Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
3817700$ Denial of Service(DoS) vulnerability in script-loader.php (CVE-2018-6389) DoS NA Pankaj Thakur (@Nep_1337_1998) Bug Bounty2019-11-212023-06-13
3816Disable Any Unconfirmed Account in Facebook Bruteforce Meta / Facebook Lokesh Kumar (@lokeshdlk77) Bug Bounty2019-11-212023-06-13
3815Stories Of IDOR-Part 2 IDOR NA Shivbihari Pandey (@ninja_pandit_) Bug Bounty2019-11-212023-06-13
3814IDOR via Websockets IDOR NA Shuaib Oladigbolu (@_sawzeeyy) Bug Bounty2019-11-232023-06-13
3813Exploiting padding oracles with fixed IVs Padding oracle attack Account takeover NA Teddy Katz (@not_aardvark) Bug Bounty2019-11-232023-06-13
3812The AccountTakeOver Killing Chain Account takeover CSRF Self-XSS NA أنس روبي (@xhzeem) Bug Bounty2019-11-232023-06-13
3811CORS Misconfiguration to Account TakeOver [Out of scope to grab items In-Scope] CORS misconfiguration Open redirect Reflected XSS Session management issue NA Mashoud1122 (@mashoud1122) Bug Bounty2019-11-242023-06-13
3810Finding a security bug in Discord and what it taught me OAuth Discord Tristan Farkas (@TristanAtFarkas) Bug Bounty2019-11-242023-06-13
3809How Did Tons of People Like Me on Tinder? HTTP request smuggling NA Mustafa iran (@Mustafaran) Bug Bounty2019-11-252023-06-13
3808Getting access to disabled/hidden features with the help of Burpsuite Match and Replace settings Authorization flaw NA Johns Simon (@Johnssimon22) Bug Bounty2019-11-272023-06-13
3807Site Isolation bypass via Chrome extension Site Isolation bypass Browser hacking Google Anthony Weems Bug Bounty2019-11-272023-06-13
3806Reflected XSS in graph.facebook.com leads to account takeover in IE/Edge Reflected XSS Account takeover Meta / Facebook Youssef Sammouda (@samm0uda) Bug Bounty2019-11-272023-06-13
3805XSS Stored On [ Outlook Web — Outlook Android App ] Stored XSS Microsoft ElMahdi Mrhassel (@ElMrhassel) Bug Bounty2019-11-282023-06-13
3804Hacking GitHub with Unicode%27s dotless %27i%27 Logic flaw GitHub John Gracey (@jagracey) Bug Bounty2019-11-282023-06-13
3803How I turned Self XSS to Stored via CSRF Self-XSS CSRF NA Abhishek Yadav (@abhishake100) Bug Bounty2019-11-292023-06-13
3802My first RCE: a tale of good ideas and good friends RCE ImageTragick NA rez0 (@rez0__) Bug Bounty2019-11-292023-06-13
3801Dank Writeup On Broken Access Control On An Indian Startup Unrestricted file upload Authorization flaw NA Divyanshu Shukla (@justm0rph3u5) Bug Bounty2019-11-302023-06-13
3800XSS like a Pro XSS NA Anas Mahmood (@AnasIsHere) Bug Bounty2019-12-052023-06-13
3799HTTP Request Smuggling + IDOR HTTP request smuggling IDOR NA hipotermia (@_hipotermia_) Bug Bounty2019-12-052023-06-13
3798Google Chrome portal element fuzzing RCE Memory corruption Buffer Overflow Use-After-Free Google Pawel Wylecial (@h0wlu) Bug Bounty2019-12-062023-06-13
3797$150 XSS at Error Page of Respository Code Reflected XSS NA Navneet (@na5n33t) Bug Bounty2019-12-072023-06-13
3796HTML Injection to XSS bypass in [REDACTED.com] Reflected XSS NA Evan Ricafort (@evanricafort) Bug Bounty2019-12-072023-06-13
3795Reusing Cookies Session management issue NA Ricardo Iramar dos Santos Bug Bounty2019-12-072023-06-13
3794Spilling Local Files via XXE when HTTP OOB fails XXE NA Rahul Maini (@iamnoooob) Bug Bounty2019-12-072023-06-13
3793Telegram (v4.9.155353) was rendering file:// links + opening them via NSWorkspace.open -> code execution. RCE Telegram Vladimir Metnew (@vladimir_metnew) Bug Bounty2019-12-082023-06-13