Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
4534Microsoft Edge Remote Code Execution RCE Microsoft Abdulrahman Alqabandi (@Qab) Bug Bounty2018-10-112023-06-13
4533Add description to Instagram Posts on behalf of other users - 6500$ IDOR Meta / Facebook Sarmad Hassan (@JubaBaghdad) Bug Bounty2018-10-122023-06-13
4532Magic XSS with two parameters XSS NA Mahmood Shahabi (@m4shahab1) Bug Bounty2018-10-122023-06-13
4531[Bug bounty | mail.ru] Access to the admin panel of the partner site and data disclosure of 2 million users Authentication bypass Blind XSS Mail.ru Max (@iSecMax) Bug Bounty2018-10-122023-06-13
4530Microsoft CSRF Vulnerability CSRF Microsoft Adesh Nandkishor kolte (@AdeshKolte) Bug Bounty2018-10-122023-06-13
4529Brave Browser Script Blocker Bypass Vulnerability Browser hacking Brave Software Xiaoyin Liu Bug Bounty2018-10-132023-06-13
4528Path traversal while uploading results in RCE Path traversal RCE NA Harsh Jaiswal (@rootxharsh) Bug Bounty2018-10-152023-06-13
4527XXE in IBM’s MaaS360 Platform XXE IBM Cody Wass Bug Bounty2018-10-162023-06-13
4526Security teams Internal attachments can be exported via "Export as .zip" feature on HackerOne Logic flaw HackerOne Japz Divino (@japzdivino) Bug Bounty2018-10-172023-06-13
4525Add comment on a private Oculus Developer bug report IDOR Authorization flaw Meta / Facebook Sarmad Hassan (@JubaBaghdad) Bug Bounty2018-10-182023-06-13
4524XSS with PUT in Ghost Blog XSS Ghost Derek (@StackCrash) Bug Bounty2018-10-192023-06-13
4523A Story of mishandling the Chunked Data (CVE-2018-17082) XSS PHP Prashanth Varma (@cymtrick) Bug Bounty2018-10-202023-06-13
4522A possibility of Account Takeover in Medium Account takeover Logic flaw Medium Prashant Kumar (@notsoshant) Bug Bounty2018-10-202023-06-13
4521Harvesting all private invites using leave program fast-tracked invitation and security@ email forwarding feature Logic flaw HackerOne Japz Divino (@japzdivino) Bug Bounty2018-10-222023-06-13
4520Cookie-based-injection XSS making exploitable with-out exploiting other Vulns XSS NA Utkarsh Agrawal (@agrawalsmart7) Bug Bounty2018-10-222023-06-13
4519Google sites and exploiting same origin policy SOP bypass Google Raushan Raj (@raushan_rajj) Bug Bounty2018-10-222023-06-13
4518XSS with HTML and how to convert the HTML into charcode() XSS Purinar Logistics Arif-ITSEC111 Bug Bounty2018-10-222023-06-13
4517Facebook hidden redirection vulnerability Open redirect Meta / Facebook Ege Ken Bug Bounty2018-10-242023-06-13
4516SOAP- Based Unauthenticated Out-of-Band XML External Entity (OOB-XXE) in a Help Desk Software XXE NA Nikhil (niks) (@niksthehacker) Bug Bounty2018-10-242023-06-13
4515DoS on Facebook Android app using 65530 characters of ZERO WIDTH NO-BREAK SPACE. DoS Meta / Facebook Rahul Kankrale (@RahulKankrale) Bug Bounty2018-10-252023-06-13
4514Subdomain takeover dew to missconfigured project settings for Custom domain . Subdomain takeover Flock Prial Islam Khan (@prial261) Bug Bounty2018-10-252023-06-13
4513CSRF account takeover Explained Automated/Manual — Bug Bounty CSRF Account takeover OpenMenu Vulnerables Bug Bounty2018-10-262023-06-13
4512A very useful technique to bypass the CSRF protection for fun and profit. CSRF NA Yeasir Arafat Bug Bounty2018-10-262023-06-13
4511How Misconfigured API leaked user private information? IDOR Authorization flaw NA Yeasir Arafat Bug Bounty2018-10-262023-06-13
4510Privilege Escalation like a Boss IDOR NA Jay Jani (@JayJani007) Bug Bounty2018-10-272023-06-13