Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
5080AWS S3 bucket misconfiguration - Paytm AWS misconfiguration Paytm Tutorgeeks (@tutorgeeks) Bug Bounty2017-04-182023-06-13
5073Pivoting from blind SSRF to RCE with HashiCorp Consul Blind XSS RCE NA Peter Adkins (@darkarnium) Bug Bounty2017-05-292023-06-13
5072XSS on Google{5.000$}-Google Vulnerability Reward Program (VRP) Stored XSS Google - Bug Bounty2017-05-302023-06-13
5071Android Browser All Versions - Address Bar Spoofing Vulnerability - CVE-2015-3830 Address Bar Spoofing Google Rafay Baloch (@rafaybaloch) Bug Bounty2017-06-012023-06-13
5067Android Browser Same Origin Policy Bypass < 4.4 - CVE-2014-6041 SOP bypass Google Rafay Baloch (@rafaybaloch) Bug Bounty2017-06-012023-06-13
5064Django Privilege Escalation – Zero To Superuser Privilege escalation NA Sean Melia (@seanmeals) Bug Bounty2017-06-012023-06-13
5062From JS to another JS files lead to authentication bypass Authentication bypass NA yappare (@yappare) Bug Bounty2017-06-062023-06-13
5058Vulnerability in Metasploit Project aka CVE-2017-5244 CSRF Rapid7 Mohamed A. Baset Bug Bounty2017-06-122023-06-13
5053Yahoo Small Business (Luminate) and the Not-So-Secret Keys Blind SSRF Yahoo! / Verizon Media Tommy DeVoss / dawgyg (@thedawgyg) Bug Bounty2017-06-232023-06-13
5051Authentication bypass on Uber’s Single Sign-On via subdomain takeover Subdomain takeover Authentication bypass Uber Arne Swinnen (@ArneSwinnen) Bug Bounty2017-06-252023-06-13
5049CVE-2017-10711: Reflected XSS vulnerability in SimpleRisk – Open Source Risk Management System Reflected XSS SimpleRisk Mohamed A. Baset Bug Bounty2017-06-282023-06-13
5048Escalating XSS in PhantomJS Image Rendering to SSRF/Local-File Read XSS SSRF LFI NA Brett Buerhaus (@bbuerhaus) Bug Bounty2017-06-292023-06-13
5046OpenProject Session Management Security Vulnerability aka CVE-2017-11667 Session management issue OpenProject Mohamed A. Baset Bug Bounty2017-06-302023-06-13
5039How a simple IDOR become a $4K User Impersonation vulnerability IDOR NA Shahmeer Amir (@Shahmeer_Amir) Bug Bounty2017-07-082023-06-13
5035Hey UserID x, what’s your secret token? Broken API enables me to leak/modify any users personal information IDOR Account takeover NA Zseano (@zseano) Bug Bounty2017-07-132023-06-13
5033ctrl+c & ctrl+v to Steal SESSIONID Clickjacking NA Arbaz Hussain (@ArbazKiraak) Bug Bounty2017-07-182023-06-13
5031Stealing Access Token of One-drive Integration By Chaining CSRF Vulnerability OAuth CSRF NA Arbaz Hussain (@ArbazKiraak) Bug Bounty2017-07-182023-06-13
5030Exploiting Misconfigured CORS on popular BTC Site CORS misconfiguration NA Arbaz Hussain (@ArbazKiraak) Bug Bounty2017-07-192023-06-13
5029Xss using dynamically generated js file XSS NA Arbaz Hussain (@ArbazKiraak) Bug Bounty2017-07-192023-06-13
5028That Escalated Quickly : From partial CSRF to reflected XSS to complete CSRF to Stored XSS CSRF Reflected XSS Stored XSS NA Mandeep Jadon (@1337tr0lls) Bug Bounty2017-07-192023-06-13
5026Self XSS to Good XSS Clickjacking XSS Clickjacking NA Arbaz Hussain (@ArbazKiraak) Bug Bounty2017-07-202023-06-13
5025Race Condition bypassing team limit Race condition NA Arbaz Hussain (@ArbazKiraak) Bug Bounty2017-07-202023-06-13
5022May the Shells be with You - A Star Wars RCE Adventure! RCE NA Andy Gill (@ZephrFish) Bug Bounty2017-07-222023-06-13
5016Cracking the lens: targeting HTTP%27s hidden attack-surface Reflected XSS SSRF Yahoo! / Verizon Media BT New Relic James Kettle (@albinowax) Bug Bounty2017-07-272023-06-13
5014Referer Based XSS XSS NA Arbaz Hussain (@ArbazKiraak) Bug Bounty2017-07-302023-06-13