Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
3012Turning Blind Error Based SQL Injection into Exploitable Boolean One SQL injection NA Ozgur Alp (@ozgur_bbh) Bug Bounty2020-11-212023-06-13
3010Weird (im)possible XSS on error page Reflected XSS NA Rody Shahnazarian (@Komradz86) Bug Bounty2020-11-212023-06-13
2981"Important, Spoofing" - zero-click, wormable, cross-platform remote code execution in Microsoft Teams RCE Stored XSS CSP bypass CSTI Microsoft Oskars Vegeris Bug Bounty2020-12-072023-06-13
2979How I Was Able To Take Over One Of Dell’s Subdomains Subdomain takeover Dell Taha Bıyıklı (@tahabykl) Bug Bounty2020-12-082023-06-13
2974Hiding from a custom list is possible on who sees our post is possible making victim not remove them from the list. Logic flaw Meta / Facebook Baibhav Anand (@SpongeBhav) Bug Bounty2020-12-112023-06-13
2954This is how I was able to view anyone’s private email and birthday on Instagram Information disclosure Logic flaw Meta / Facebook Saugat Pokharel (@saugatpk5) Bug Bounty2020-12-202023-06-13
2949Hiding from custom story privacy list is possible in FBlite making the victim unable to remove you from the list. Logic flaw Meta / Facebook Baibhav Anand (@SpongeBhav) Bug Bounty2020-12-242023-06-13
2938Event Creator Is Not Able To Block The Attacker During Event Livestream Logic flaw Meta / Facebook Prakash Panta (@prakashpanta268) Bug Bounty2020-12-302023-06-13
2937Group Admin Can’t Able To Moderate Comments When Posted Through Page : Facebook Bug Bounty 2020 Logic flaw Meta / Facebook Prakash Panta (@prakashpanta268) Bug Bounty2020-12-302023-06-13
2934Facebook bug bounty (500 USD) : A blocked fundraiser organizer would be unable to view or remove themselves from the fundraiser. DoS Logic flaw Meta / Facebook Vivek ps (@vivekps143) Bug Bounty2020-12-312023-06-13
2924Achieving Remote Code Execution By Exploiting Variable Check Feature RCE NA Shawar Khan (@ShawarkOFFICIAL) Bug Bounty2021-01-062023-06-13
2912A %27Novel%27 Way to Bypass Executable Signature Checks with Electron Local Privilege Escalation NA Parsia Hackerman (@cryptogangsta) Bug Bounty2021-01-082023-06-13
2911How I was able to Regain access to account deleted by Admin leading to $$$ Logic flaw Authorization flaw NA Rajesh Ranjan (@_rajesh_ranjan_) Bug Bounty2021-01-102023-06-13
2897Irremovable Facebook group album photos and entire album under certain circumstances (Bounty: 1000 USD) Logic flaw Meta / Facebook Shubham Bhamare (@theshubh77) Bug Bounty2021-01-142023-06-13
2840How I was able to Turn a XSS into a Account Takeover Web cache poisoning Stored XSS Account takeover OAuth Logic flaw NA Josh Fam (@Pullerze) Bug Bounty2021-02-032023-06-13
2816How I was able to get extra coins Logic flaw Android NA Saddam Hussain (@wisdomfreak1) Bug Bounty2021-02-122023-06-13
2799SHAREit Flaw Could Lead to Remote Code Execution Android RCE MiTM Man-in-the-Disk attack Insecure intent Vulnerable Android content provider SHAREit Echo Duan Bug Bounty2021-02-152023-06-13
2778Is Math.random() Safe? from missing rate limit to bypass 2fa and possible sqli Race condition Lack of rate limiting OTP bypass SQL injection NA Yasser Mohammed (@boomneroli) Bug Bounty2021-02-202023-06-13
2744The Invincible Kid Logic flaw Meta / Facebook Samip Aryal (@samiparyal_) Bug Bounty2021-03-032023-06-13
2741Low hanging fruits on Facebook Group Room. Unable to remove post on group when post room add with event ($500) Logic flaw Meta / Facebook Randy Arios Bug Bounty2021-03-042023-06-13
2733Partially disable Cybereason EDR as low privileges user on Windows EDR bypass Local Privilege Escalation Cybereason Mehdi Alouache Bug Bounty2022-10-282023-06-13
2690How I was able to see likes and dislikes count even though is hidden by victim | YouTube #2 Broken Access Control IDOR Google R ando (@Rando02355205) Bug Bounty2021-03-262023-06-13
2687How I was able to see likes and dislikes count even though is hidden by victim | YouTube #1 Broken Access Control IDOR Google R ando (@Rando02355205) Bug Bounty2021-03-282023-06-13
2647Exploiting Struts RCE on 2.5.26 RCE Double OGNL evaluation Apache Struts Chris (@mc_0wn) Bug Bounty2021-04-122023-06-13
2620How I was able to inject XSS payload into any user%27s mailbox XSS NA Gaurav Popalghat (@N008x) Bug Bounty2021-04-212023-06-13