Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
3657A Tale of Two Formats: Exploiting Insecure XML and ZIP File Parsers to Create a Web Shell XXE RCE Directory Traversal NA Eugene Lim (@spaceraccoonsec) Bug Bounty2020-02-182023-06-13
3656Hacking SMS API Service Provider of a Company |Android App Static Security Analysis | Bug Bounty POC Information disclosure Hardcoded credentials NA Muhammad Khizer Javed (@khizer_javed47) Bug Bounty2020-02-192023-06-13
3655Exploiting Jira for Host Discovery CSRF Atlassian Alex Peña Bug Bounty2020-02-202023-06-13
3654Hunting Tesla Model Y Secrets in the Parts Catalog Authorization flaw Tesla Evan Connelly (@Evan_Connelly) Bug Bounty2020-02-222023-06-13
3653Tale of Account Takeovers (Part-1) Account takeover HTTP parameter pollution Password reset OTP bypass NA Vijaysimha Reddy Bathini (@fatratfatrat) Bug Bounty2020-02-222023-06-13
3652Reflected XSS In AT&T Reflected XSS AT&T Myo Min Thu (@myominthu1337) Bug Bounty2020-02-232023-06-13
3651Blind XSS against a Googler Blind XSS Google Rojan Rijal (@uraniumhacker) Bug Bounty2020-02-232023-06-13
3650Discord DoS with a single message DoS Discord DarkMatterMatt Bug Bounty2020-02-242023-06-13
3649Stored-XSS-on-groups-google-com Stored XSS Google Alessandro Rumampuk (@Rando02355205) Bug Bounty2020-02-252023-06-13
3648Mail.Ru Ext.B Scope Account Takeover [ $1500 ] Account takeover OAuth Mail.ru Myo Min Thu (@myominthu1337) Bug Bounty2020-02-252023-06-13
3647How i found 3 SSRF in one day on different bug bounty targets SSRF NA - Bug Bounty2020-02-252023-06-13
3646How I Get my first P1 (Sensitive Information Disclosure) using WPScan Information disclosure NA Harrmahar (@harrmahar) Bug Bounty2020-02-262023-06-13
3645Long String DoS DoS NA Shrey Shah (@ShreySh43332033) Bug Bounty2020-02-262023-06-13
3644Write-up: AWS Document Signing Security Control Bypass AWS misconfiguration NA Ozgur Alp (@ozgur_bbh) Bug Bounty2020-02-262023-06-13
3643RCE via Apache Struts2 - Still out there. RCE NA Abhishek (@abhishake100) Bug Bounty2020-02-272023-06-13
3641The Tricky XSS XSS NA Smaran Chand (@smaranchand) Bug Bounty2020-02-282023-06-13
3640Page Admin Disclosure via an Upgraded Page Post Authorization flaw Information disclosure Meta / Facebook Dan Fabro (@0x61_) Bug Bounty2020-02-282023-06-13
3639Account Hijack using Authorization bypass $$$$ Account takeover Authorization flaw NA Bhavesh Thakur (@Bhavesh_Thakur_) Bug Bounty2020-02-282023-06-13
3638A mysterious bug in the firmware of Google%27s Titan M chip (CVE-2019-9465) Cryptographic issues Google Alexander Bakker Bug Bounty2020-02-292023-06-13
3636Discord embed spoofing Phishing Discord DarkMatterMatt Bug Bounty2020-03-022023-06-13
3635SSRF on PDF generator. SSRF NA John Michael (@michan2514) Bug Bounty2020-03-022023-06-13
3634SQL Injection Via Stopping the redirection to a login page SQL injection Authorization flaw NA Abde Ouabala (@4mgh0z) Bug Bounty2020-03-032023-06-13
3633How I CSRF’d My First Bounty! CSRF NA Rajesh Ranjan (@rajesh_ranjan4) Bug Bounty2020-03-032023-06-13
3632ManageEngine ServiceDesk Plus: Arbitrary File Upload Arbitrary file upload RCE NA Duc Anh Bui Bug Bounty2020-03-032023-06-13
3631Exploiting an SSRF: Trials and Tribulations SSRF NA A Bug’z Life (@abugzlife1) Bug Bounty2020-03-032023-06-13