Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
2767Password Reset Token Leak via X-Forwarded-Host Host header injection Account takeover Password reset NA Saajan Bhujel (@saajanbhujel) Bug Bounty2021-02-262023-06-13
2764IDOR which allowed me to view Personal Email Addresses of More than 50K Users! IDOR Password reset NA Savir Suda (@savxiety) Bug Bounty2021-02-262023-06-13
2745How I Might Have Hacked Any Microsoft Account Account takeover Password reset Bruteforce MFA bypass Microsoft Laxman Muthiyah (@laxmanmuthiyah) Bug Bounty2021-03-022023-06-13
2722Account Takeover Via Reset Password Worth 2000$ Password reset Account takeover NA Ashutosh mishra (@ashutoshmish_ra) Bug Bounty2021-03-122023-06-13
2714An Interesting Account Takeover!! IDOR Account takeover Weak encryption Password reset NA Mayank Pandey (@mayank_pandey01) Bug Bounty2021-03-172023-06-13
2689Increasing impact of Information Disclosure — Full Account Takeover ! Information disclosure Password reset NA Abhisek R (@abh1sek_r) Bug Bounty2021-03-262023-06-13
2650Unauthenticated Account Takeover Through Forget Password Password reset Account takeover Information disclosure NA Nikhil (niks) (@niksthehacker) Bug Bounty2021-04-122023-06-13
2632Misconfiguration in Change-password Functionality Leads to Account Takeover IDOR Logic flaw Password reset Account takeover NA Mahmoud Radwan (@0x___2m) Bug Bounty2021-04-182023-06-13
2610From Wayback Machine To Account Takeover Account takeover Password reset Open redirect NA Demon (@R29k_) Bug Bounty2021-04-252023-06-13
2591Password reset code brute-force vulnerability in AWS Cognito Password reset Bruteforce Rate limiting bypass Account takeover AWS Pentagrid (@pentagridsec) Bug Bounty2021-04-302023-06-13
2550My Fourth Account takeover through password reset Account takeover Password reset NA Omar Hamdy (@seaman00o) Bug Bounty2021-05-172023-06-13
2547Drupal Insecure Default Leads To Password Reset Poisoning Password reset Host header injection Drupal Bogdan Tiron (@Bogdan___T) Bug Bounty2021-05-292023-06-13
2495Joomla Password Reset Vulnerability And A Stored XSS For Full Compromise Password reset Stored XSS Privilege escalation RCE Security code review NA Adrian Tiron (@Adrian__T) Bug Bounty2021-06-072023-06-13
2463Zero Click account Takeover Account takeover Password reset NA Zahir Tariq (@ZahirTariq3) Bug Bounty2021-06-192023-06-13
2438How I was able to Takeover Accounts on Foxit.com Password reset Account takeover NA Jefferson Gonzales (@gonzxph) Bug Bounty2021-06-292023-06-13
2424Facebook Email/phone disclosure using Binary search Password reset Information disclosure Bruteforce Meta / Facebook Rikesh Baniya / NotRickyy (@rikeshbaniya) Bug Bounty2021-07-092023-06-13
2423Account Takeovers — Believe the Unbelievable Account takeover Session management issue Weak credentials Components with known vulnerabilities Password reset NA Nikhil (niks) (@niksthehacker) Bug Bounty2021-07-092023-06-13
2420Critical Bug Bounty Reports: Part 1 Account takeover Password reset RCE Information disclosure NA Greg Gibson Bug Bounty2021-07-112023-06-13
2418Trick to bypass rate limit of password reset functionality Rate limiting bypass NA Abdulrahman-Kamel Bug Bounty2021-07-122023-06-13
2384Bug Chain leads to Mass Account Takeover! Information disclosure Password reset Account takeover NA Shubhayu Majumdar (@shubhayu64) Bug Bounty2021-07-262023-06-13
2380You’ve Got (a Reset) Mail: A Security Analysis of Email-Based Password Reset Procedures Password reset Host header injection CSRF Account takeover NA Tommaso Innocenti (@innotommy) Bug Bounty2021-07-262023-06-13
2360The journey from Google Honorable Mention to Hall of Fame. Referer leakage Information disclosure Password reset Google Akash basnet (@noneofyou007) Bug Bounty2021-08-012023-06-13
2346Account Takeover (User + Admin) Via Password Reset Account takeover Password reset Logic flaw NA Hemant Patidar (@HemantSolo) Bug Bounty2021-08-052023-06-13
2300[$5K] Misconfigured Reset password that leads to Account Takeover (No user Interaction ATO) Account takeover Password reset Information disclosure NA Aditya Sharma (@Assass1nmarcos) Bug Bounty2021-08-242023-06-13
2196Bug-Bounty | FASTMAIL [pobox.com : account takeover] Account takeover Password reset Fastmail Mohammed ELdawody Bug Bounty2021-09-242023-06-13