Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
4457Exploiting SSRF like a Boss — Escalation of an SSRF to Local File Read! SSRF LFI NA Zain Sabahat (@Zain_Sabahat) Bug Bounty2018-11-222023-06-13
4456Bypassing Scratch Cards On Google Pay Logic flaw Google Pratheesh P Narayanan Bug Bounty2018-11-222023-06-13
4455Stored XSS Vulnerability in Jotform and H1C Private Site Stored XSS NA Anas Mahmood (@AnasIsHere) Bug Bounty2018-11-232023-06-13
4454My Journey To The Google Hall Of Fame Open redirect XSS Google Abartan Dhakal (@imhaxormad) Bug Bounty2018-11-252023-06-13
4453From CTFs to Bug Bounty Booty Information disclosure Tailor Store Benji Tobias Bug Bounty2018-11-262023-06-13
4448Instagram Multi-factor authentication Bypass MFA bypass Meta / Facebook Vishnuraj Bug Bounty2018-11-272023-06-13
4447Pwning eBay - How I Dumped eBay Japan%27s Website Source Code .git folder disclosure Source code disclosure Ebay David (@slashcrypto) Bug Bounty2018-11-282023-06-13
4446IRCTC — Millions of Passenger Details left at huge risk! Information disclosure Lack of rate limiting IRCTC Avinash Jain (@logicbomb_1) Bug Bounty2018-11-282023-06-13
4445Broken Authentication — Bug Bounty Session management issue NA Vulnerables Bug Bounty2018-11-282023-06-13
4444Story of Stored Xss XSS NA Walid Hossain (@NoobWalid) Bug Bounty2018-11-282023-06-13
4443Exploiting post message to steal and replace user’s cookies postMessage NA Yasser Gersy (@yassergersy) Bug Bounty2018-11-302023-06-13
4442Story about my first bug bounty XSS Alibaba Sudhanshu Rajbhar (@sudhanshur705) Bug Bounty2018-11-302023-06-13
4441Love Story Of A Account Takeover (Chaining Host Header Injection To Takeover Someones Account) Host header injection NA Logical Bimboo Bug Bounty2018-11-302023-06-13
4440Remotely Hijacking Zoom Clients Logic flaw Zoom David Wells Bug Bounty2018-12-032023-06-13
4439[BBP系列三] Hijack the JS File of Uber%27s Website JS file hijacking Uber Chaobin Zhang Bug Bounty2018-12-032023-06-13
4438Digging in to SCP Command Injection OS command injection JSch Dylan Katz (@Plazmaz) Bug Bounty2018-12-032023-06-13
4437GitHub Desktop RCE (OSX) RCE GitHub André Baptista (@0xacb) Bug Bounty2018-12-042023-06-13
4436How to accidentally find a XSS in ProtonMail iOS app XSS ProtonMail SecuNinja (@secuninja) Bug Bounty2018-12-042023-06-13
4435Taking over Google calendar of a company Subdomain takeover NA Daniel V. (@d4niel_v) Bug Bounty2018-12-042023-06-13
4433XSS to XXE in Prince v10 and below (CVE-2018-19858) XSS XXE NA Corben Leo (@hacker_) Bug Bounty2018-12-052023-06-13
4432Billion Laugh Attack in https://sites.google.com Billion laugh attack DoS Google Antonio Sanso (@asanso) Bug Bounty2018-12-052023-06-13
4431Facebook WhiteHat: Able to access group plan even after leaving the group Authorization flaw Logic flaw Meta / Facebook Family guy Bug Bounty2018-12-062023-06-13
4430RCE in Hubspot with EL injection in HubL RCE HubSpot Fyoorer (@ƒyoorer) Bug Bounty2018-12-072023-06-13
4429How I was Able To Bypass Email Verification Information disclosure NA Muzammil Kayani (@muzammilabbas2) Bug Bounty2018-12-082023-06-13
4428Proof Of Concept Nokia Cross Site Scripting XSS Nokia Adesh Nandkishor kolte (@AdeshKolte) Bug Bounty2018-12-092023-06-13