Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
3443My Expense Report resulted in a Server-Side Request Forgery (SSRF) on Lyft SSRF Lyft Ben Sadeghipour (@nahamsec) Bug Bounty2020-05-292023-06-13
3442Analysis and Discovery of CVE-2020-13693 Privilege escalation Security code review BBPress Raphael Karger (@pwnszn) Bug Bounty2020-05-292023-06-13
3441Weak Cryptography Leads To Open Redirect Open redirect NA DarkLotus (@darklotuskdb) Bug Bounty2020-05-302023-06-13
3440Microsoft%27s first bug Memory corruption File format vulnerability Microsoft Lê Hữu Quang Linh (@linhlhq) Bug Bounty2020-05-302023-06-13
3439Zero-day in Sign in with Apple Account takeover Apple Bhavuk Jain (@bhavukjain1) Bug Bounty2020-05-302023-06-13
3438Cross-site scripting: The power of the hidden parameters. Reflected XSS Sony Kassih Mouhssine (@KassihMouhssine) Bug Bounty2020-05-302023-06-13
3437The story of My First $xxx Bug Bounty From Facebook Logic flaw Information disclosure Meta / Facebook Sudip Shah Bug Bounty2020-05-312023-06-13
3436Weird “Subdomain Take Over” pattern of Amazon S3 Subdomain takeover NA Simgamsetti Manikanta (@zaheckmania) Bug Bounty2020-05-312023-06-13
3435Hunting on ASPX Application For P1%27s [Unauthenticated SOAP,RCE, Info Disclosure] RCE Information disclosure IDOR NA ElMahdi Mrhassel (@ElMrhassel) Bug Bounty2020-05-312023-06-13
3434h1{Error based XXE - bug bounty writeup} XXE NA f4d3 (@f4d3_cl) Bug Bounty2020-05-312023-06-13
3433How I made $31500 by submitting a bug to Facebook SSRF Meta / Facebook Bipin Jitiya (@win3zz) Bug Bounty2020-05-312023-06-13
3432How I leveraged an interesting CSRF vulnerability to turn self XSS into a persistent attack? Self-XSS CSRF NA Akash Methani (@0xAkash) Bug Bounty2020-06-012023-06-13
3431Information disclosure and reflected XSS on Tokopedia Reflected XSS Information disclosure Tokopedia wis4nggeni Bug Bounty2020-06-012023-06-13
3430When it’s not only about a Kubernetes CVE… SSRF Microsoft Reever Zax (@ReeverZax) Bug Bounty2020-06-022023-06-13
3429Double URL-encoded XSS Reflected XSS NA vict0ni (@vict0ni) Bug Bounty2020-06-022023-06-13
3428The Curious Case of Copy & Paste – on risks of pasting arbitrary content in browsers XSS Google Mozilla Michał Bentkowski (@SecurityMB) Bug Bounty2020-06-022023-06-13
3427IP-in-IP protocol routes arbitrary traffic by default DoS Spoofing Internet Bug Bounty yannayl (@Yannayli) Bug Bounty2020-06-022023-06-13
3426From CRLF to Account Takeover CRLF injection HTTP response splitting Reflected XSS Account takeover NA Valeriy Shevchenko (@Krevetk0Valeriy) Bug Bounty2020-06-032023-06-13
3425How I got my first big bounty payout with Tesla Information disclosure Tesla CJ Fairhead (@xyantix) Bug Bounty2020-06-042023-06-13
3424Privilege Escalation in Google Cloud Platform%27s OS Login Privilege escalation Google Chris Moberly (@init_string) Bug Bounty2020-06-042023-06-13
3423Another image removal vulnerability on Facebook IDOR Meta / Facebook Pouya Darabi (@Pouyadarabi) Bug Bounty2020-06-042023-06-13
3422Three Privilege Escalation Bugs in Google Cloud Platform’s OS Login Local Privilege Escalation Cloud Google initstring (@init_string) Bug Bounty2020-06-042023-06-13
3421[IDOR] Delete saved credit cards from any Business Manager Account — Facebook Bug Bounty IDOR Meta / Facebook Rohit kumar (@rohitcoder) Bug Bounty2020-06-052023-06-13
3420Story of Blind SQL with a typo error. SQL injection NA Amyrahm (@Amyrahm11) Bug Bounty2020-06-052023-06-13
3419Local file read via XSS using PDF generate functionality XSS LFI NA Sanjay Singh Jhala (@lordjerry0x01) Bug Bounty2020-06-052023-06-13