Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
1159Bypassing ModSecurity for RCEs WAF bypass Code injection RCE ModSecurity Somdev Sangwan (s0md3v) Bug Bounty2022-08-292023-06-13
1086Data Exfiltration through Blind XXE on PDF Generator Blind XXE WAF bypass NA Arben Shala (@arbennsh) Bug Bounty2022-09-132023-06-13
1042WAF bypasses via 0days WAF bypass Content-type confusion Charset confusion ModSecurity Terjanq (@terjanq) Bug Bounty2022-09-232023-06-13
996Error based SQL Injection with WAF bypass manual Exploit 100% SQL injection WAF bypass NA Ahmed Qaramany (@c0nqr0r) Bug Bounty2022-10-062023-06-13
977Web application firewall bypass WAF bypass NA - Bug Bounty2022-10-112023-06-13
813Bypassing XSS filters using Double Encoding XSS WAF bypass NA ag3n7 (@ag3n7apk) Bug Bounty2022-11-182023-06-13
729Bug Writeup: RCE via SSTI on Spring Boot Error Page with Akamai WAF Bypass SSTI RCE WAF bypass GitHub Peter M (@h1pmnh) Bug Bounty2022-12-042023-06-13
717{JS-ON: Security-OFF}: Abusing JSON-Based SQL to Bypass WAF WAF bypass SQL injection Palo Alto Networks AWS Cloudflare F5 Imperva Noam Moshe Bug Bounty2022-12-082023-06-13
712Automate Cross-Site Scripting (XSS) exploitation with unusal events and Burp Intruder XSS WAF bypass NA Riccardo Malatesta (@seeu_inspace) Bug Bounty2022-12-102023-06-13
698Exploiting an SQL injection with WAF bypass SQL injection WAF bypass NA Benoit Philippe Bug Bounty2022-12-132023-06-13
697Doing it the researcher’s way: How I Managed to Get SSTI (Server Side Template Injection) which lead to arbitrary file reading on One of the Leading Payment Systems in Asia SSTI WAF bypass NA JzeeRx Bug Bounty2022-12-132023-06-13
636Exploring the World of ESI Injection ESI injection WAF bypass XSS NA Sudhanshu Rajbhar (@sudhanshur705) Bug Bounty2022-12-292023-06-13
558Bypassing Cloudflare WAF: XSS via SQL Injection Reflected XSS SQL injection WAF bypass NA Uku Sõrmus Bug Bounty2023-01-212023-06-13
481Reflected XSS on Target with tough WAF ( WAF Bypass ) Reflected XSS WAF bypass NA Eagle_92 Bug Bounty2023-02-082023-06-13
454SQL Injection: Utilizing XML Functions in Oracle and PostgreSQL to bypass WAFs SQL injection WAF bypass NA Mahmoud Gamal (@Zombiehelp54) Bug Bounty2023-02-132023-06-13
428Bypassing Akamai’s Web Application Firewall Using an Injected Content-Encoding Header WAF bypass CRLF injection XSS Akamai Adam Crosser Bug Bounty2023-02-212023-06-13
322Rxss inside href attribute - Bypassing lots of weird checks to takeover accounts! Reflected XSS WAF bypass NA Ashutosh Dutta (@maniacmarvel_) Bug Bounty2023-03-102023-06-13
177How I hacked hackers in Voorivex Hunt Event Cloudflare bypass WAF bypass Account takeover NA snoopy (@snoopy101101) Bug Bounty2023-04-192023-06-13
141Bug Bounty Writeup: Stored XSS Vulnerability WAF Bypass Stored XSS WAF bypass NA Rafael Silva "lopseg" Bug Bounty2023-05-012023-06-13
122A smorgasbord of a bug chain: postMessage, JSONP, WAF bypass, DOM-based XSS, CORS, CSRF… postMessage JSONP DOM XSS CORS misconfiguration CSRF WAF bypass NA Julien Cretel (@jub0bs) Bug Bounty2023-05-052023-06-13
115How I discovered XSS via triple URL encode XSS WAF bypass NA Muhammed Mubarak Bug Bounty2023-05-072023-06-13
35Bypassing An Industry-Leading WAF and Exploiting SQLi SQL injection WAF bypass NA Adeeb Shah Bug Bounty2023-06-012023-06-13
33Prototype Pollution Akamai Client-side prototype pollution WAF bypass NA Sudhanshu Rajbhar (@sudhanshur705) Bug Bounty2023-06-032023-06-13