe busy) Open redirect NA KatsuragiCSL (@ZuuitterE) Bug Bounty2018-12-122023-06-13
4417Exploiting XXE with local DTD files XXE NA Arseniy Sharoglazov (@_mohemiv) Bug Bounty2018-12-132023-06-13
4416#BugBounty — “User Account Takeover-I just need your email id to login into your shopping portal account” OAuth Authentication bypass Account takeover NA Avinash Jain (@logicbomb_1) Bug Bounty2018-12-132023-06-13
4415Chaining Two Vulnerabilities to Break Facebook Appointment Times For the Second Time Logic flaw Application-level DoS Meta / Facebook Max Pasqua Bug Bounty2018-12-142023-06-13
4413$3k Bug Bounty - Twitter%27s OAuth Mistakes OAuth Twitter Terence Eden (@edent) Bug Bounty2018-12-142023-06-13
4412XSSing Google Code-in thanks to improperly escaped JSON data XSS Google Thomas Orlita (@ThomasOrlita) Bug Bounty2018-12-142023-06-13
4410CVE-2018-20139 - Daikin Emura Series - Arbitrary Remote Control via DNS Rebinding DNS rebinding Daikin Europe void (@voidz0r) Bug Bounty2018-12-142023-06-13
4409Self XSS to Interesting Stored XSS Stored XSS NA Rohan aggarwal (@nahoragg) Bug Bounty2018-12-152023-06-13
4408Accessing VoIP Internal service via Port 8009: Routing traffic through local Apache proxy Information disclosure NA Ahmed A. Sherif Bug Bounty2018-12-162023-06-13
4407Reading ASP secrets for $17,000 Local file disclosure (LFD) NA Sam Curry (@samwcyo) Bug Bounty2018-12-162023-06-13
4406Subdomain Takeover — New Level Subdomain takeover NA Valeriy Shevchenko (@Krevetk0Valeriy) Bug Bounty2018-12-172023-06-13
4403Exploiting Two Endpoints to get Account Takeover Authorization flaw Privilege escalation NA Hritik Sharma Bug Bounty2018-12-192023-06-13
4401Facebook BugBounty - Disclosing page members Information disclosure Meta / Facebook Nirmal Thapa / mpz (@tnirmalz) Bug Bounty2018-12-202023-06-13
4397Client side validation strikes again: PIN code bypass ! Client-side enforcement of server-side security Authentication bypass Authorization flaw Netflix Linxo Davy (@RandoriSec) Bug Bounty2018-12-222023-06-13
4396Server-side Request Forgery in OpenID support SSRF Liberapay Putra Adhari Bug Bounty2018-12-242023-06-13
4391Reflected XSS on ws-na.amazon-adsystem.com(Amazon) Reflected XSS Amazon ssid (@newp_th) Bug Bounty2018-12-272023-06-13