Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
4059Account Takeover Using CSRF(json-based) CSRF Account takeover NA shub rathore (@shub66452) Bug Bounty2019-07-042023-06-13
4058Facebook Vulnerability: Unremovable Co-Host in facebook page events Logic flaw DoS Meta / Facebook Ritish Kumar Singh Bug Bounty2019-07-042023-06-13
4056Blind (time-based) SQLi - Bug Bounty SQL injection NA jspin (@jespinhara) Bug Bounty2019-07-052023-06-13
4055Cleartext password in LocalStorage (Writeup) Violation of secure design principles NA ruvlol Bug Bounty2019-07-072023-06-13
4054Information Disclosure via Misconfigured AWS to AWS Bucket Takeover AWS misconfiguration NA Pratyush Anjan Sarangi Bug Bounty2019-07-082023-06-13
4052OAuth authentication bypass on Airbnb acquisition using 1-char Open Redirect Open redirect Token leak Account takeover Airbnb Evgeniy Yakovchuk (@h1_sp1d3r) Bug Bounty2019-07-102023-06-13
4051Tale of account takeover — Sensitive info Disclosure + Broken Access Control IDOR Account takeover NA Md Saqib (@sakyb7) Bug Bounty2019-07-102023-06-13
4050SQL Injection Bug Bounty POC! SQL injection NA Arif-ITSEC111 Bug Bounty2019-07-112023-06-13
4049Story of my Biggest Bounty ever : Command Execution on Jenkins RCE Exposed Jenkins instance NA Jay Jani (@JayJani007) Bug Bounty2019-07-112023-06-13
4046Account takeover on Airbnb acquisition | An Unusual Bug Part-2 🐛 IDOR Account takeover Airbnb PRince CHaddha (@princechaddha) Bug Bounty2019-07-132023-06-13
4042[TOKOPEDIA] Site-wide CSRF through GraphQL request CSRF Tokopedia Rafie Muhammad (@rafiem777) Bug Bounty2019-07-152023-06-13
4039The Bugs Are Out There, Hiding in Plain Sight IDOR SSRF Information disclosure CORS misconfiguration NA A Bug’z Life (@abugzlife1) Bug Bounty2019-07-152023-06-13
4037What do Netcat, SMTP and self XSS have in common? Stored XSS Stored XSS NA Plenum (@plenumlab) Bug Bounty2019-07-162023-06-13
4036Bypass CSRF With ClickJacking Worth $1250 CSRF Clickjacking NA Saad Ahmed (@XSaadAhmedX) Bug Bounty2019-07-162023-06-13
4035CSRF Email Confirmation Vulnerability for Gmail & G-Suite in Facebook CSRF Meta / Facebook Lokesh Kumar (@lokeshdlk77) Bug Bounty2019-07-162023-06-13
4032Account Takeover Vulnerability :) Password reset Account takeover NA Sumit Jain (@sumit_cfe) Bug Bounty2019-07-172023-06-13
4031Сookie-based XSS exploitation | $2300 Bug Bounty story XSS NA Max (@iSecMax) Bug Bounty2019-07-172023-06-13
4029SQL Injection in Forget Password Function SQL injection NA Khaled Gaber Bug Bounty2019-07-182023-06-13
4028Microsoft Office 365 - Outlook XSS XSS Microsoft Abdulrahman Alqabandi (@Qab) Bug Bounty2019-07-192023-06-13
4025Exploiting a Tricky Blind SQL Injection inside LIMIT clause SQL injection NA Rahul Maini (@iamnoooob) Bug Bounty2019-07-212023-06-13
4024Shopping Products For Free- Parameter Tampering Vulnerability Parameter tampering Payment tampering NA D1vy4n5hu 5hukl4 (@justm0rph3u5) Bug Bounty2019-07-212023-06-13
4022Not a fancy bug, just HTML Injection in Clause - clause.io (Write Up) HTML injection Clause Evan Ricafort (@evanricafort) Bug Bounty2019-07-212023-06-13
4020XSS On Twitter [Worth 1120$] XSS NA Bywalks (@bywalkss) Bug Bounty2019-07-222023-06-13
4019Pwning child company to get access to ParentCompany%27s Slack Team SQL injection Default credentials NA Parth Malhotra (@Parth_Malhotra)< Bug Bounty2019-07-232023-06-13
4017Disclose any main and 3rd party contributors email address and movie local path thru XML file in Plex TV - plex.tv (Write Up) Information disclosure Internal path disclosure Plex Evan Ricafort (@evanricafort) Bug Bounty2019-07-242023-06-13