Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
4147A base64 encoded parameter. HTML injection NA Navneet (@na5n33t) Bug Bounty2019-05-192023-06-13
4146Open-redirect to Account Takeover. Open redirect Account takeover NA Rishabh (@____cypher____) Bug Bounty2019-05-192023-06-13
4145WRITE UP – GOOGLE BUG BOUNTY: LFI ON PRODUCTION SERVERS in “springboard.google.com” – $13,337 USD LFI Google Omar Espino (@omespino) Bug Bounty2019-05-212023-06-13
4144Leaking OpenID tokens with “ — the bug right infront of you OpenID Connect Open redirect Token leak NA Zseano (@zseano) Bug Bounty2019-05-212023-06-13
4143Local File Inclusion in peering.google.com LFI Google Jafar Abo Nada (@Jafar_Abo_Nada) Bug Bounty2019-05-212023-06-13
4142Google Adwords(Privilege Escalation): Read-only user able to add YouTube channels via Linked accounts Privilege escalation Authorization flaw Google Family guy Bug Bounty2019-05-212023-06-13
4140Escalating subdomain takeovers to steal cookies by abusing document.domain Subdomain takeover Postmates Ameya (@iamTakeMyHand) Bug Bounty2019-05-232023-06-13
4139How I acquired $XXX bounty by investing 99 cents Logic flaw NA Smaran Chand (@smaranchand) Bug Bounty2019-05-242023-06-13
4137Security assessment on the staging domains Missing authentication NA Tutorgeeks (@tutorgeeks) Bug Bounty2019-05-242023-06-13
4136From file upload to email:pass Unrestricted file upload NA fr0stNuLL Bug Bounty2019-05-242023-06-13
4135Multiple API issues due to Fixed Authorization token. Authorization flaw NA Mustafa Khan (@by6153) Bug Bounty2019-05-242023-06-13
4133How did I bypass a Custom Brute Force protection and why that solution is not a good idea? Bruteforce Authentication flaw NA dortz Bug Bounty2019-05-252023-06-13
4132An unexploited CORS misconfiguration reflecting further issues. CORS misconfiguration NA Smaran Chand (@smaranchand) Bug Bounty2019-05-272023-06-13
4131Stored XSS on Edmodo Stored XSS Edmodo Rohit Verma (@rv0x00) Bug Bounty2019-05-282023-06-13
4130Exploiting File Uploads Pt. 1 – MIME Sniffing to Stored XSS #bugbounty Stored XSS MIME sniffing NA HackerOn2Wheels (@HackerOn2Wheels) Bug Bounty2019-05-302023-06-13
4129My First CSRF to Account Takeover worth $750 CSRF Account takeover NA Nishant Saurav (@inishantsinha) Bug Bounty2019-05-302023-06-13
4128Edmodo Account Deactivation Vulnerability CORS misconfiguration Edmodo Shankar R Bug Bounty2019-06-012023-06-13
4127Story of a uri based xss with some simple google dorking XSS NA Jatin Aesthetic (@techyfreakk) Bug Bounty2019-06-022023-06-13
4126The Unusual Case of Status code- 301 Redirection to AWS Security Credentials Compromise SSRF RFI NA Avinash Jain (@logicbomb_1) Bug Bounty2019-06-022023-06-13
4125Missing access control at play store Authorization flaw Google Vishwaraj Bhattrai (@vishwaraj101) Bug Bounty2019-06-032023-06-13
4124Simple PathTraversal bypass Path traversal NA fr0stNuLL Bug Bounty2019-06-032023-06-13
4123Chaining multiple low-impact bugs to arbitrary file read in GitLab Path traversal GitLab Li Rongxi (@nyan_gawa) Bug Bounty2019-06-042023-06-13
4122REMOTE CODE EXECUTION ! 😜 Recon Wins RCE NA Vishnuraj Bug Bounty2019-06-042023-06-13
4121Bypassing CSP with policy injection CSP bypass Paypal Gareth Heyes (@garethheyes) Bug Bounty2019-06-052023-06-13
4120Unicode vs WAF — XSS WAF Bypass XSS NA Prial Islam Khan (@prial261) Bug Bounty2019-06-052023-06-13