Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
4637IDOR leads to getting Access tokens of users linked to Google Drive on Edmodo IDOR Edmodo Aagam shah (@neutrinoguy) Bug Bounty2018-08-122023-06-13
4636XSS at Hubspot and XSS in email areas. XSS HubSpot Friendly (@SkeletorKeys) Bug Bounty2018-08-132023-06-13
4635Another "TicketTrick" story Ticket Trick Logic flaw Uber Rojan Rijal (@uraniumhacker) Bug Bounty2018-08-142023-06-13
4634IDOR leads to account takeover IDOR NA s0cket7 (@s0cket7) Bug Bounty2018-08-162023-06-13
46333 Minutes & XSS! XSS Edmodo Ashish Jha Bug Bounty2018-08-172023-06-13
4632YAHOO IDOR -elimination of any comment IDOR Yahoo! / Verizon Media Bada Diaz (@bada77) Bug Bounty2018-08-172023-06-13
4631User credential are sent in clear text in Whatsapp web— FIXED | Facebook Bug Bounty Credentials sent over unencrypted channel Meta / Facebook Thuvarakan Nakarajah Bug Bounty2018-08-182023-06-13
4630https://www.updatelap.com/2018/08/privileged-escalation-in-facebook-rooms.html Authorization flaw Privilege escalation Meta / Facebook Jafar Abo Nada (@Jafar_Abo_Nada) Bug Bounty2018-08-182023-06-13
4629API key: The real goldmine Information disclosure NA Yumi Bug Bounty2018-08-192023-06-13
4628Liking GitHub repositories on behalf of other users — Stored XSS in WebComponents.org Stored XSS Webcomponents.org Thomas Orlita (@ThomasOrlita) Bug Bounty2018-08-232023-06-13
4627SQL Injection Vulnerability In University Of Cambridge SQL injection Cambridge Adesh Nandkishor kolte (@AdeshKolte) Bug Bounty2018-08-242023-06-13
4626Privileged Escalation in Facebook Messenger Rooms Privilege escalation IDOR Meta / Facebook Jafar Abo Nada (@Jafar_Abo_Nada) Bug Bounty2018-08-242023-06-13
4625Remote Code Execution on a Facebook server RCE Meta / Facebook Daniel Le Gall (@Blaklis_) Bug Bounty2018-08-242023-06-13
4624My first valid xss(@Hackerone) XSS NA Jatin Aesthetic (@techyfreakk) Bug Bounty2018-08-252023-06-13
4623Traversing the Path to RCE Path traversal RCE NA hawkinsecurity Bug Bounty2018-08-272023-06-13
4622IDOR FACEBOOK: malicious person add people to the “Top Fans” IDOR Meta / Facebook Jafar Abo Nada (@Jafar_Abo_Nada) Bug Bounty2018-08-282023-06-13
4621How i found a 1500$ worth Deserialization vulnerability Misconfigured JSF ViewState Insecure deserialization NA Ashish Kunwar (@D0rkerDevil) Bug Bounty2018-08-282023-06-13
4620Reflected Swf XSS at ( https://plugins.svn.wordpress.org ) Flash XSS Reflected XSS WordPress Mohamed Haron (@m7mdharon) Bug Bounty2018-09-072023-06-13
4618A Infinite Loop Story. DoS NA Ashish Kunwar (@D0rkerDevil) Bug Bounty2018-08-292023-06-13
4617Finding hidden gems vol. 2: REAMDE.md, the story of a bit too helpful readme file Information disclosure NA Mateusz Olejarka (@molejarka) Bug Bounty2018-08-292023-06-13
4616Reflected XSS in Django REST Framework Api at MapBox Subdomain Reflected XSS Mapbox Mohamed Haron (@m7mdharon) Bug Bounty2018-08-292023-06-13
4615$100 Bounty in 300 seconds isn’t bad !!! Stored XSS Zoho Rohan Chavan (@rohanchavan1918) Bug Bounty2018-08-312023-06-13
4614Pwned Together: Hacking dev.to Stored XSS Dev.to Antony Garand (@AntoGarand) Bug Bounty2018-08-312023-06-13
4613https://medium.com/@mahitman1/i-own-your-customers-22e965761abd Information disclosure Hardcoded credentials AWS misconfiguration NA Muhammad Abdullah Bug Bounty2018-09-012023-06-13
4612Send request to Martians. Earthlings are already your friends. CSRF Google Sagar VD Bug Bounty2018-09-012023-06-13