Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
2467M1 Macs GateKeeper bypass aka CVE-2021-30658 Local Privilege Escalation Apple Wojciech Reguła (@_r3ggi) Bug Bounty2021-06-182023-06-13
2466Account takeover via stored XSS with arbitrary file upload Insecure file upload XSS Account takeover NA 0xbadb00da (@0xbadb00da) Bug Bounty2021-06-182023-06-13
2465Accessing Restricted Documents With Extra JSON Body Content Mass assignment Authorization flaw NA Imran Huda (@imranHudaA) Bug Bounty2021-06-182023-06-13
2464Exploiting File Upload Functionality in Unique Way. Unrestricted file upload NA Rohit Soni (@streetofhacker) Bug Bounty2021-06-192023-06-13
2463Zero Click account Takeover Account takeover Password reset NA Zahir Tariq (@ZahirTariq3) Bug Bounty2021-06-192023-06-13
2462Full Local File Read via Error Based XXE using XLIFF File XXE NA pwn.vg / Tomi (@mastomii) Bug Bounty2021-06-192023-06-13
2460Unprivileged User with Read/Write permission to `User Access` can escalate their role to ADMIN — Privilege Escalation Privilege escalation NA Ertugrul Ozdemir (@ertugrulphp) Bug Bounty2021-06-202023-06-13
2458Cracking Encrypted Credit Card Numbers Exposed By API Information disclosure Weak crypto NA Craig Hays (@craighays) Bug Bounty2021-06-222023-06-13
2456How i was able to get Appreciation from the organization of a website just by changing a sign..!!! Information disclosure Source code disclosure NA Fardeen Ahmed (@fardeenahmed411) Bug Bounty2021-06-232023-06-13
2452Flywheel Subdomain Takeover Subdomain takeover NA Smaran Chand (@smaranchand) Bug Bounty2021-06-242023-06-13
2451A supply-chain breach: Taking over an Atlassian account XSS CSRF Atlassian Dikla Barda, Yaara Shriki Bug Bounty2021-06-242023-06-13
2450PII Leakage - Revealing Secrets Information disclosure NA Jerry Shah (@Jerry) Bug Bounty2021-06-252023-06-13
2449From Information Disclosure to interesting Privilege Escalation Information disclosure Account takeover Privilege escalation NA David Shaul (@dudy2kk) Bug Bounty2021-06-252023-06-13
2448Gaining access to protected components Vulnerable Android content provider Android NA DavMehtab Zafar (@0xmzfr) Bug Bounty2021-06-252023-06-13
2447Some ways to find more IDOR IDOR NA Thái Vũ (@thaivd98) Bug Bounty2021-06-262023-06-13
2444Escalating XSS to Arbitrary File Read XSS LFI NA Pethuraj (@Pethuraj) Bug Bounty2021-06-272023-06-13
2443Misconfigured $3 Bucket - A Semi Opened Environment AWS misconfiguration Redbull Yukesh Kumar (@3th1c_yuk1) Bug Bounty2021-06-272023-06-13
2440How I found my first Chrome bug (CVE-2021–21210) NAT Slipstreaming Google (Chrome) Daniel Santos (@bananabr) Bug Bounty2021-06-282023-06-13
2439gcp-dhcp-takeover-code-exec DHCP flood VM takeover Google Imre Rad (@ImreRad) Bug Bounty2021-06-282023-06-13
2438How I was able to Takeover Accounts on Foxit.com Password reset Account takeover NA Jefferson Gonzales (@gonzxph) Bug Bounty2021-06-292023-06-13
2437Pre-auth RCE in ForgeRock OpenAM (CVE-2021-35464) RCE Insecure deserialization NA Michael Stepankin (@artsploit) Bug Bounty2021-06-292023-06-13
2435Testing Cookies worth $500 Account takeover IDOR NA Sankalpa Acharya (@sankalpa_02) Bug Bounty2021-06-302023-06-13
2432Blind XSS in Apple School- Enrollment Data Disclosure Blind XSS Apple hackrzvijay (@hackrzvijay) Bug Bounty2021-07-052023-06-13
2431Solarwinds Serv-U 15.2.3 Share URL XSS (CVE-2021-32604) XSS SolarWinds Victor Kahan Bug Bounty2021-07-062023-06-13
2430Exploiting Auto-save Functionality To Steal Login Credentials HTML injection NA Saad Ahmed (@XSaadAhmedX) Bug Bounty2021-07-062023-06-13