Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
4226How I was able to get your facebook private friend list [Responsible Disclosure] Information disclosure Meta / Facebook Raja Sekar Durairaj Bug Bounty2019-04-012023-06-13
4225FileZilla Untrusted Search Path RCE FileZilla (EU-FOSSA 2) Chris Lyne (@lynerc) Bug Bounty2019-04-022023-06-13
4224Facebook Vulnerability: Hiding from Facebook Page Admin(s) in /hacked workflow Logic flaw Meta / Facebook Ritish Kumar Singh Bug Bounty2019-04-022023-06-13
4223How I am able to hijack you. Logic flaw Google Terjanq (@terjanq) Bug Bounty2019-04-032023-06-13
4222DownNotifier SSRF SSRF DownNotifier _m_q_t (@_m_q_t) Bug Bounty2019-04-042023-06-13
4221Leaked Salesforce API access token at IKEA.com Information disclosure Salesforce Ikea Jonathan Bouman (@JonathanBouman) Bug Bounty2019-04-042023-06-13
4220Handlebars template injection and RCE in a Shopify app SSTI RCE Shopify Mahmoud Gamal (@Zombiehelp54) Bug Bounty2019-04-042023-06-13
4219Google Ads — Information Disclosure via null pointer exception Information disclosure Google Valerio brussani (@val_brux) Bug Bounty2019-04-042023-06-13
4218Same-Origin Policy: From birth until today SOP bypass Browser hacking CSRF CORS Mozilla Google (Chrome) Opera Alex Nikolova (@AaylaSecura1138) Bug Bounty2019-04-042023-06-13
4217Scary Bug in Burp Suite Upstream Proxy Allows Hackers to Hack Hackers MiTM PortSwigger Armaan Pathan (@armaancrockroax) Bug Bounty2019-04-062023-06-13
4216Edmodo — IDOR to view private files of any class IDOR Edmodo Rohan Pagey (@rohan_x3) Bug Bounty2019-04-062023-06-13
4215Email content spoofing at IKEA.com Email content spoofing Ikea Jonathan Bouman (@JonathanBouman) Bug Bounty2019-04-062023-06-13
4214Old but GOLD Dot Dot Slash to Get the Flag — Uber Microservice SSRF Path traversal Account takeover Uber Ron Chan (@ngalongc) Bug Bounty2019-04-072023-06-13
4213How I got a trip to amsterdam through bug bounty Bruteforce NA Ninad Mathpati (@ninad_mathpati) Bug Bounty2019-04-072023-06-13
4212Obtaining XSS Using Moodle Features and Minor Bugs Login CSRF XSS Moodle Daniel Thatcher (@_danielthatcher) Bug Bounty2019-04-092023-06-13
4211SSRF Tips: SSRF/XSPA in Microsoft’s Bing Webmaster Central SSRF XSPA Microsoft Elber Andre (@Elber333) Bug Bounty2019-04-092023-06-13
4210Dell KACE K1000 Remote Code Execution — the Story of Bug K1–18652 RCE Dropbox Julien Ahrens (@MrTuxracer) Bug Bounty2019-04-092023-06-13
4209Spokeo Bug bounty Experience XSS Spokeo Nur A Alam Dipu (@Dipu1A) Bug Bounty2019-04-102023-06-13
4208Multiple xss in *.skype.com XSS Microsoft Jayateertha Guruprasad (@JayateerthaG) Bug Bounty2019-04-102023-06-13
4207Account Takeover by chaining two vulnerabilities. CSRF Open redirect Account takeover NA Sheraz Khalid Bug Bounty2019-04-102023-06-13
4206Unauthenticated Account Takeover Through HTTP Leak HTML injection HTTP Leak Account takeover NA Nikhil (niks) (@niksthehacker) Bug Bounty2019-04-112023-06-13
4205[RCE] Remote code execution at api.PrivateProgram.com (CVE-2017-5638) RCE NA Mohamed Haron (@m7mdharon) Bug Bounty2019-04-122023-06-13
4204Web Cache Deception to API endpoint attack using cached token header Web cache deception NA Kunal pandey (@kunalp94) Bug Bounty2019-04-132023-06-13
4203How I gained access to revenue and traffic data of thousands of Shopify stores IDOR Shopify Ayoub Fathi (@_ayoubfathi_) Bug Bounty2019-04-152023-06-13
4202The Outlook Winner is Dash Authorization flaw Microsoft marcan2020 (@marcan2020) Bug Bounty2019-04-152023-06-13