Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
4560Hacking the Subway Android app Logic flaw Authorization flaw Subway Wesley Gahr (@wesley_gahr) Bug Bounty2018-09-282023-06-13
4559How I was able to takeover account%27s of an Earning App Information disclosure NA Abbas Wafa Bug Bounty2018-10-012023-06-13
4558Subdomain Takeover via Shopify Vendor ( blog.exchangemarketplace.com ) with Steps Subdomain takeover Shopify Mohamed Haron (@m7mdharon) Bug Bounty2018-10-012023-06-13
4557Collecting Shells by the Sea of NAS Vulnerabilities OS command injection XSS CSRF Lenovo Rick Ramgattie (@RRamgattie) Bug Bounty2018-10-012023-06-13
4556How i found Stored xss on your-domain.redacted.com XSS NA Rudra Sarkar (@rudr4_sarkar) Bug Bounty2018-10-022023-06-13
4555Applying a small bypass to steal Facebook Session tokens in Uber XSS CSP bypass OAuth Uber Samuel (@saamux) Bug Bounty2018-10-022023-06-13
4554AWS takeover through SSRF in JavaScript SSRF NA Gwendal Le Coguic (@gwendallecoguic) Bug Bounty2018-10-022023-06-13
4553Facebook Bug Bounty: Email Id, Phone Number Can be exposed Through Business Manager Logic flaw Information disclosure Meta / Facebook Rohit kumar (@rohitcoder) Bug Bounty2018-10-032023-06-13
4552Exploiting an unknown vulnerability Logic flaw Payment tampering NA Abhishek Bundela (@abhibundela) Bug Bounty2018-10-032023-06-13
4551Persistent XSS (Unvalidated oEmbed) at Medium.com Stored XSS Medium Jonathan Bouman (@JonathanBouman) Bug Bounty2018-10-042023-06-13
4550An interesting Google vulnerability that got me 3133.7 reward. CSRF Google Ebrahem Hegazy (@Zigoo0) Bug Bounty2018-10-042023-06-13
4549GoogleMeetRoulette: Joining random meetings Bruteforce Logic flaw Google Martin Vigo (@martin_vigo) Bug Bounty2018-10-042023-06-13
4548Apache Struts double evaluation RCE lottery RCE Double OGNL evaluation Apache Struts Man Yue Mo (@mmolgtm) Bug Bounty2018-10-042023-06-13
4547Clickjacking in Google Docs and Voice typing feature. Clickjacking Google Raushan Raj (@raushan_rajj) Bug Bounty2018-10-052023-06-13
4546Blind XML External Entities Out-Of-Band Channel Vulnerability : PayPal Case Study Blind XXE Paypal Abdelmoughite Eljoaydi Bug Bounty2018-10-052023-06-13
4545Bypassing Web Cache Poisoning Countermeasures Web cache poisoning Cloudflare James Kettle (@albinowax) Bug Bounty2018-10-052023-06-13
4544My First 0day Exploit (CSP Bypass + Reflected XSS) #BUGBOUNTY Reflected XSS CSP bypass NA Ali Tütüncü(@alicanact60) Bug Bounty2018-10-072023-06-13
4543Persistent XSS (unvalidated Open Graph embed) at LinkedIn.com Stored XSS LinkedIn Jonathan Bouman (@JonathanBouman) Bug Bounty2018-10-072023-06-13
4542[Critical] Bypass CSRF protection on IBM CSRF IBM Mohamed Sayed (@FlEx0Geek) Bug Bounty2018-10-092023-06-13
4541Make any Unit in Facebook Groups Undeletable Logic flaw IDOR Authorization flaw Meta / Facebook Sarmad Hassan (@JubaBaghdad) Bug Bounty2018-10-092023-06-13
4540DOM-XSS Bug Affecting Tinder, Shopify, Yelp, and More DOM XSS Tinder VPN Mentor (@vpnmentor) Bug Bounty2018-10-092023-06-13
4539Get as image function pulls any Insights/NRQL data from any New Relic account (IDOR) IDOR New Relic Jon Bottarini (@jon_bottarini) Bug Bounty2018-10-092023-06-13
4537Payment bypass Payment bypass Logic flaw NA Pratik Yadav (@PratikY9967) Bug Bounty2018-10-092023-06-13
4536Symantec Messaging Gateway authentication bypass Authentication bypass Symantec Artem Kondratenko (@artkond) Bug Bounty2018-10-102023-06-13
4535Access to staging environment via User-Agent string Authentication bypass NA Yasser Gersy (@yassergersy) Bug Bounty2018-10-102023-06-13