Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
3076How i got 250$ in 5 munites using my phone HTML injection Basecamp Abdelkader Mouaz (@hamzadzworm) Bug Bounty2020-10-262023-06-13
3075The YouTube bug that allowed unlisted uploads to any channel IDOR Information disclosure Google Ryan Kovatch Bug Bounty2020-10-272023-06-13
3074Automating xss identification with Dalfox & Paramspider Reflected XSS NA Paras Arora (@parasarora06) Bug Bounty2020-10-272023-06-13
3073Error-Based SQL Injection on a WordPress website and extract more than 150k user details SQL injection NA Ynoof Alassiri Bug Bounty2020-10-272023-06-13
3072Story of an interesting bug. Lack of rate limiting DoS NA Vedant Tekale (@_justYnot) Bug Bounty2020-10-282023-06-13
3071Weblogic RCE by only one GET request — CVE-2020–14882 Analysis RCE Authentication bypass Security code review Oracle (WebLogic) Nguyễn Tiến Giang (@testanull) Bug Bounty2020-10-282023-06-13
3070Manual broken link monitoring Broken link hijacking NA GrumpinouT (@RVerwilghen) Bug Bounty2020-10-292023-06-13
3069Rate Limit Bypassing Allowing Identity Spoofing Rate limiting bypass OTP bypass NA Mohamed Talaat (@T4144t) Bug Bounty2020-10-292023-06-13
3068Wormable remote code execution in Alien Swarm RCE Valve mev Bug Bounty2020-10-302023-06-13
3067Ability To Backdoor Facebook For Android Insecure deeplink Android Meta / Facebook Ashley King (@AshleyKingUK) Bug Bounty2020-10-302023-06-13
3066Hinge Hackerone Writeup Broken Access Control Hinge Tyle Butler (@tbutler0x90) Bug Bounty2020-10-312023-06-13
3065Beyond the wall: command injection still alive. OS command injection NA Ahmed Constant (@a_Constant_) Bug Bounty2020-10-312023-06-13
3064Abusing %27Report Abuse%27 Logic flaw Authorization flaw NA Aseem Shrey (@AseemShrey) Bug Bounty2020-10-312023-06-13
3063How i got 7000$ in Bug-Bounty for my Critical Finding. Information disclosure NA Kishan Kumar / Noobie BoY (@hst_kishan) Bug Bounty2020-10-312023-06-13
3062An often overlooked Oauth misconfiguration. OAuth NA VipItHunter (@VipItHunter1) Bug Bounty2020-11-012023-06-13
3061Leaked .git folder leads to RCE .git folder disclosure RCE NA James Clee (@jtcsec) Bug Bounty2020-11-012023-06-13
3060Subdomain Takeover in Azure: making a PoC Subdomain takeover NA Diego Bernal Adelantado (@secfaults) Bug Bounty2020-11-012023-06-13
3059CVE-2020-13294 Authentication flaw OpenID Connect OAuth GitLab Lauritz Holtmann (@_lauritz_) Bug Bounty2020-11-012023-06-13
3058Reveal the page admin that uploaded a video on the page in comment section Information disclosure Logic flaw Meta / Facebook Lokesh Kumar (@lokeshdlk77) Bug Bounty2020-11-022023-06-13
3057Forcing for a bounty$$ Authorization flaw NA Rafi Ahamed (Leonidas D. Ace) Bug Bounty2020-11-032023-06-13
3056From a 500 error to Django admin takeover Authorization bypass Account takeover NA Shashank (@cyberboyIndia) Bug Bounty2020-11-032023-06-13
3055Delete Any Photos In Facebook Authorization flaw Logic flaw Meta / Facebook Lokesh Kumar (@lokeshdlk77) Bug Bounty2020-11-042023-06-13
3054How I found a Tor vulnerability in Brave Browser, reported it, watched it get patched, got a CVE (CVE-2020-8276) and a small bounty, all in one working day Information disclosure Brave Software sickcodes (@sickcodes) Bug Bounty2020-11-052023-06-13
30531000$ for Open redirect via unknown technique [BugBounty writeup] Open redirect GitLab ruvlol Bug Bounty2020-11-052023-06-13
3052Story of a Pre-Account Takeover Account takeover OAuth NA Kushal Dhakal (@dhakal0kushal) Bug Bounty2020-11-062023-06-13