Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
3495DOM-Based XSS at accounts.google.com by Google Voice Extension. DOM XSS Google missoum1307 (@missoum1307) Bug Bounty2020-05-072023-06-13
3494I Found XSS Security Flaws in Rails – Here%27s What Happened. XSS Ruby on Rails Jesse Campos Bug Bounty2020-05-072023-06-13
3493$20000 Facebook DOM XSS DOM XSS Meta / Facebook Vinoth Kumar (@vinodsparrow) Bug Bounty2020-05-072023-06-13
3491Bypass XSS filter using HTML Escape XSS Google Syahri Ramadan (@adonkidz7) Bug Bounty2020-05-082023-06-13
3482How I got my first swag on Edmodo with a simple XSS. Stored XSS Edmodo Sanjay Verdu (@codersanjay) Bug Bounty2020-05-162023-06-13
3480Chained Bugs [ Account TakeOver ] IDOR XSS Account takeover NA Bilal Khan (@bilalmerokhel) Bug Bounty2020-05-162023-06-13
3477One Param => $10k IDOR XSS Account takeover NA Bilal Khan (@bilalmerokhel) Bug Bounty2020-05-172023-06-13
3476Stored XSS Leads to Plaintext Password Disclosure Stored XSS Information disclosure Unrestricted file upload NA bad5ect0r (@bad5ect0r) Bug Bounty2020-05-172023-06-13
3474Cors Blimey: The power of chaining CORS CORS misconfiguration Stored XSS CSRF NA Hazana (@hazanasec) Bug Bounty2020-05-172023-06-13
3461Parsing the DOM elements of Other pages via XSS: A Bug Bounty Story XSS Information disclosure NA Mandeep Jadon (@1337tr0lls) Bug Bounty2020-05-222023-06-13
3458Story About OTP Bypass To Stored XSS OTP bypass Stored XSS NA PJ Borah (@PJBorah1) Bug Bounty2020-05-232023-06-13
3455Bug Hunting Stories: Schneider Electric & The Andover Continuum Web.Client XXE Reflected XSS Uber Niv Levy (@restr1ct3d) Bug Bounty2020-05-272023-06-13
3453Stored XSS in Yahoo mail IOS app($3500) Stored XSS Yahoo! / Verizon Media kminthein / weev3 (@kyawminthein99) Bug Bounty2020-05-282023-06-13
3452Stored XSS in Microsoft outlook Stored XSS Microsoft kminthein / weev3 (@kyawminthein99) Bug Bounty2020-05-282023-06-13
3451iOS Outlook Stored XSS Write-Up($3000) XSS Microsoft kminthein / weev3 (@kyawminthein99) Bug Bounty2020-05-282023-06-13
3447Bypassing WAF to perform XSS XSS NA Kleiton Kurti (@kleiton0x7e) Bug Bounty2020-05-282023-06-13
3446XSS Stored On Messages In [ Outlook Web — Outlook Android App ] Stored XSS Microsoft ElMahdi Mrhassel (@ElMrhassel) Bug Bounty2020-05-282023-06-13
3438Cross-site scripting: The power of the hidden parameters. Reflected XSS Sony Kassih Mouhssine (@KassihMouhssine) Bug Bounty2020-05-302023-06-13
3432How I leveraged an interesting CSRF vulnerability to turn self XSS into a persistent attack? Self-XSS CSRF NA Akash Methani (@0xAkash) Bug Bounty2020-06-012023-06-13
3431Information disclosure and reflected XSS on Tokopedia Reflected XSS Information disclosure Tokopedia wis4nggeni Bug Bounty2020-06-012023-06-13
3429Double URL-encoded XSS Reflected XSS NA vict0ni (@vict0ni) Bug Bounty2020-06-022023-06-13
3428The Curious Case of Copy & Paste – on risks of pasting arbitrary content in browsers XSS Google Mozilla Michał Bentkowski (@SecurityMB) Bug Bounty2020-06-022023-06-13
3426From CRLF to Account Takeover CRLF injection HTTP response splitting Reflected XSS Account takeover NA Valeriy Shevchenko (@Krevetk0Valeriy) Bug Bounty2020-06-032023-06-13
3419Local file read via XSS using PDF generate functionality XSS LFI NA Sanjay Singh Jhala (@lordjerry0x01) Bug Bounty2020-06-052023-06-13
3415XSS to Database Credential Leakage & Database Access — Story of total luck! Reflected XSS Information disclosure NA Harsh Bothra (@harshbothra_) Bug Bounty2020-06-062023-06-13