Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
2105A Technical Analysis of CVE-2021-30864: Bypassing App Sandbox Restrictions Local Privilege Escalation MacOS Apple Perception Point (@PerceptionPo1nt) Bug Bounty2021-11-032023-06-13
20994 Crits in 48 hours: Unicorn Programs Privilege escalation Information disclosure IDOR NA Monke (@pmofcats) Bug Bounty2021-11-062023-06-13
2091ChaosDB Explained: Azure%27s Cosmos DB Vulnerability Walkthrough Cross-tenant vulnerability Account takeover Privilege escalation Microsoft Nir Ohfeld (@nirohfeld) Bug Bounty2021-11-102023-06-13
2083Privilege Escalation, worth of €300 Broken Access Control IDOR Privilege escalation NA Hemant Kumar Bug Bounty2021-11-122023-06-13
2067URL whitelist bypass in https://cxl-services.appspot.com Privilege escalation URL validation bypass SSRF Google David Schütz (@xdavidhu) Bug Bounty2021-11-172023-06-13
2058GoSecure Investigates Abusing Windows Server Update Services (WSUS) to Enable NTLM Relaying Attacks Local Privilege Escalation Microsoft Romain Carnus Bug Bounty2021-11-222023-06-13
2052Multiple Vulnerabilities In Concrete CMS – Part2 (PrivEsc/SSRF/etc) Privilege escalation SSRF Concrete CMS FORTBRIDGE (@FORTBRIDGE1) Bug Bounty2021-11-252023-06-13
2019Hacking into Admin Panel of U.S Federal government system C.A.R.S — without credentials. Client-side enforcement of server-side security Privilege escalation U.S. General Services Administration Hazem Brini (@ImJungsuu) Bug Bounty2021-12-072023-06-13
2016Privilege Escalation in Microsoft Teams Privilege escalation Broken Access Control Microsoft Vikas Anil Sharma (@vikzsharma) Bug Bounty2021-12-072023-06-13
1997Bypassing the macOS Gatekeeper Local Privilege Escalation Gatekeeper bypass MacOS Apple Ron Masas (@RonMasas) Bug Bounty2021-12-152023-06-13
1979Sandbox escape + privilege escalation in StorePrivilegedTaskService Local Privilege Escalation MacOS Apple Sector 7 (@sector7_nl) Bug Bounty2021-12-212023-06-13
1939Accessing GoDaddy internal instance through an email logic bug. Logic flaw Privilege escalation Account takeover GoDaddy Mostafa Mamdoh Bug Bounty2022-01-052023-06-13
1936Exploiting Redash instances with CVE-2021-41192 Privilege escalation Session management issue SSRF NA Ian Carroll (@iangcarroll) Bug Bounty2022-01-062023-06-13
1870Microsoft OneDrive For Macos Local Privilege Escalation Local Privilege Escalation MacOS Microsoft Offensive Security (@offsectraining) Bug Bounty2022-01-312023-06-13
1861A misconfigured Apache Airflow to AWS Account Compromise Outdated component with a known vulnerability Privilege escalation Information disclosure NA Avinash Jain (@logicbomb_1) Bug Bounty2022-02-022023-06-13
1838How Docker Made Me More Capable and the Host Less Secure Local Privilege Escalation Microsoft Alon Zahavi (@Alon_Z4) Bug Bounty2022-02-082023-06-13
1837SpoolFool: Windows Print Spooler Privilege Escalation (CVE-2022-21999) Local Privilege Escalation Microsoft Olivier Lyak (@ly4k_) Bug Bounty2022-02-082023-06-13
1811How I earned $9000 with Privilege escalations Privilege escalation NA Junaid Khan (@JunoonBro) Bug Bounty2022-02-162023-06-13
1771webOS Revisited - Even More Mistaken Identities Local Privilege Escalation Browser hacking LG Andreas Lindh (@addelindh) Bug Bounty2022-03-022023-06-13
1756Container Escape to Shadow Admin: GKE Autopilot Vulnerabilities Privilege escalation Container escape Kubernetes Google Unit 42 (@Unit42_Intel) Bug Bounty2022-03-082023-06-13
1751Escalating from Logic App Contributor to Root Owner in Azure Privilege escalation Microsoft Josh Magri (@passthehashbrwn) Bug Bounty2022-03-092023-06-13
1747CVE-2022-24696 – Glance By Mirametrix Privilege Escalation Local Privilege Escalation Lenovo Oddvar Moe (@Oddvarmoe) Bug Bounty2022-03-112023-06-13
1730CVE-2022-22616: Simple way to bypass GateKeeper, hidden for years Local Privilege Escalation GateKeeper bypass MacOS Apple Mickey Jin (@patch1t) Bug Bounty2022-03-152023-06-13
1727Securing Developer Tools: Git Integrations Local Privilege Escalation Microsoft JetBrains GitHub Sonar (@SonarSource) Bug Bounty2022-03-152023-06-13
1720Abusing Azure Hybrid Workers for Privilege Escalation – Part 1 Privilege escalation Microsoft (Azure) Josh Magri (@passthehashbrwn) Bug Bounty2022-03-172023-06-13