Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
1229Remote Code Execution on Element Desktop Application using Node Integration in Sub Frames Bypass - CVE-2022-23597 RCE XSS Matrix (Element) s1r1us (@s1r1u5_) Bug Bounty2022-08-132023-06-13
1228XSS via Angular Template Injection CSTI XSS WAF bypass NA Bartłomiej Bergier (@_bergee_) Bug Bounty2022-08-132023-06-13
1225URL filter bypass, RFI and XSS Stored XSS RFI NA Bartłomiej Bergier (@_bergee_) Bug Bounty2022-08-142023-06-13
1224The forgotten API and XSS filter bypass XSS NA Bartłomiej Bergier (@_bergee_) Bug Bounty2022-08-142023-06-13
1223Five-minute hunting for hidden XSS Reflected XSS NA Bartłomiej Bergier (@_bergee_) Bug Bounty2022-08-152023-06-13
1210RCE on Spip and Root-Me, v2! RCE SSTI DNS rebinding XSS Code injection Unrestricted file upload SPIP Laluka (@TheLaluka) Bug Bounty2022-08-162023-06-13
1208N/a to $750 bounty for a Blind XSS. Blind XSS NA Dirtycoder (@dirtycoder0124) Bug Bounty2022-08-182023-06-13
1207You Have One New Appwntment: Exploiting iCalendar Properties in Enterprise Applications XSS SMTP injection VMware Synology Apple Microsoft Google NextCloud Eugene Lim (@spaceraccoonsec) Bug Bounty2022-08-182023-06-13
1201Amazon Quickly Fixed A Vulnerability In Ring Android App That Could Expose Users’ Camera Recordings XSS iOS Android Amazon David Sopas (@dsopas) Bug Bounty2022-08-182023-06-13
1170My Hall of Fame at United Nations Success Story XSS United Nations Joshua Arulsamy (@Joshua_Arulsamy) Bug Bounty2022-08-272023-06-13
1164How I found reflected XSS on IDFC Bank with burp-suite Intruder Reflected XSS IDFC Bank Santosh Kumar Sha (@killmongar1996) Bug Bounty2022-08-282023-06-13
1162How I bypassed Reflected XSS in well-known platform XSS NA Iori Yagami Bug Bounty2022-08-292023-06-13
1161Bypassing Amazon WAF to pop an alert() WAF bypass XSS NA Manash (@manash036) Bug Bounty2022-08-292023-06-13
1151HTMLI/XSS - Crafting a better PoC XSS HTML injection NA RiotSecurityTeam (@RiotSecTeam) Bug Bounty2022-08-302023-06-13
1148How reading robots.txt file got me 4 XSS reports ? XSS NA Ahmed Qaramany (@c0nqr0r) Bug Bounty2022-08-312023-06-13
1137Caching the Un-cacheables - Abusing URL Parser Confusions (Web Cache Poisoning Technique) Web cache poisoning XSS DoS Glassdoor Harel (@h4r3l) Bug Bounty2022-09-022023-06-13
1124Turning cookie based XSS into account takeover XSS Account takeover Terrahost Bartłomiej Bergier (@_bergee_) Bug Bounty2022-09-062023-06-13
1115How I found Moodle Cross site scripting XSS Moodle ParagBagul Bug Bounty2022-09-072023-06-13
1113How I found 3 RXSS on the Lululemon bug bounty program XSS lululemon Omar Hashem (@OmarHashem666) Bug Bounty2022-09-072023-06-13
1111$900 Blind XSS Blind XSS NA ѕнín (@shinchina_) Bug Bounty2022-09-072023-06-13
1092Bug Bounty - Cross-site request forgery is a thing CSRF XSS NA Patrick Hener (@C1sc01) Bug Bounty2022-09-122023-06-13
1087Blind XSS and Time-Based SQL Injection to Admin Panel Control and Database Takeover Blind XSS SQL injection NA Cyberali Bug Bounty2022-09-132023-06-13
1056Parameters in Lambda Functions that lead to XSS and Injection XSS Serverless AWS Teri Radichel (@TeriRadichel) Bug Bounty2022-09-202023-06-13
1052Exploiting Web3’s Hidden Attack Surface: Universal XSS on Netlify’s Next.js Library Universal XSS SSRF Open redirect Web cache poisoning Netlify Gemini PancakeSwap Docusign Moonpay Celo Sam Curry (@samwcyo) Bug Bounty2022-09-212023-06-13
1045My First XSS Open redirect XSS NA Avyukt Syrine (@AvyuktSyrine) Bug Bounty2022-09-232023-06-13