Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
3952Private bug bounty $$,$$$ USD: “RCE as root on Marathon-Mesos instance” RCE NA Omar Espino (@omespino) Bug Bounty2019-08-272023-06-13
3951How to look for JS files Vulnerability for fun and profit? Information disclosure NA Yeasir Arafat Bug Bounty2019-08-272023-06-13
3950Address bar spoofing in Firefox Lite for Android ...and the idiocy that followed Address Bar Spoofing URL spoofing Mozilla Piyush Raj (@0x48piraj) Bug Bounty2019-08-012023-06-13
3949Shodan is your friend!!! If you ignore him you will lose many… SQL injection Authentication bypass NA Vijaysimha Reddy Bathini (@fatratfatrat) Bug Bounty2019-08-282023-06-13
3948My First LFI LFI NA Tirtha Mandal (@tirtha_mandal) Bug Bounty2019-08-312023-06-13
3947Graphql Bug to Steal Anyone’s Address Information disclosure GraphQL NA Pratik Yadav (@PratikY9967) Bug Bounty2019-09-012023-06-13
3946Google Cloud Blog platform vulnerability XSS Google Alexandru Coltuneac (@dekeeu) Bug Bounty2019-09-012023-06-13
3944RCE using Path Traversal RCE Path traversal NA inc0gbyt3 (@incogbyte) Bug Bounty2019-09-022023-06-13
3943Add new user with Admin permission and takeover the organization Authorization flaw Privilege escalation NA Tarek Mohamed (@Conan0x3) Bug Bounty2019-09-042023-06-13
3942Exposed Jenkins to RCE on 8 Adobe Experience Managers RCE Exposed Jenkins instance NA Corben Leo (@hacker_) Bug Bounty2019-09-042023-06-13
3941Readme.com Account Takeover Password reset Readme.com Ankush Goel (@0xankush) Bug Bounty2019-09-052023-06-13
3940DOM Based XSS in Private Program DOM XSS NA Mohamed Haron (@m7mdharon) Bug Bounty2019-09-052023-06-13
3939Super Glamorous Recon with Intended Functionalities SSTI XSS NA hateshape (@hateshaped) Bug Bounty2019-09-062023-06-13
3938Finding Gem in Someone’s Report: Instant $500USD at HackerOne Platform Information disclosure NA Hisoka Morou Bug Bounty2019-09-072023-06-13
3937Write up of two HTTP Requests Smuggling HTTP request smuggling NA C1h2e1 (@C1h2e11) Bug Bounty2019-09-072023-06-13
3936Exploiting JSONP and Bypassing Referer Check Information disclosure JSONP NA Osama Avvan (@osamaavvan) Bug Bounty2019-09-072023-06-13
3935XSS in Zoho Mail XSS Zoho Anas Mahmood (@AnasIsHere) Bug Bounty2019-09-082023-06-13
3934Oculus identity verification bypass through brute-force OTP bypass Lack of rate limiting Meta / Facebook karthik kumar reddy (@karthiksunny007) Bug Bounty2019-09-092023-06-13
3933Accessing 2 million Verizon Pay Monthly contracts Information disclosure Authentication bypass IDOR Yahoo! / Verizon Media Daley Bee (@daley) Bug Bounty2019-09-092023-06-13
3932Telegram addresses another privacy issue Logic flaw Privacy issue Telegram Dhiraj (@RandomDhiraj) Bug Bounty2019-09-092023-06-13
3931H1-4420: From Quiz to Admin - Chaining Two 0-Days to Compromise An Uber Wordpress Stored XSS SQL injection Uber Julien Ahrens (@MrTuxracer) Bug Bounty2019-09-102023-06-13
3929Pwn Them All #BugBounty Host header injection Password reset NA Bilal Khan (@bilalmerokhel) Bug Bounty2019-09-112023-06-13
3927How does my recon win $250 in 15 minutes Open redirect NA Hein Thant Zin (@H3Lowr) Bug Bounty2019-09-122023-06-13
3925Exploiting File Uploads Pt. 2 – A Tale of a $3k worth RCE. Unrestricted file upload RCE NA HackerOn2Wheels (@HackerOn2Wheels) Bug Bounty2019-09-132023-06-13
3924HTTP Request Smuggling CL.TE HTTP request smuggling NA memN0ps (@memN0ps) Bug Bounty2019-09-132023-06-13