Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
5013How i found massive information disclosure of 1500 famous people Information disclosure NA Valeriy Shevchenko (@Krevetk0Valeriy) Bug Bounty2017-07-312023-06-13
5011XSS Because of wrong Content-type Header XSS Internshala Noman Shaikh (@nomanali181) Bug Bounty2017-08-042023-06-13
5008Getting access to 25k employees details Exposed registration page NA Sahil Ahamad (@ehsahil) Bug Bounty2017-08-112023-06-13
5004Accidentally typo to bypass administration access Authentication bypass NA yappare (@yappare) Bug Bounty2017-08-132023-06-13
5003Password Not Provided - Compromising Any Flurry User%27s Account [Yahoo Bug Bounty] Authentication flaw Account takeover Yahoo! / Verizon Media Jack Cable (@jackhcable) Bug Bounty2017-08-152023-06-13
5000Pre-domain wildcard CORS Exploitation CORS misconfiguration NA Arbaz Hussain (@ArbazKiraak) Bug Bounty2017-08-262023-06-13
4999Upgrade from LFI to RCE via PHP Sessions LFI RCE NA Julien Ahrens (@MrTuxracer) Bug Bounty2017-08-282023-06-13
4998Bypassing Rate Limit Protection by spoofing originating IP Bruteforce NA Arbaz Hussain (@ArbazKiraak) Bug Bounty2017-08-302023-06-13
4997Improper Storage of Private Project’s Files IDOR NA Arbaz Hussain (@ArbazKiraak) Bug Bounty2017-08-302023-06-13
4992Stealing 0Auth Token (MITM) OAuth NA Arbaz Hussain (@ArbazKiraak) Bug Bounty2017-09-012023-06-13
4991My write up about UBER Cross-site scripting by help of KNOXSS Reflected XSS Uber Emad Shanab (@Alra3ees) Bug Bounty2017-09-022023-06-13
4986Phishing with history.back() open redirect Open redirect NA Brian Hyde (@0xHyde) Bug Bounty2017-09-092023-06-13
4982Stored XSS] with arbitrary cookie installation XSS NA Arbaz Hussain (@ArbazKiraak) Bug Bounty2017-09-172023-06-13
4981Chaining Self XSS with UI Redressing is Leading to Session Hijacking (PWN users like a boss) Self-XSS Clickjacking NA Armaan Pathan (@armaancrockroax) Bug Bounty2017-09-182023-06-13
4980Story of a Parameter Specific XSS! XSS NA Rahul Maini (@iamnoooob) Bug Bounty2017-09-192023-06-13
4979Exploiting a Single Request for Multiple Vulnerabilities Stored XSS Reflected XSS SSRF OS command injection NA Osama Ansari (@AnsariOsama10) Bug Bounty2017-09-192023-06-13
4978First bounty, time to step up my game Same Origin Method Execution NA Roderick Schaefer (@kciredor_) Bug Bounty2017-09-192023-06-13
4977Multiple vulnerabilities in Oracle EBS SQL injection XXE XSS NA Shubham Gupta (@hackerspider1) Bug Bounty2017-09-192023-06-13
4968Device Authorization Bypass! Authorization flaw NA Hassan Khan Yusufzai Bug Bounty2017-09-252023-06-13
4959How I was Able to see someone’s all private files with a single file share link through Atom feed & Never Give Up #togetherwehitharder HackerOne Information disclosure NA Yogendra Jaiswal (@vulnh0lic) Bug Bounty2017-10-132023-06-13
4957Reading Internal Files using SSRF vulnerability SSRF NA Neeraj Sonaniya (@neeraj_sonaniya) Bug Bounty2017-10-162023-06-13
4956How I hacked all the [REDACT] Agents accounts Default credentials NA Neeraj Sonaniya (@neeraj_sonaniya) Bug Bounty2017-10-172023-06-13
4955Sensitive data exposure by requesting a resource with a different content type Information disclosure NA Yogendra Jaiswal (@vulnh0lic) Bug Bounty2017-10-172023-06-13
4949App Maker and Colaboratory: a stored Google XSS double-bill Stored XSS Google Yasin Soliman (@SecurityYasin) Bug Bounty2017-11-012023-06-13
4948Senstive Information Leak Lead To join any Organisation Information disclosure NA Shivbihari Pandey (@ninja_pandit_) Bug Bounty2017-11-042023-06-13