Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
1519How an Open Redirection Leads to an Account Takeover? Open redirect Account takeover NA Mahendra Purbia (@Mah3Sec_) Bug Bounty2022-05-262023-06-13
1518Social Media Take Over = Easy Money Broken link hijacking NA Jesse Clark (@Hogarth45_) Bug Bounty2022-05-262023-06-13
1517DNN CMS Server-Side Request Forgery (CVE-2021-40186) SSRF Security code review DNN (DotNetNuke) Appcheck NG Bug Bounty2022-05-262023-06-13
1516Bygone Vulnerabilities - Remote Code Execution in IBM Lotus SameTime Clients (CVE-2013-0553) XSS RCE IBM Brian (@hoyahaxa) Bug Bounty2022-05-272023-06-13
1515A Simple SQL Injection in an Air Force Website SQL injection U.S. Dept Of Defense Corben Leo (@hacker_) Bug Bounty2022-05-272023-06-13
1514Weird Email Verification Bypass Email verification bypass NA Vaibhav Atkale Bug Bounty2022-05-282023-06-13
1513Hall of Fame Vice Media ? hacking while sleepy… Subdomain takeover Vice Media Muhammad Syahrul Haniawan Bug Bounty2022-05-292023-06-13
1512Exploiting iOS app for fun and profit Account takeover Information disclosure NA Bijan Murmu (@0xbijan) Bug Bounty2022-05-292023-06-13
1511External Authentication bypass in ingress-nginx Path traversal Authentication bypass Kubernetes Niemiec Marcin (@xvnpw) Bug Bounty2022-05-292023-06-13
1510DOMAIN ADMIN Compromise in 3 HOURS Default credentials NA popalltheshells Bug Bounty2022-05-292023-06-13
1509Bypass CSP Using WordPress By Abusing Same Origin Method Execution CSP bypass Same Origin Method Execution WordPress Paulos Yibelo (@PaulosYibelo) Bug Bounty2022-05-292023-06-13
1508How to find & access Admin Panel by digging into JS files…🥰 Weak credentials WAF bypass NA Ratnadip Gajbhiye (@scspcommunity) Bug Bounty2022-05-302023-06-13
1507Abusing Facebook’s feature for a permanent account confusion(logic vulnerability) MFA bypass DoS Logic flaw Meta / Facebook Liv Bug Bounty2022-05-312023-06-13
1506From open redirect to RCE in one week Open redirect SSRF Insecure deserialization LFI RCE Mail.ru byq (@ByQwert) Bug Bounty2022-05-312023-06-13
1505SQL injection to Remote Command Execution (RCE) SQL injection RCE NA Kwadwo Amoako Bug Bounty2022-05-312023-06-13
1504How I found a GoldMine but got No Gold Old components with known vulnerabilities NA Muhammad Abdullah Bug Bounty2022-06-012023-06-13
1503Microsoft Dynamics Container Sandbox RCE via Unauthenticated Docker Remote API 20,000$ Bounty RCE Microsoft Chen Cohen (@chencococococo) Bug Bounty2022-06-012023-06-13
1502How I Mass hunt for Admin Panel Access…🤩 Default credentials Gemeente Delft (The City of Delft) Ratnadip Gajbhiye (@scspcommunity) Bug Bounty2022-06-022023-06-13
1501Is Exploiting A Null Pointer Deref For LPE Just A Pipe Dream? Memory corruption Microsoft (Bitdefender) Michael DePlante (@izobashi) Bug Bounty2022-06-022023-06-13
1500How Attacker could have suffocated the company staff Default credentials NA Muhammad Abdullah Bug Bounty2022-06-052023-06-13
1499If It’s a Feature!!! Let’s Abuse It for $750 CSRF NA Shakti Mohanty (@3ncryptSaan) Bug Bounty2022-06-052023-06-13
1498Ivanti EPM Remote Code Execution RCE Components with known vulnerabilities NA Nick Berrie (@machevalia) Bug Bounty2022-06-052023-06-13
1497Another vision for SSRF SSRF NA phor3nsic (@phor3nsic_br) Bug Bounty2022-06-062023-06-13
1496Multiple vulnerabilities in Zyxel zysh OS command injection Memory corruption Zyxel Marco Ivaldi / Raptor (@0xdea) Bug Bounty2022-06-072023-06-13
1495An unusual way to find XSS injection in one minute CSTI XSS TimeWeb Andrey Onishchenko Bug Bounty2022-06-072023-06-13