Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
3418Account takeover via postMessage Account takeover postMessage NA socket (@yxw21) Bug Bounty2020-06-052023-06-13
3417Multiple Information exposed due to misconfigured Service-now ITSM instances Missing authentication Information disclosure NA Th3G3nt3lman (@Th3G3nt3lman) Bug Bounty2020-06-052023-06-13
3416From 3,99 to 1,650 USD (Part I) – Simple Vertical Privilege Escalation by Changing HTTP Response Privilege escalation NA YoKo Kho (@YokoAcc) Bug Bounty2020-06-062023-06-13
3415XSS to Database Credential Leakage & Database Access β€” Story of total luck! Reflected XSS Information disclosure NA Harsh Bothra (@harshbothra_) Bug Bounty2020-06-062023-06-13
3414How i earned $500 from google by change one character . CSRF Google Oday Alhalbe Bug Bounty2020-06-062023-06-13
3413Different host header injection worth 2k Host header injection NA Imran Nissar (@Imrannissar3) Bug Bounty2020-06-072023-06-13
3412This is fine 🐢 Information disclosure NA Ricardo Iramar dos Santos (@ricardo_iramar) Bug Bounty2020-06-082023-06-13
3411Local Privilege Escalation Discovered in VMware Fusion Local Privilege Escalation MacOS VMware Rich Mirch (@0xm1rch) Bug Bounty2020-06-092023-06-13
3410The Accidental RCE Unrestricted file upload NA Mr. Beast (@__mr_beast__) Bug Bounty2020-06-092023-06-13
3409Cmd Hijack - a command/argument confusion with path traversal in cmd.exe OS command injection Path traversal Microsoft Julian Horoszkiewicz Bug Bounty2020-06-102023-06-13
3408Abusing Microsoft Teams rate limiting for DDoS DoS Microsoft Omayr Zanata (@omayrzanata) Bug Bounty2020-06-102023-06-13
3407The β€œP5” Link Injection Story Hyperlink injection NA Silent Bronco (@silentbronco) Bug Bounty2020-06-102023-06-13
3406Utilizing Lockdown: Blind Sqli leads to Account Takeover & Data Extraction Blind SQL injection Account takeover NA Shakti Mohanty (@3ncryptSaan) Bug Bounty2020-06-102023-06-13
3405Privilege Escalation by Changing HTTP Response (Admin Access) Privilege escalation NA Bachrudin Ashari Pujakusuma (@Bachrudinashari) Bug Bounty2020-06-102023-06-13
3404Guest Blog: From File Upload to RCE Unrestricted file upload RCE NA Lukasz Wierzbicki (@v13rs8a) Bug Bounty2020-06-102023-06-13
3403The Frustrating XSS XSS NA Mr. Beast (@__mr_beast__) Bug Bounty2020-06-112023-06-13
3402HUNT for SQL Injection- The Smart Way! SQL injection NA Mudassir Sharief Bug Bounty2020-06-112023-06-13
3401Race Conditions - Exploring the Possibilities Race condition Reddit Milind Purswani (@MilindPurswani) Bug Bounty2020-06-112023-06-13
3400Let’s Bypass CSRF Protection & Password Confirmation to Takeover Victim Accounts :D CSRF NA Harsh Bothra (@harshbothra_) Bug Bounty2020-06-122023-06-13
3399DoS and BugBounties :A series of DoS attacks on HackerOne DoS NA Ninad Mishra (@iamr000t) Bug Bounty2020-06-122023-06-13
3398Account Takeover via OTP Bruteforce (Apigee API) OTP bypass Bruteforce Lack of rate limiting NA Vishnuraj Bug Bounty2020-06-132023-06-13
3397RACE Condition vulnerability found in bug-bounty program Race condition NA Pravinrp Bug Bounty2020-06-132023-06-13
3392How to Secure AWS ServerLess Lambda from ReDoS(Regular Expression Denial-of-Service) & Resultant Financial Impact ReDoS NA Ddigvijay (@itsdig) Bug Bounty2020-06-142023-06-13
3391Another "Fappening" on the Horizon? Account takeover Phishing Apple Sociosploit Bug Bounty2020-06-152023-06-13
3390Business logic flaw in the invitation system allows to Takeover any account at a private company Account takeover IDOR NA Daniel V. (@d4niel_v) Bug Bounty2020-06-152023-06-13