Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
3389Reflected User Input == XSS! Reflected XSS NA Silent Bronco (@silentbronco) Bug Bounty2020-06-152023-06-13
3388SMTP Injection in Gsuite SMTP injection Google Zohar Shachar Bug Bounty2020-06-152023-06-13
3387All *.intercom.help subdomains vulnerable to Subdomain Takeover from intercom Service Subdomain takeover Intercom Mohamed Haron (@m7mdharon) Bug Bounty2020-06-162023-06-13
3386How I was able to buy t-shirt for €1 — Payment Price Manipulation Payment tampering NA Muztahidul Tanim (@TheMuztahidul) Bug Bounty2020-06-162023-06-13
3385How I managed to Escalate privilege as admin Lack of rate limiting Bruteforce Weak credentials NA Abisheik Magesh (@AbisheikMagesh) Bug Bounty2020-06-162023-06-13
3384How I made more than $30K with Jolokia CVEs Reflected XSS RCE Information disclosure NA Patrik Fehrenbach (@ITSecurityguard) Bug Bounty2020-06-162023-06-13
3382A subtle stored-XSS in WordPress core Stored XSS RCE WordPress Sam Thomas (@_s_n_t) Bug Bounty2020-06-172023-06-13
3381Hackerone Bug Bounty Report: Hinge Information disclosure Hinge Tyle Butler (@tbutler0x90) Bug Bounty2020-06-182023-06-13
3380Replying on LiveStream leading to Page Admin Disclosure: Facebook Bug Bounty Information disclosure Meta / Facebook Saugat Pokharel (@saugatpk5) Bug Bounty2020-06-182023-06-13
3379One Token to leak them all : The story of a $8000 NPM_TOKEN Information disclosure Google Aseem Shrey (@AseemShrey) Bug Bounty2020-06-192023-06-13
3378From Recon to Bypassing MFA Implementation in OWA by Using EWS Misconfiguration Information disclosure MFA bypass NA YoKo Kho (@YokoAcc) Bug Bounty2020-06-192023-06-13
3377Hacking Starbucks and Accessing Nearly 100 Million Customer Records Path traversal Starbucks Sam Curry (@samwcyo) Bug Bounty2020-06-202023-06-13
3376How did i find information Disclosure on Facebook-Writeup Information disclosure Meta / Facebook Alaa Abdulridha (@Madrid89001310) Bug Bounty2020-06-202023-06-13
3375Bypass 2FA like a Boss Lack of rate limiting Bruteforce NA Seqrity (@seQrity) Bug Bounty2020-06-202023-06-13
3374Simple story of some complicated XSS on Facebook Reflected XSS Meta / Facebook Bipin Jitiya (@win3zz) Bug Bounty2020-06-212023-06-13
3373It took me only 5 minutes to find an RCE on Bentley RCE Weak credentials Bentley Divyansh Sharma Bug Bounty2020-06-212023-06-13
3372How i was able to chain bugs and gain access to internal okta instance Missing authentication NA Mmohammed Eldeeb (@malcolmx0x) Bug Bounty2020-06-222023-06-13
3371API Token Hijacking Through Clickjacking Clickjacking NA DarkLotus (@darklotuskdb) Bug Bounty2020-06-222023-06-13
3370Leveraging an SSRF to leak a secret API key SSRF NA Julien Cretel (@jub0bs) Bug Bounty2020-06-222023-06-13
3369A tale of my first ever full SSRF bug SSRF NA Jadek Mark (@mase289) Bug Bounty2020-06-222023-06-13
3368Exploiting Bitdefender Antivirus: RCE from any website RCE Information disclosure Bitdefender Wladimir Palant (@WPalant) Bug Bounty2020-06-222023-06-13
3367All About Getting First Bounty with IDOR IDOR NA Mukul Trivedi (@M0hn1sh) Bug Bounty2020-06-232023-06-13
3366Bug Bounty in Lockdown (SQLi and Business Logic) SQL injection Logic flaw NA Abhishek Yadav (@abhishake100) Bug Bounty2020-06-242023-06-13
3365Create hidden comment by blocking an Admin: Facebook Bug Bounty 2020 Logic flaw Meta / Facebook Saugat Pokharel (@saugatpk5) Bug Bounty2020-06-252023-06-13
3364How i hacked worldwide ZOOM users OAuth Account takeover Zoom s3c (@s3c_krd) Bug Bounty2020-06-272023-06-13