Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
4135Multiple API issues due to Fixed Authorization token. Authorization flaw NA Mustafa Khan (@by6153) Bug Bounty2019-05-242023-06-13
4133How did I bypass a Custom Brute Force protection and why that solution is not a good idea? Bruteforce Authentication flaw NA dortz Bug Bounty2019-05-252023-06-13
4132An unexploited CORS misconfiguration reflecting further issues. CORS misconfiguration NA Smaran Chand (@smaranchand) Bug Bounty2019-05-272023-06-13
4130Exploiting File Uploads Pt. 1 – MIME Sniffing to Stored XSS #bugbounty Stored XSS MIME sniffing NA HackerOn2Wheels (@HackerOn2Wheels) Bug Bounty2019-05-302023-06-13
4129My First CSRF to Account Takeover worth $750 CSRF Account takeover NA Nishant Saurav (@inishantsinha) Bug Bounty2019-05-302023-06-13
4127Story of a uri based xss with some simple google dorking XSS NA Jatin Aesthetic (@techyfreakk) Bug Bounty2019-06-022023-06-13
4126The Unusual Case of Status code- 301 Redirection to AWS Security Credentials Compromise SSRF RFI NA Avinash Jain (@logicbomb_1) Bug Bounty2019-06-022023-06-13
4124Simple PathTraversal bypass Path traversal NA fr0stNuLL Bug Bounty2019-06-032023-06-13
4123Chaining multiple low-impact bugs to arbitrary file read in GitLab Path traversal GitLab Li Rongxi (@nyan_gawa) Bug Bounty2019-06-042023-06-13
4122REMOTE CODE EXECUTION ! 😜 Recon Wins RCE NA Vishnuraj Bug Bounty2019-06-042023-06-13
4120Unicode vs WAF — XSS WAF Bypass XSS NA Prial Islam Khan (@prial261) Bug Bounty2019-06-052023-06-13
4118How I was able to get private ticket response panel and FortiGate web panel via blind XSS Blind XSS NA Bijan Murmu (@0xBijan) Bug Bounty2019-06-062023-06-13
4116IDOR Leads To Project Takeover IDOR NA Hariharan.s (@DJHARIZ1) Bug Bounty2019-06-092023-06-13
4115Account takeover using IDOR and the misleading case of error 403. IDOR NA Plenum (@plenumlab) Bug Bounty2019-06-112023-06-13
4114Facebook Vulnerability: Non-unfriendable user in /hacked workflow Logic flaw Meta / Facebook Ritish Kumar Singh Bug Bounty2019-06-112023-06-13
4113Reflected XSS on Error Page Reflected XSS NA Tomi (@noobe_io) Bug Bounty2019-06-112023-06-13
4112Redstrom Denial Of Service — Write Up DoS NA Zerb0a Bug Bounty2019-06-122023-06-13
4111Chaining Improper Authorization To Race Condition To Harvest Credit Card Details : A Bug Bounty Story Authorization flaw Race condition NA Mandeep Jadon (@1337tr0lls) Bug Bounty2019-06-132023-06-13
4110How spending our Saturday hacking earned us 20k IDOR NA Matti Bijnens (@MattiBijnens) Bug Bounty2019-06-142023-06-13
4109IDOR — Account Takeover IDOR NA Saad Ahmed (@XSaadAhmedX) Bug Bounty2019-06-142023-06-13
4107Admin Account total Information Disclosure Source code disclosure Information disclosure NA Nishant Saurav (@inishantsinha) Bug Bounty2019-06-152023-06-13
4104Complete Web Server Access Unrestricted file upload RCE NA Saad Ahmed (@XSaadAhmedX) Bug Bounty2019-06-152023-06-13
4103Bug Bounty - Information Disclosure through error message + WAF Bypass led to Local File Inclusion WAF bypass LFI Information disclosure NA Λявєη (@spenkkkkk) Bug Bounty2019-06-152023-06-13
4102Stealing Cookies to Login in any Account Cookie theft NA Osama Avvan (@osamaavvan) Bug Bounty2019-06-162023-06-13
4101Account Takeover Worth $900 Account takeover CSRF NA Saad Ahmed (@XSaadAhmedX) Bug Bounty2019-06-162023-06-13