Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
4873Internal IPs disclosure Information disclosure Nokia Omar Espino (@omespino) Bug Bounty2018-02-022023-06-13
4866Bug bounty left over (and rant) Part III (Google and Twitter) OAuth Authentication flaw Information disclosure Google Twitter Antonio Sanso (@asanso) Bug Bounty2018-02-062023-06-13
4865Taking over Facebook accounts using Free Basics partner portal Information disclosure IDOR Meta / Facebook Josip Franjkovic (@josipfranjkovic) Bug Bounty2018-02-072023-06-13
4844The 2.5mins or 2.5k$ hawk-eye bug – A Facebook Pages Admins Disclosure Vulnerability! Information disclosure Meta / Facebook Mohamed A. Baset Bug Bounty2018-02-252023-06-13
4841Facebook Bug Bounty Reports Authorization flaw Logic flaw Information disclosure Meta / Facebook Raushan Raj (@raushan_rajj) Bug Bounty2018-03-062023-06-13
4838Getting any Facebook user%27s friend list and partial payment card details Information disclosure IDOR Meta / Facebook Josip Franjkovic (@josipfranjkovic) Bug Bounty2018-03-092023-06-13
4794Whatsapp user’s IP disclosure with Link Preview feature Information disclosure Meta / Facebook Rahul Kankrale (@RahulKankrale) Bug Bounty2018-04-182023-06-13
4771Asus Control Center – An Information Disclosure and a database connection Clear-Text password leakage Vulnerability Authorization flaw Information disclosure Asus Mohamed A. Baset Bug Bounty2018-05-082023-06-13
4769How I used a simple Google query to mine passwords from dozens of public Trello boards Authorization flaw Information disclosure Trello Kushagra Pathak (@xKushagra) Bug Bounty2018-05-092023-06-13
4762How i got 100$ from one private website Information disclosure NA Aayush Pokhrel (@aayushpok) Bug Bounty2018-05-192023-06-13
4734How I was able to list some internal information from PayPal #BugBounty Expression Language Injection (JSTL) Information disclosure Paypal Adrien Jeanneau (@adrien_jeanneau) Bug Bounty2018-06-072023-06-13
4720Manage Engine OpManager Multiple Authenticated RCE Vulnerabilities RCE Path traversal Unrestricted file upload Information disclosure Arbitrary file write Zoho (ManageEngine) Denis Andzakovic Bug Bounty2018-06-182023-06-13
4708This popular Facebook app publicly exposed your data for years Information disclosure Authorization flaw Meta / Facebook Nametests.com Inti De Ceukelaire (@securinti) Bug Bounty2018-06-282023-06-13
4706https://leigh-annegalloway.com/tumblr/ Captcha bypass Username enumeration Information disclosure Automattic Leigh-Anne Galloway (@L_AGalloway) Bug Bounty2018-06-292023-06-13
4695Should this be public though? Information disclosure Shopify Uber Rojan Rijal (@uraniumhacker) Bug Bounty2018-07-132023-06-13
4688Hey Developer, Give me your API keys.!! Information disclosure Crowdin Devansh batham (@devanshwolf) Bug Bounty2018-07-182023-06-13
4682RCE due to ShowExceptions RCE Information disclosure Debugging enabled NA Harsh Jaiswal (@rootxharsh) Bug Bounty2018-07-202023-06-13
4678Finding hidden gems vol. 1: forging OAuth tokens using discovered client id and client secret Information disclosure NA Mateusz Olejarka (@molejarka) Bug Bounty2018-07-232023-06-13
4668Hacking Imgur for Fun and Profit Outdated component with a known vulnerability Information disclosure Imgur Nathan (@NathOnSecurity) Bug Bounty2018-07-292023-06-13
4652How I gained commit access to Homebrew in 30 minutes Information disclosure Homebrew Eric Holmes (@vesirin) Bug Bounty2018-08-072023-06-13
4651From data leak to account takeover Account takeover Information disclosure Password reset NA Antony Garand (@AntoGarand) Bug Bounty2018-08-072023-06-13
4647My Disclosed Report about Basic auth Api details at Reverb.com Information disclosure Reverb Mohamed Haron (@m7mdharon) Bug Bounty2018-08-092023-06-13
4643[Twitter Bug Bounty] Misconfigured JSON endpoint on ads.twitter.com lead to Access control issue and Information Disclosure of role privileged users. Authorization flaw Information disclosure Twitter Peerzada Fawaz Ahmad Qureshi Bug Bounty2018-08-102023-06-13
4642Misconfigured JIRA setting - Apigee Information disclosure Google Atlassian Tutorgeeks Bug Bounty2018-08-102023-06-13
4629API key: The real goldmine Information disclosure NA Yumi Bug Bounty2018-08-192023-06-13