Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
4401Facebook BugBounty - Disclosing page members Information disclosure Meta / Facebook Nirmal Thapa / mpz (@tnirmalz) Bug Bounty2018-12-202023-06-13
4400Facebook BugBounty — Disclosing page members Information disclosure Meta / Facebook Nirmal Thapa (@tnirmalz) Bug Bounty2018-12-202023-06-13
4399XSS worm – A creative use of web application vulnerability XSS Swisscom Nicolas Heiniger (@NicolasHeiniger) Bug Bounty2018-12-212023-06-13
4398How I accidentally found a clickjacking “feature” in Facebook Clickjacking Meta / Facebook Lasq (@lasq88) Bug Bounty2018-12-212023-06-13
4397Client side validation strikes again: PIN code bypass ! Client-side enforcement of server-side security Authentication bypass Authorization flaw Netflix Linxo Davy (@RandoriSec) Bug Bounty2018-12-222023-06-13
4396Server-side Request Forgery in OpenID support SSRF Liberapay Putra Adhari Bug Bounty2018-12-242023-06-13
4395Tokopedia Account Takeover Bug Worth 8 Million IDR Password reset Account takeover Tokopedia Mukul Lohar (@ironfisto) Bug Bounty2018-12-242023-06-13
4394Unauthenticated user can upload an attachment at HackerOne Authorization flaw HackerOne Ahamed Morad (@Modam3r5) Bug Bounty2018-12-242023-06-13
4393RCE in nokia.com RCE Nokia Sampanna Chimoriya Bug Bounty2018-12-272023-06-13
4392From Hunting for a Laptop to Hunting down Remote Code Execution RCE WebDAV Asus Anil Tom (mr_4nk) Bug Bounty2018-12-272023-06-13
4391Reflected XSS on ws-na.amazon-adsystem.com(Amazon) Reflected XSS Amazon ssid (@newp_th) Bug Bounty2018-12-272023-06-13
4390How I Was Able To Takeover All User Account And Admin Panel IDOR Account takeover NA Dipak kumar Das (@d1pakdas) Bug Bounty2018-12-282023-06-13
4389How I Takeover Wordpress Admin fiiipay.my Account takeover CMS default files FiiiPay Syahrul Akbar Rohmani (@sahruldotid) Bug Bounty2018-12-282023-06-13
4388Abusing ACL Permissions to Overwrite other User’s Uploaded Files/Videos on s3 Bucket Unrestricted file upload Authorization flaw NA Armaan Pathan (@armaancrockroax) Bug Bounty2018-12-302023-06-13
4387How I was able to delete Google Gallery Data [IDOR] IDOR Google Yogesh Tantak Bug Bounty2018-12-302023-06-13
4386Bypassing Access Control in a Program on Hackerone !! Authorization flaw HackerOne Sahil Tikoo (@viperbluff) Bug Bounty2018-12-302023-06-13
4385Tale of a Misconfiguration in Password Reset Password reset NA Shuaib Oladigbolu (@_sawzeeyy) Bug Bounty2018-12-302023-06-13
4384A Curious Case From Little To Complete Email Verification Bypass Email verification bypass Authorization flaw NA Megaman (@N0_M3ga_Hacks) Bug Bounty2019-01-012023-06-13
4383How i found web shell on AntiHack.me and Awarded Gold Coin And SWAG RCE Rudra Sarkar (@rudr4_sarkar) AntiHack.me Bug Bounty2019-01-012023-06-13
4382How I was able to Harvest other Vine users IP address IDOR Vine Prial Islam Khan (@prial261) Bug Bounty2019-01-022023-06-13
4381A Tricky Open Redirect Open redirect NA Anas Mahmood (@AnasIsHere) Bug Bounty2019-01-032023-06-13
4380Yes I can see your OTP IDOR NA Vulnerables Bug Bounty2019-01-032023-06-13
4379Stealing Side-Channel Attack Tokens in Facebook Account Switcher Token leak Meta / Facebook Max Pasqua Bug Bounty2019-01-042023-06-13
4378How I stumbled upon a Stored XSS(My first bug bounty story). Stored XSS Edmodo Parth Shah Bug Bounty2019-01-042023-06-13
4377How I could have taken over any Pinterest account CSRF Account takeover Pinterest Arnold Anthony (@armold9anthony) Bug Bounty2019-01-052023-06-13