Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
2515Escalating SSRF to Accessing all user PII information by aws metadata SSRF NA Santosh Kumar Sha (@killmongar1996) Bug Bounty2021-05-312023-06-13
2511Escalating SSRF to Accessing all user PII information by aws metadata SSRF NA Santosh Kumar Sha (@killmongar1996) Bug Bounty2021-06-012023-06-13
2505Server Side Request Forgery - A Forged Document SSRF File upload NA Jerry Shah (@Jerry) Bug Bounty2021-06-032023-06-13
2498How Github recon help me to find NINE FULL SSRF Vulnerability with AWS metadata access SSRF NA Santosh Kumar Sha (@killmongar1996) Bug Bounty2021-06-062023-06-13
2496Story of my first cash bounty on hackerone. SSRF XSS NA Vedant Tekale (@_justYnot) Bug Bounty2021-06-072023-06-13
2483An exciting journey to find SSRF , Bypass Cloudflare , and extract AWS metadata ! SSRF NA hosein vita (@HoseinVita) Bug Bounty2021-06-132023-06-13
2441Diving into Dependabot along with a bug in npm SSRF RCE GitHub tyage (@tyage) Bug Bounty2021-06-272023-06-13
2379Telegram Report: SSRF leads to DOS attack [Reports that didn%27t make it] SSRF DoS Telegram Philippe Delteil (@PhilippeDelteil) Bug Bounty2021-07-272023-06-13
2358Blind XXE Leads to Internal Port Scanning Through SSRF XXE SSRF NA Sam Paredes (@caffeinevulns) Bug Bounty2021-08-012023-06-13
2330Blind SSRF in URL Validator Blind SSRF NA Yash Kandekar (@Neutron__) Bug Bounty2021-08-122023-06-13
2325Finding multiple SSRF with aws metadata access on A BANK system SSRF NA Santosh Kumar Sha (@killmongar1996) Bug Bounty2021-08-142023-06-13
2305Server Side Request Forgery with huge impact in production application SSRF NA Gökhan Güzelkokar (@gkhck_) Bug Bounty2021-08-232023-06-13
2285SSRF External Service Interaction for Find Real IP CloudFlare and Leads to SQL Injection WAF bypass SSRF SQL injection NA Caesar Evan Santoso Bug Bounty2021-08-282023-06-13
2244SSRF in PDF export with PhantomJs SSRF XSS LFI NA أنس روبي (@xhzeem) Bug Bounty2021-09-072023-06-13
2209Chaining bugs for better bounties SSRF XSS Information disclosure NA Manas Harsh (@ManasH4rsh) Bug Bounty2021-09-192023-06-13
2175Pre-Auth SSRF To Full MailBox Access (Microsoft Exchange Server Exploit) SSRF NA Vanshal Gaur (@VanshalG) Bug Bounty2021-10-022023-06-13
2166Hacking Netflix Eureka! SSRF XSS Netflix Maxim Tyukov (@maxtyukov) Bug Bounty2021-10-062023-06-13
2133Moodle - Stored XSS and blind SSRF possible via feedback answer text Stored XSS SSRF Moodle rekter0 (@rekter0) Bug Bounty2021-10-222023-06-13
2120Easy SSRF from Wayback Machine SSRF NA Khaled Mohamed (@0xElkomy) Bug Bounty2021-10-272023-06-13
2089Unrestricted File Upload Leads to SSRF and RCE ImageTragick Unrestricted file upload SSRF RCE NA Muhammad Adel (@ItsFadinG_) Bug Bounty2021-11-112023-06-13
2087Simple SSRF Allows Access To Internal Assets SSRF NA Sam Paredes (@caffeinevulns) Bug Bounty2021-11-112023-06-13
2067URL whitelist bypass in https://cxl-services.appspot.com Privilege escalation URL validation bypass SSRF Google David Schütz (@xdavidhu) Bug Bounty2021-11-172023-06-13
2052Multiple Vulnerabilities In Concrete CMS – Part2 (PrivEsc/SSRF/etc) Privilege escalation SSRF Concrete CMS FORTBRIDGE (@FORTBRIDGE1) Bug Bounty2021-11-252023-06-13
2038VMware vCenter earlier versions (7.0.2.00100) has unauthorized arbitrary file read + ssrf + xss vulnerability LFI SSRF XSS Arbitrary file read VMware Khoa Dinh (@_l0gg) Bug Bounty2021-11-302023-06-13
2021SSRF vulnerability in AppSheet - Google VRP SSRF Google David Nechuta (@david_nechuta) Bug Bounty2021-12-052023-06-13