Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
3258CVE-2020-13379 Unauthenticated Full-Read SSRF in Grafana SSRF Open redirect NA Justin Gardner (@Rhynorater) Bug Bounty2020-08-012023-06-13
3257Refocusing in bug hunting, Bonus: An interestingly simple to test CSRF bypass CSRF NA Vuk Ivanovic Bug Bounty2020-08-012023-06-13
3256CVE-2020–9854: "Unauthd" MacOS Local Privilege Escalation SIP bypass Apple (macOS) Ilias Morad (@A2nkF_) Bug Bounty2020-08-012023-06-13
3255Multi-factor Auth Bypass with Password Reset Function MFA bypass Password reset Account takeover NA Vaibhav Joshi (@vj0shii) Bug Bounty2020-08-022023-06-13
3254Banning users Race condition Race condition NA Saddam Hussain (@wisdomfreak1) Bug Bounty2020-08-022023-06-13
3253Look at what i found in Comodo Stored XSS Reflected XSS Comodo Maor Dayan (@mord1234) Bug Bounty2020-08-032023-06-13
3252Account takeover in cups.mail.ru Logic flaw Password reset Account takeover Mail.ru kminthein / weev3 (@kyawminthein99) Bug Bounty2020-08-032023-06-13
3251Vulnerability in new TouchID feature put iCloud accounts at risk of being breached OAuth Account takeover Apple Thijs Alkemade (@xnyhps) Bug Bounty2020-08-032023-06-13
3250Amazon AWS Bastion - Logger Bypass Logging bypass Local Privilege Escalation AWS Denis Andzakovic Bug Bounty2020-08-032023-06-13
3249How I was able to do Mass Account Takeover[Bug Bounty] Account takeover Password reset NA Not Rickyy (@RickyyNot) Bug Bounty2020-08-052023-06-13
3248I want all these features Logic flaw Payment tampering NA Mohamed Ayad Bug Bounty2020-08-052023-06-13
3247CSRF PoC mistake that broke crucial functions for the end user/victim Logic flaw NA Vuk Ivanovic Bug Bounty2020-08-052023-06-13
3246The Case of the Missing Cache Keys Web cache poisoning NA Aaron Costello (@ConspiracyProof) Bug Bounty2020-08-052023-06-13
3245Apache Example Servlet leads to $$$$ Clickjacking NA Debangshu Kundu (@debangshu_kundu) Bug Bounty2020-08-062023-06-13
3244Stored XSS on Slack, Bug Bounty Stored XSS Slack Tommysuriel Bug Bounty2020-08-062023-06-13
3243Blind SQL Injection at fasteditor.hema.com SQL injection Hema Jonathan Bouman (@JonathanBouman) Bug Bounty2020-08-062023-06-13
3242Reflected XSS at fotoservice.hema.nl Reflected XSS Open redirect Hema Jonathan Bouman (@JonathanBouman) Bug Bounty2020-08-062023-06-13
3241Smear phishing: a new Android vulnerability Phishing Android Google Jim Fisher (@MrJamesFisher) Bug Bounty2020-08-062023-06-13
3240Exploiting JWT - Lack of Signature Verification Account takeover NA Aditya Dixit (@zombie007o) Bug Bounty2020-08-062023-06-13
3239The feature works as intended, but what’s in the source? Information disclosure NA Zseano (@zseano) Bug Bounty2020-08-082023-06-13
3238Reflected XSS in Facebook’s mirror websites Reflected XSS Meta / Facebook Sudhanshu Rajbhar (@sudhanshur705) Bug Bounty2020-08-082023-06-13
3237Bug Hunting with Param Miner: Cache poisoning with XSS, a peculiar case XSS Web cache poisoning NA Vuk Ivanovic Bug Bounty2020-08-082023-06-13
3236Bypassing Google Maps API Key Restrictions Logic flaw Google Aditya Dixit (@zombie007o) Bug Bounty2020-08-082023-06-13
3235Hacking Zoom: Uncovering Tales of Security Vulnerabilities in Zoom Information disclosure RCE Memory leak Zoom Mazin Ahmed (@mazen160) Bug Bounty2020-08-082023-06-13
3234Bypassing 403 Authentication bypass NA Michael Hyndman (@michaelhyndman) Bug Bounty2020-08-092023-06-13