Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
1603Adventures Into The MeowCorp Bug Bounty Program Information disclosure Weak credentials SSRF .git folder disclosure RCE NA Nirmal Thapa (@tnirmalz) Bug Bounty2022-04-212023-06-13
1593Encrypting our way to SSRF in VMWare Workspace One UEM (CVE-2021-22054) SSRF VMware Keiran Sampson (@hpy_downunder) Bug Bounty2022-04-272023-06-13
1589Exploitation of an SSRF vulnerability against EC2 IMDSv2 SSRF NA Yassine Aboukir (@Yassineaboukir) Bug Bounty2022-04-282023-06-13
1549Stealing Google Drive OAuth tokens from Dropbox CSRF SSRF Account takeover Dropbox Sivanesh Ashok (@sivaneshashok) Bug Bounty2022-05-172023-06-13
1517DNN CMS Server-Side Request Forgery (CVE-2021-40186) SSRF Security code review DNN (DotNetNuke) Appcheck NG Bug Bounty2022-05-262023-06-13
1506From open redirect to RCE in one week Open redirect SSRF Insecure deserialization LFI RCE Mail.ru byq (@ByQwert) Bug Bounty2022-05-312023-06-13
1497Another vision for SSRF SSRF NA phor3nsic (@phor3nsic_br) Bug Bounty2022-06-062023-06-13
1486Chaining vulnerabilities to criticality in Progress WhatsUp Gold SSRF Local File Disclosure Information disclosure Progress (WhatsUp Gold) Shubham Shah (@infosec_au) Bug Bounty2022-06-092023-06-13
1480From blind SSRF to localhost dirbusting and asset enumeration SSRF NA Jovan Šikanja (@joshibeast) Bug Bounty2022-06-112023-06-13
1476Finding vulnerabilities in curl 7.83.0 without reading a single-line of C code SSRF Information disclosure HSTS bypass Internet Bug Bounty (curl) Haxatron (@Haxatron1) Bug Bounty2022-06-122023-06-13
1451Hacking a NFT Platform SSRF NA Muhammad Abdullah Bug Bounty2022-06-172023-06-13
1435Pwn2Own 2021 Microsoft Exchange Exploit Chain SSRF RCE Microsoft Rskvp93 (@rskvp93) Bug Bounty2022-06-232023-06-13
1434Miracle - One Vulnerability To Rule Them All Insecure deserialization SSRF RCE Oracle Nguyễn Tiến Giang (@testanull) Bug Bounty2022-06-232023-06-13
1428Abusing functionality to exploit a super SSRF in Jira Server (CVE-2022-26135) SSRF Atlassian Shubham Shah (@infosec_au) Bug Bounty2022-06-262023-06-13
1411CVE-2022-28219: Unauthenticated XXE to RCE and Domain Compromise in ManageEngine ADAudit Plus XXE SSRF RCE Zoho Naveen Sunkavally Bug Bounty2022-06-292023-06-13
1378Write Up 1: Hellosign Integration [Full Read SSRF] SSRF NA Soufiane Habti (@wld_basha) Bug Bounty2022-07-122023-06-13
1280Came looking for SSRF and found XSS XSS WAF bypass NA Ibrahim Radi (@ibraradi9) Bug Bounty2022-08-042023-06-13
1192SSRF & Google HOF(Hall of Fame) SSRF Google Aman Pareek (@aman_notsogreat) Bug Bounty2022-08-222023-06-13
1168SSRF leads to access AWS metadata. SSRF NA Akash Patil (@skypatil98) Bug Bounty2022-08-272023-06-13
1135How I found my first SSRF to RCE! IDOR SSRF RCE NA Md. Asif Hossain (@0x0asif) Bug Bounty2022-09-042023-06-13
1126Bug Bounty { How I found an SSRF ( Reconnaissance ) } SSRF NA S Rahul (@7srambo) Bug Bounty2022-09-062023-06-13
1123WordPress Core - Unauthenticated Blind SSRF SSRF WordPress Simon Scannell (@scannell_simon) Bug Bounty2022-09-062023-06-13
1122Exploiting Out-of-Band XXE in the Wild XXE SSRF NA Mahmoud Youssef (@0xmahmoudjo0) Bug Bounty2022-09-062023-06-13
1094SSRF(g/vrp) for 5000$ SSRF NA lalka (@0x01alka) Bug Bounty2022-09-122023-06-13
1070SSRF Attack Leading To AWS Metadata SSRF CERT-EU ParagBagul Bug Bounty2022-09-182023-06-13