Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
3309Self stored xss to full account takeover XSS Account takeover NA Jatin Aesthetic (@techyfreakk) Bug Bounty2020-07-122023-06-13
3308How An API Misconfiguration Can Lead To Your Internal Company Data Information disclosure NA Me9187 (@Me9187) Bug Bounty2020-07-122023-06-13
3307SSRF in import file function SSRF NA Rafael Silva Bug Bounty2020-07-142023-06-13
3306Exploiting Imported Libraries to Bypass WAF Reflected XSS NA Greg Gibson Bug Bounty2020-07-142023-06-13
3305Hunting postMessage Vulnerabilities postMessage DOM XSS Apple Google (Youtube) Adobe Gary O%27Leary-Steele (@garyoleary) Bug Bounty2020-07-142023-06-13
3304Admin ,Editor can disclose personnel email of other editor, admin on page(who created shop) Information disclosure Meta / Facebook The 3 Day Account Takeover Bug Bounty2020-07-162023-06-13
3303The 3 Day Account Takeover Logic flaw Password reset Account takeover Bruteforce Lack of rate limiting NA Mr. Beast (@__mr_beast__) Bug Bounty2020-07-172023-06-13
3302I am able to see user’s sensitive data through JSON file. Information disclosure Authorization flaw NA Saurabh siddharam sanmane (@saurabhsanmane2) Bug Bounty2020-07-172023-06-13
3301The Story of My first 4 digit bounty from Facebook Logic flaw Information disclosure Meta / Facebook Sudip Shah Bug Bounty2020-07-172023-06-13
3300How I lost my followers on Medium GraphQL Authorization flaw Medium Florian (@fh4ntke) Bug Bounty2020-07-172023-06-13
3299Idor in google product IDOR Google Baluz (@t3chman) Bug Bounty2020-07-172023-06-13
3298Android pin bypass with rate limiting Lack of rate limiting Authentication bypass NA Baluz (@t3chman) Bug Bounty2020-07-182023-06-13
3297Creative Android pin bypass with Race conditon Race condition Authentication bypass NA Baluz (@t3chman) Bug Bounty2020-07-182023-06-13
3296Unique Case for Price Manipulation | BugBounty | VAPT Payment tampering NA Harshit Sengar (@sengarharshit1) Bug Bounty2020-07-182023-06-13
3295How I landed on my first bounty : No SPF / DMARC Record Found leading to Social Engineering Attack No valid SPF records No DMARC records Lululemon Fardeen Ahmed Bug Bounty2020-07-182023-06-13
3294bypass user-restriction registration Logic flaw Payment tampering NA Mohamed Ayad Bug Bounty2020-07-182023-06-13
3293Chaining rate limiting for account lockout Lack of rate limiting NA Sandip Oli Bug Bounty2020-07-192023-06-13
3292DOS over wep application DoS NA Mohamed Ayad Bug Bounty2020-07-192023-06-13
3291The $1,000 worth cookie XSS Mail.ru Jadek Mark (@mase289) Bug Bounty2020-07-192023-06-13
3290Denial of Service(DoS) By Regex DoS NA Ashik B Bug Bounty2020-07-202023-06-13
3289Increasing reward points N number of time Logic flaw NA Saddam Hussain (@wisdomfreak1) Bug Bounty2020-07-212023-06-13
3288Hack Till Your Last Breath IDOR NA mechboy / _m.u.h.e_ (@Muhe76355002) Bug Bounty2020-07-212023-06-13
3286HTTP Parameter Pollution - It’s Contaminated HTTP parameter pollution NA Shrey Shah (@ShreySh43332033) Bug Bounty2020-07-242023-06-13
3285Hunting Android Application Bugs Using Android Studio. Authorization flaw Client-side enforcement of server-side security Information disclosure NA Tarek Mohammed (@Conan0x3) Bug Bounty2020-07-242023-06-13
3284A $5000 Account Takeover Account takeover Password reset NA neelam Bug Bounty2020-07-252023-06-13