Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
3180Denial of Service in the protection service provided by Avast Security Premium. DoS Avast Silton Santos Bug Bounty2020-09-012023-06-13
3179Cloud firewall management API SNAFU put 500k SonicWall customers at risk IDOR SonicWall Vangelis Stykas (@evstykas) Bug Bounty2020-09-022023-06-13
3178CVE-2020-6519 - Chromium 83 Zero Day Full CSP Bypass Cross Platforms CSP bypass Google (Chrome & Chromium) Gal Weizman (@WeizmanGal) Bug Bounty2022-09-022023-06-13
3177My Story With XSS XSS NA Soufiane Habti (@wld_basha) Bug Bounty2020-09-032023-06-13
3176Account Takeover via IDOR IDOR Account takeover NA Roma Ramazanoff (@r0hack) Bug Bounty2020-09-042023-06-13
3175How_i_was_able_to_pawned_website_via_escilating_webcache deception to rce Web cache deception SSRF RCE NA mohit (@mohit29295572) Bug Bounty2020-09-052023-06-13
3174XSS that can pay your Bills :) Reflected XSS NA Smile Hacker (@_smile_hacker_) Bug Bounty2020-09-052023-06-13
3173Never Give Up, The Story Behind a Dupe-To-Triaged XSS OAuth Account takeover NA Alan Brian (@soyelmago) Bug Bounty2020-09-062023-06-13
3172How response Manipulation got me a little, but sweet Bounty MFA bypass NA Tommaso De Ponti (@heytdep) Bug Bounty2020-09-072023-06-13
3171My first bug in google and how i got CSRF token for victim account rather than bypass it ($1337)! CSRF Google Oday Alhalbe Bug Bounty2020-09-072023-06-13
3170From Android Static Analysis to RCE on Prod RCE Directory listing Missing authentication NA Aditya Dixit (@zombie007o) Bug Bounty2020-09-072023-06-13
3169XSS->Fix->Bypass: 10000$ bounty in Google Maps XSS Google Zohar Shachar Bug Bounty2020-09-072023-06-13
3168CVE-2020-8150 – Remote Code Execution as SYSTEM/root via Backblaze RCE Local Privilege Escalation Backblaze Jason Geffner (@JasonGeffner) Bug Bounty2020-09-092023-06-13
3167How often do we overlook vulnerabilities? Information disclosure HackerOne Baibhav Anand (@SpongeBhav) Bug Bounty2020-09-092023-06-13
3166Unintended Behaviour of domain got me P4 Logic flaw NA Takester (@dhiraj_ramteke) Bug Bounty2020-09-102023-06-13
3165Universal XSS in Android WebView (CVE-2020-6506) Universal XSS Google Microsoft Twitter Alesandro Ortiz (@AlesandroOrtizR) Bug Bounty2020-09-102023-06-13
3164How I Hacked Facebook Again! Unauthenticated RCE on MobileIron MDM RCE JNDI Injection Meta / Facebook Orange Tsai (@orange_8361) Bug Bounty2020-09-122023-06-13
3163How I hacked redbus [An online bus-ticketing application] LFI SSRF redBus Sangeetha Rajesh S (@rajesh_sangi12) Bug Bounty2020-09-122023-06-13
3162SQL Injection & Remote Code Execution - Double P1 SQL injection RCE NA Shrey Shah (@ShreySh43332033) Bug Bounty2020-09-132023-06-13
3161Business logic vulnerabilities — Low-level logic flaw Logic flaw NA Harry D Bug Bounty2020-09-132023-06-13
3160Account takeover by OTP bypass OTP bypass NA Bhavarth Kandoria Bug Bounty2020-09-132023-06-13
3159Firefox for Android: LAN Based Intent Triggering Insecure intent Android Mozilla initstring (@init_string) Bug Bounty2020-09-152023-06-13
3158How I Accidentally Got My First Bounty From Facebook Logic flaw Meta / Facebook Bishal Shrestha (@bishal0x01) Bug Bounty2020-09-152023-06-13
3157Exploiting a "Useless" Cookie-Based XSS and Making it Useful XSS NA Daniel Thatcher (@_danielthatcher) Bug Bounty2020-09-162023-06-13
3156Res-block: Extension Resources Block Attack on Chrome’s Incognito Mode Browser hacking Google Piyush Raj (@0x48piraj) Bug Bounty2020-09-162023-06-13