Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
4093Business user Employees could have applied block list to all ad accounts listed in the business manager. Authorization flaw Logic flaw Meta / Facebook Rohit kumar (@rohitcoder) Bug Bounty2019-06-172023-06-13
4092XSS Filter Evasion XSS NA m0z (@LooseSecurity) Bug Bounty2019-06-172023-06-13
4091Account Takeover with Clickjacking Clickjacking NA Osama Avvan (@osamaavvan) Bug Bounty2019-06-192023-06-13
4090Facebook Vulnerability: Unremovable Co-Host in facebook group events Logic flaw Meta / Facebook Ritish Kumar Singh Bug Bounty2019-06-192023-06-13
4089How a classical XSS can lead to persistent ATO Vulnerability? XSS Account takeover NA Milind Purswani (@MilindPurswani) Bug Bounty2019-06-192023-06-13
4088A Fight For Duplicate Marked Bug: Story of BBC Hall Of Fame XSS BBC Wasim Shaikh (@Wa_sim_sim) Bug Bounty2019-06-202023-06-13
4087Self XSS To Evil XSS XSS NA Saad Ahmed (@XSaadAhmedX) Bug Bounty2019-06-202023-06-13
4086IDOR: Payment Fraud IDOR Payment tampering NA Vibhurushi Chotaliya (@_Vibhurushi_) Bug Bounty2019-06-202023-06-13
4085About a Sucuri RCE...and How Not to Handle Bug Bounty Reports RCE Sucuri Julien Ahrens (@MrTuxracer) Bug Bounty2019-06-202023-06-13
4084$1800 worth Clickjacking Clickjacking NA Osama Avvan (@osamaavvan) Bug Bounty2019-06-212023-06-13
4083Catching support emails from my internet service provider Logic flaw T-Mobile Sander Lentink Bug Bounty2019-06-212023-06-13
4082How I Hacked the Microsoft Outlook Android App and Found CVE-2019-1105 XSS Microsoft Bryan Appleby (@bryapp)< Bug Bounty2019-06-212023-06-13
4081Page Admin Disclosure | Facebook Bug Bounty 2019 Authorization flaw Meta / Facebook Ajay Gautam (@evilboyajay) Bug Bounty2019-06-222023-06-13
4080Password Reset Vulnerability — Full Account takeover (Insecure Direct Object Reference) Password reset IDOR Account takeover NA Muhammad Asim Shahzad (@protector47) Bug Bounty2019-06-222023-06-13
4079CSV injection at Comment Section. CSV injection NA Navneet (@na5n33t) Bug Bounty2019-06-242023-06-13
4077F5 Networks Endpoint Inspector – Browser-to-RCE? RCE F5 Dave U. Ramdon Bug Bounty2019-06-262023-06-13
4076Sensitive Information Disclosure: Web Cache Deception Attack Information disclosure Intuit Wasim Shaikh (@Wa_sim_sim) Bug Bounty2019-06-262023-06-13
4074CORS To CSRF Attack CORS misconfiguration CSRF NA Osama Avvan (@osamaavvan) Bug Bounty2019-06-272023-06-13
40731-Click Account Takeover in Virgool.io — a Nice Case Study Account takeover Open redirect NA Yashar Shahinzadeh (@YShahinzadeh) Bug Bounty2019-06-272023-06-13
4071Gain adfly SMTP access with SSRF via Gopher Protocol SSRF Adf.ly Zerb0a Bug Bounty2019-06-272023-06-13
4070Nuget/Squirrel uncontrolled endpoints leads to arbitrary code execution RCE Microsoft Reegun J (@reegun21) Bug Bounty2019-06-282023-06-13
4069Facebook BugBounty : Short story on Page admin disclosure Authorization flaw Privilege escalation Meta / Facebook Bijan Murmu (@0xBijan) Bug Bounty2019-06-282023-06-13
4068One more Parameter manipulation bug (🤑) Parameter tampering NA Kanchan Singh Yadav (@KanchanSingh0) Bug Bounty2019-06-282023-06-13
4067Stored XSS on Indeed Stored XSS Indeed Tirtha Mandal (@tirtha_mandal) Bug Bounty2019-06-302023-06-13
4066Accidental IDOR IDOR NA Saad Ahmed (@XSaadAhmedX) Bug Bounty2019-07-012023-06-13