Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
558Bypassing Cloudflare WAF: XSS via SQL Injection Reflected XSS SQL injection WAF bypass NA Uku Sõrmus Bug Bounty2023-01-212023-06-13
544MyBB <= 1.8.31: Remote Code Execution Chain RCE SQL injection Stored XSS MyBB Aleksey Solovev Bug Bounty2023-01-252023-06-13
456Blind Time-based SQL injection vulnerability in an Indian government website SQL injection NCIIPC Kartikhunt3r Bug Bounty2023-02-132023-06-13
454SQL Injection: Utilizing XML Functions in Oracle and PostgreSQL to bypass WAFs SQL injection WAF bypass NA Mahmoud Gamal (@Zombiehelp54) Bug Bounty2023-02-132023-06-13
451Securing Open-Source Solutions: A Study of osTicket Vulnerabilities Stored XSS Reflected XSS SQL injection Session fixation osTicket Miguel Correia Bug Bounty2023-02-142023-06-13
414Vulnerability write-up - "Dangerous assumptions" Prototype pollution SQL injection Security code review DIVD Thomas Rinsma (@thomasrinsma) Bug Bounty2023-02-222023-06-13
331How I got Owned A Multi-Billion Dollar Retailer’s MySQL Databases Using Simple SQL Injection SQL injection NA nav1n (@nav1n0x) Bug Bounty2023-03-082023-06-13
323I Earned $3500 and 40 Points for A GraphQL Blind SQL Injection Vulnerability. SQL injection GraphQL NA nav1n (@nav1n0x) Bug Bounty2023-03-102023-06-13
312Dolibarr : unauthenticated contacts database theft SQL injection Security code review Dolibarr Vladimir Bug Bounty2023-03-132023-06-13
298IP spoofing and SQL injection in Textcube SQL injection IP spoofing HTTP header attack Security code review Textcube Sjoerd Langkemper Bug Bounty2023-03-152023-06-13
145How I Chained an Information Disclosure Bug with SQL Injection SQL injection .git folder disclosure NA Mba-oji Chiagoziem (@g0ziem) Bug Bounty2023-04-302023-06-13
129Automating SQL Injection On Encrypted Request SQL injection Client-side encryption bypass NA Janirudransh Bug Bounty2023-05-032023-06-13
94Pimcore: One click, two security vulnerabilities Path traversal SQL injection Arbitrary file write RCE Security code review Pimcore Yaniv Nizry (@YNizry) Bug Bounty2023-05-152023-06-13
69Exploiting SQL Error SQLSTATE[42000] To Own MariaDB of A Large Online Media Leader SQL injection NA nav1n (@nav1n0x) Bug Bounty2023-05-202023-06-13
66I helped a top Indian health benefits management platform from major PII leak by hacking their SQL Servers, AWS instance, DCs etc. SQL injection NA nav1n (@nav1n0x) Bug Bounty2023-05-222023-06-13
51Utilizing Historical URLs of an Organization to successfully execute SQL queries — Blind SQLi Blind SQL injection NA Aayush Vishnoi (@AayushVishnoi10) Bug Bounty2023-05-262023-06-13
40Kramer VIA GO² – Multiple issues RCE SQL injection Arbitrary file upload Arbitrary file read Kramer Jim Rush (@JimSRush) Bug Bounty2023-05-312023-06-13
35Bypassing An Industry-Leading WAF and Exploiting SQLi SQL injection WAF bypass NA Adeeb Shah Bug Bounty2023-06-012023-06-13