Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
5147[demo.paypal.com] Node.js code injection (RCE) RCE Paypal Michael Stepankin (@artsploit) Bug Bounty2016-08-192023-06-13
5146Floating Domains – Taking Over 20K DigitalOcean Domains via a Lax Domain Import System Subdomain takeover DigitalOcean Matthew Bryant (@IAmMandatory) Bug Bounty2016-08-252023-06-13
5145Turning Self-XSS into Good XSS v2: Challenge Completed but Not Rewarded XSS Uber - Bug Bounty2016-08-292023-06-13
5144PornHub: Email Confirmation Bypass Email verification bypass PornHub Vaxo Dai (@___0x00) Bug Bounty2016-09-042023-06-13
5143RCE In AddThis RCE AddThis whitehatnepal Bug Bounty2016-09-042023-06-13
5142Reading Uber’s Internal Emails [Uber Bug Bounty report worth $10,000] Subdomain takeover Uber Rojan Rijal (@uraniumhacker) Bug Bounty2016-09-052023-06-13
5141Internet Explorer has a URL problem OAuth RPO XSS GitHub Google File Descriptor (@filedescriptor) Bug Bounty2016-09-062023-06-13
5140Decoding a $😱,000.00 htpasswd bounty .htpasswd misconfiguration NA Patrik Fehrenbach (@ITSecurityguard) Bug Bounty2016-09-082023-06-13
5139How I snooped into your private Slack messages [Slack Bug bounty worth $2,500] Subdomain takeover Slack Rojan Rijal (@uraniumhacker) Bug Bounty2016-09-132023-06-13
5138Bug Bounty : Account Takeover Vulnerability POC OAuth Account takeover XSS NA Rakesh Mane (@RakeshMane10) Bug Bounty2016-09-162023-06-13
5137CSRF in partners.facebook.com CSRF Meta / Facebook Prashanth Varma (@cymtrick) Bug Bounty2016-09-202023-06-13
5136Vine Re-auth Bypass [Twitter Bug Bounty] Authentication flaw Twitter Abdullah Hussam (@Abdulahhusam) Bug Bounty2016-09-212023-06-13
5135Link Injection Manipulation at admin.google.com Hyperlink injection Google Ak1T4 (@akita_zen) Bug Bounty2016-09-232023-06-13
5134Persisting on Pornhub Stored XSS PornHub Andy Gill (@ZephrFish) Bug Bounty2016-09-232023-06-13
5133XSS Vulnerability in Twitter [https://twitter.com] (Write Up) XSS Twitter Evan Ricafort (@evanricafort) Bug Bounty2016-09-262023-06-13
5132gif it time it%27ll come to you - Finding More Holes in The Hub XSS PornHub Andy Gill (@ZephrFish) Bug Bounty2016-10-012023-06-13
5131Command Injection Without Spaces OS command injection NA Fyoorer (@ƒyoorer) Bug Bounty2016-10-022023-06-13
5130Open Redirect Scanner with Uber.com Open redirect Uber Ak1T4 (@akita_zen) Bug Bounty2016-10-102023-06-13
5129Parameter pollution bug at twitter HTTP parameter pollution Twitter Mert (@mertistaken) Bug Bounty2016-10-122023-06-13
5128Exploiting CORS misconfigurations for Bitcoins and bounties CORS misconfiguration NA James Kettle (@albinowax) Bug Bounty2016-10-122023-06-13
5127Hacking JasperReports – The Hidden Shell Feature RCE NA Steve Breen (@breenmachine) Bug Bounty2016-10-142023-06-13
5126Leak Private Videos [Vimeo Bug Bounty] Logic flaw Authorization flaw Vimeo Abdullah Hussam (@Abdulahhusam) Bug Bounty2016-10-232023-06-13
5124Backslash Powered Scanning: hunting unknown vulnerability classes - NA James Kettle (@albinowax) Bug Bounty2016-11-042023-06-13
5123Stored XSS in UniFi v4.8.12 Controller Stored XSS Ubiquity Networks Shubham Gupta (@hackerspider1) Bug Bounty2016-11-122023-06-13
5122Svg XSS in Unifi v5.0.2 Stored XSS Ubiquity Networks Shubham Gupta (@hackerspider1) Bug Bounty2016-11-132023-06-13