Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
2429Kaspersky Password Manager: All your passwords are belong to us Weak crypto Kaspersky Jean-Baptiste Bédrune Bug Bounty2021-07-062023-06-13
2428Let’s cancel the subscription (informative) Logic flaw Payment tampering NA Adnan Malik (@adnanmalikinfo) Bug Bounty2021-07-072023-06-13
2427CVE-2021-22555: Turning x00x00 into 10000$ Memory corruption Local Privilege Escalation Google Andy Nguyen (@theflow0) Bug Bounty2021-07-072023-06-13
2425Discovering Zero-Day Vulnerabilities in McAfee Products Local Privilege Escalation McAfee mr.d0x (@mrd0x) Bug Bounty2021-07-092023-06-13
2423Account Takeovers — Believe the Unbelievable Account takeover Session management issue Weak credentials Components with known vulnerabilities Password reset NA Nikhil (niks) (@niksthehacker) Bug Bounty2021-07-092023-06-13
2421Reflected XSS Through Insecure Dynamic Loading XSS NA Greg Gibson Bug Bounty2021-07-112023-06-13
2420Critical Bug Bounty Reports: Part 1 Account takeover Password reset RCE Information disclosure NA Greg Gibson Bug Bounty2021-07-112023-06-13
2419Pre-Denial Of Service (set-up 2FA on unverified account) Application-level DoS NA Vikash Maurya Bug Bounty2021-07-112023-06-13
2418Trick to bypass rate limit of password reset functionality Rate limiting bypass NA Abdulrahman-Kamel Bug Bounty2021-07-122023-06-13
2417Broken Access control bug : Bypassing 403’s by finding another endpoint that do the same thing. Broken Access Control 403 bypass NA tomorrowisnew (@tomorrowisnew_) Bug Bounty2021-07-122023-06-13
2413Forced Browsing to Access Admin Panel Forced browsing NA the_unluck_guy (@7he_unlucky_guy) Bug Bounty2021-07-132023-06-13
2411Credential stuffing in Bug bounty hunting Credential stuffing NA Valeriy Shevchenko (@Krevetk0Valeriy) Bug Bounty2021-07-142023-06-13
2410How I found Blind SQL Injection just by browsing and getting a unique URL SQL injection NA Jawad Mahdi (@hunter0x1) Bug Bounty2021-07-142023-06-13
2408RFD Vulnerability And Content-Disposition Header Bypass Story! Reflected File Download NA Kabilan S (@kabilan1290) Bug Bounty2021-07-142023-06-13
2407How i was able to bypass Cloudflare for XSS! XSS NA hosein vita (@HoseinVita) Bug Bounty2021-07-162023-06-13
2406Logical Flaw Resulting Path Hijacking Namespace attack NA Veshraj Ghimire (@GhimireVeshraj) Bug Bounty2021-07-162023-06-13
2404IIS-Default-Page-to-Information-Disclosure Information disclosure NA 0xdln (@0xdln) Bug Bounty2021-07-172023-06-13
2403RCE via WebDav - Power Of PUT Default credentials RCE NA Jerry Shah (@Jerry) Bug Bounty2021-07-182023-06-13
2402Account Takeover + A Bonus Vulnerability Account takeover Session fixation NA Vikash Maurya Bug Bounty2021-07-182023-06-13
2400How I Bypassed a tough WAF to steal user cookies using XSS! XSS WAF bypass NA Asem Eleraky (@melotover) Bug Bounty2021-07-192023-06-13
2399Hacking Xiaomi%27S Android Apps - Part 1 Android Information disclosure Open redirect Privacy issue Xiaomi Ameya (@iamTakeMyHand) Bug Bounty2021-07-192023-06-13
2398IBM HMC Exploit CVE-2021-29707 Local Privilege Escalation IBM Thomas Cope Bug Bounty2020-10-212023-06-13
2397How I was able Find mass leaked AWS s3 bucket from js File AWS misconfiguration NA Santosh Kumar Sha (@killmongar1996) Bug Bounty2021-07-202023-06-13
2396XSS-Through-Fuzzing-Default-IIS Reflected XSS NA 0xdln (@0xdln) Bug Bounty2021-07-202023-06-13
2395Guest Blog Post - Attacking the DevTools Browser hacking Microsoft David Erceg (@david_erceg) Bug Bounty2021-07-212023-06-13