Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
3104Weak Password Setting function on practo.com Authorization flaw Practo dark-haxor Bug Bounty2020-10-092023-06-13
3103JS is l0ve ❤️. Information disclosure API key leakage NA Shivam Kamboj Dattana (@sechunt3r) Bug Bounty2020-10-092023-06-13
3102Leveraging XSS to Read Internal Files XSS LFI NA Aditya Dixit (@zombie007o) Bug Bounty2020-10-092023-06-13
3101Unauthorized access to all the user’s account. Account takeover Authentication bypass JWT NA Rahul Naidu Bug Bounty2020-10-122023-06-13
3098How I find my first P1 level Bug. $$$ XSS NA Harsh Bug Bounty2020-10-132023-06-13
3097Blind SSRF - The Hide & Seek Game Blind SSRF NA Shrey Shah (@ShreySh43332033) Bug Bounty2020-10-132023-06-13
3096I had fun with this XSS XSS NA yappare (@yappare) Bug Bounty2020-10-132023-06-13
3095MS Enterprise app management service RCE. CVE-2022-35841 RCE Local Privilege Escalation Windows Microsoft Ceri Coburn (@_ethicalchaos_) Bug Bounty2020-10-132023-06-13
3094Weaponizing XSS For Fun & Profit XSS CSRF NA Saad Ahmed (@XSaadAhmedX) Bug Bounty2020-10-142023-06-13
3092GitHub - RCE via git option injection (almost) - $20,000 Bounty RCE GitHub William Bowling / vakzz (@wcbowling) Bug Bounty2020-10-182023-06-13
3091GitHub Gist - Account takeover via open redirect - $10,000 Bounty Open redirect Account takeover GitHub William Bowling / vakzz (@wcbowling) Bug Bounty2020-10-192023-06-13
3090Multiple Address Bar Spoofing Vulnerabilities In Mobile Browsers Authentication bypass JWT Android NHS COVID-19 App James Sanderson (@zofrex) Bug Bounty2020-10-202023-06-13
3088Back to 2019: Disclosure Employers PII and Credentials Information disclosure NA Wh11teW0lf (@wh11tew0lf) Bug Bounty2020-10-202023-06-13
3087GitHub Pages - Multiple RCEs via insecure Kramdown configuration - $25,000 Bounty RCE Path traversal GitHub William Bowling / vakzz (@wcbowling) Bug Bounty2020-10-202023-06-13
3084IBM Datapower Exploit CVE-2020-5014 SSRF HTTP Request Smuggling IBM Thomas Cope Bug Bounty2020-10-212023-06-13
3083300$ P3 Easy Bug in 30 Seconds Missing authentication Broken Access Control NA Omar Hamdy (@seaman00o) Bug Bounty2020-10-222023-06-13
3082Samsung S20 - RCE via Samsung Galaxy Store App RCE Samsung F-Secure Bug Bounty2020-10-232023-06-13
3081Accidental Observation to Critical IDOR IDOR NA Harsh Bothra (@harshbothra_) Bug Bounty2020-10-242023-06-13
3074Automating xss identification with Dalfox & Paramspider Reflected XSS NA Paras Arora (@parasarora06) Bug Bounty2020-10-272023-06-13
3073Error-Based SQL Injection on a WordPress website and extract more than 150k user details SQL injection NA Ynoof Alassiri Bug Bounty2020-10-272023-06-13
3072Story of an interesting bug. Lack of rate limiting DoS NA Vedant Tekale (@_justYnot) Bug Bounty2020-10-282023-06-13
3071Weblogic RCE by only one GET request — CVE-2020–14882 Analysis RCE Authentication bypass Security code review Oracle (WebLogic) Nguyễn Tiến Giang (@testanull) Bug Bounty2020-10-282023-06-13
3070Manual broken link monitoring Broken link hijacking NA GrumpinouT (@RVerwilghen) Bug Bounty2020-10-292023-06-13
3069Rate Limit Bypassing Allowing Identity Spoofing Rate limiting bypass OTP bypass NA Mohamed Talaat (@T4144t) Bug Bounty2020-10-292023-06-13
3065Beyond the wall: command injection still alive. OS command injection NA Ahmed Constant (@a_Constant_) Bug Bounty2020-10-312023-06-13