Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
4016How I found the most critical bug in live bug bounty event? Password reset Account takeover NA Lakshay (@inn0c3ntd3v1L) Bug Bounty2019-07-242023-06-13
4014Full Account Takeover via Changing Email And Password of any User through API Parameters IDOR Password reset Account takeover NA Adesh Nandkishor kolte (@AdeshKolte) Bug Bounty2019-07-262023-06-13
4010Chaining Cache Poisoning To Stored XSS Web cache poisoning Stored XSS NA Rohan aggarwal (@nahoragg) Bug Bounty2019-07-282023-06-13
4009Old GitHub Profile Takeover! Github account takeover NA Mohamed Haron (@m7mdharon) Bug Bounty2019-07-282023-06-13
4008Story of an IDOR via Email IDOR NA Shuaib Oladigbolu (@_sawzeeyy) Bug Bounty2019-07-292023-06-13
40071st Bounty Story | Rewarded 300$ (IDOR) IDOR NA Md Hridoy Bug Bounty2019-07-292023-06-13
4006SQL Injection in private-site.com/login.php SQL injection NA Mohamed Haron (@m7mdharon) Bug Bounty2019-07-302023-06-13
4005Paypal bug $10K - All Secondary users account takeover leads to unauthorized money transfer from paypal business accounts IDOR Paypal Mohd haji (@mohdhaji24) Bug Bounty2019-07-302023-06-13
4002RCE in Ruby using Mustache Templates RCE NA Rhys Elsmore (@rhyselsmore) Bug Bounty2019-08-012023-06-13
4001Bypassing CORS CORS misconfiguration NA Saad Ahmed (@XSaadAhmedX) Bug Bounty2019-08-012023-06-13
3996One Misconfig (JIRA) to Leak Them All- Including NASA and Hundreds of Fortune 500 Companies! Information disclosure NA Avinash Jain (@logicbomb_1) Bug Bounty2019-08-022023-06-13
3995From Sub domain Takeover to Open-Redirect Subdomain takeover Open redirect NA Anil Tom (mr_4nk) Bug Bounty2019-08-022023-06-13
3994No Rate limiting eligible for bounty ? Lack of rate limiting NA Smaran Chand (@smaranchand) Bug Bounty2019-08-032023-06-13
3993How I Found XSS By Searching In Shodan Reflected XSS NA D1vy4n5hu 5hukl4 (@justm0rph3u5) Bug Bounty2019-08-042023-06-13
3992Leveraging AngularJS-based XSS to Privilege Escalation XSS Privilege escalation NA Shawar Khan (@ShawarkOFFICIAL) Bug Bounty2019-08-042023-06-13
3990BugBounty WriteUp — Creative thinking is our everything (Race Condition + Business Logic Error) Race condition Logic flaw NA Oleksandr Opanasiuk (@Lekssik2) Bug Bounty2019-08-052023-06-13
3989Exploiting Out Of Band XXE using internal network and php wrappers XXE NA Mahmoud Gamal (@Zombiehelp54) Bug Bounty2019-08-062023-06-13
3988self XSS to stored XSS [ think out the box] Self-XSS Stored XSS TIBCO Abdelhak Kharroubi Bug Bounty2019-08-062023-06-13
3985LAN-Based Blind SSRF Attack Primitive for Windows Systems (switcheroo) SSRF Microsoft initstring (@init_string) Bug Bounty2019-08-092023-06-13
3983Privilege Escalation using Api endpoint Privilege escalation NA Ronak Patel (@ronak_9889) Bug Bounty2019-08-092023-06-13
3982Read other user support tickets in https://support..com (Write Up) IDOR NA Evan Ricafort (@evanricafort) Bug Bounty2019-08-092023-06-13
3980Application Level Denial of Service [DoS] using SVG file in https://[REDACTED].com (Write Up) Application-level DoS NA Evan Ricafort (@evanricafort) Bug Bounty2019-08-102023-06-13
3978Reporting - Amazon 1 click device XSS XSS Amazon Sneakerhax (@sneakerhax) Bug Bounty2019-08-122023-06-13
3977SSRF Vulnerability in https://app.[REDACTED].com SSRF NA Evan Ricafort (@evanricafort) Bug Bounty2019-08-132023-06-13
3975BugBounty WriteUp — take attention and get Stored XSS Stored XSS NA Oleksandr Opanasiuk (@Lekssik2) Bug Bounty2019-08-142023-06-13