Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
3104Weak Password Setting function on practo.com Authorization flaw Practo dark-haxor Bug Bounty2020-10-092023-06-13
3103JS is l0ve ❤️. Information disclosure API key leakage NA Shivam Kamboj Dattana (@sechunt3r) Bug Bounty2020-10-092023-06-13
3102Leveraging XSS to Read Internal Files XSS LFI NA Aditya Dixit (@zombie007o) Bug Bounty2020-10-092023-06-13
3101Unauthorized access to all the user’s account. Account takeover Authentication bypass JWT NA Rahul Naidu Bug Bounty2020-10-122023-06-13
3100Guest Blog Post: Rollback Attack Local Privilege Escalation Mozilla Xiaoyin Liu (@general_nfs) Bug Bounty2020-10-122023-06-13
3099Disclose Emails, phone numbers, more For Facebook users who tried to add funds to their account Information disclosure Meta / Facebook Mustafa Ahmed (@mustafa0x2021) Bug Bounty2020-10-122023-06-13
3098How I find my first P1 level Bug. $$$ XSS NA Harsh Bug Bounty2020-10-132023-06-13
3097Blind SSRF - The Hide & Seek Game Blind SSRF NA Shrey Shah (@ShreySh43332033) Bug Bounty2020-10-132023-06-13
3096I had fun with this XSS XSS NA yappare (@yappare) Bug Bounty2020-10-132023-06-13
3095MS Enterprise app management service RCE. CVE-2022-35841 RCE Local Privilege Escalation Windows Microsoft Ceri Coburn (@_ethicalchaos_) Bug Bounty2020-10-132023-06-13
3094Weaponizing XSS For Fun & Profit XSS CSRF NA Saad Ahmed (@XSaadAhmedX) Bug Bounty2020-10-142023-06-13
3093Discord Desktop app RCE RCE Discord Masato Kinugawa (@kinugawamasato) Bug Bounty2020-10-172023-06-13
3092GitHub - RCE via git option injection (almost) - $20,000 Bounty RCE GitHub William Bowling / vakzz (@wcbowling) Bug Bounty2020-10-182023-06-13
3091GitHub Gist - Account takeover via open redirect - $10,000 Bounty Open redirect Account takeover GitHub William Bowling / vakzz (@wcbowling) Bug Bounty2020-10-192023-06-13
3090Multiple Address Bar Spoofing Vulnerabilities In Mobile Browsers Authentication bypass JWT Android NHS COVID-19 App James Sanderson (@zofrex) Bug Bounty2020-10-202023-06-13
3089Multiple Address Bar Spoofing Vulnerabilities In Mobile Browsers Address Bar Spoofing Yandex Apple Opera Rafay Baloch (@rafaybaloch) Bug Bounty2020-10-202023-06-13
3088Back to 2019: Disclosure Employers PII and Credentials Information disclosure NA Wh11teW0lf (@wh11tew0lf) Bug Bounty2020-10-202023-06-13
3087GitHub Pages - Multiple RCEs via insecure Kramdown configuration - $25,000 Bounty RCE Path traversal GitHub William Bowling / vakzz (@wcbowling) Bug Bounty2020-10-202023-06-13
3084IBM Datapower Exploit CVE-2020-5014 SSRF HTTP Request Smuggling IBM Thomas Cope Bug Bounty2020-10-212023-06-13
3083300$ P3 Easy Bug in 30 Seconds Missing authentication Broken Access Control NA Omar Hamdy (@seaman00o) Bug Bounty2020-10-222023-06-13
3082Samsung S20 - RCE via Samsung Galaxy Store App RCE Samsung F-Secure Bug Bounty2020-10-232023-06-13
3081Accidental Observation to Critical IDOR IDOR NA Harsh Bothra (@harshbothra_) Bug Bounty2020-10-242023-06-13
3080My first bug on Google IDOR Google Manas Harsh (@ManasH4rsh) Bug Bounty2020-10-252023-06-13
3078Link Previews: How a Simple Feature Can Have Privacy and Security Risks Information disclosure Discord Meta / Facebook Google LINE LinkedIn Slack Twitter Zoom Talal Haj Bakry (@parasarora06) Bug Bounty2020-10-252023-06-13
3077TikTok fixes privacy issue discovered by Check Point Research Information disclosure TikTok Eran Vaknin Bug Bounty2020-10-262023-06-13