Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
1140How can i get SQL Injection SQL injection NA Mohamed Abdelhady Bug Bounty2022-09-022023-06-13
1139The Database Handover | A Dumb Mistake | Critical BUG Information disclosure NA Saransh Saraf (@mr23r0) Bug Bounty2022-09-022023-06-13
1137Caching the Un-cacheables - Abusing URL Parser Confusions (Web Cache Poisoning Technique) Web cache poisoning XSS DoS Glassdoor Harel (@h4r3l) Bug Bounty2022-09-022023-06-13
1136Discovery of CVE-2022-35406 Logic flaw Referer leakage PortSwigger Mr. Vrushabh (@doshi_vrushabh) Bug Bounty2022-09-032023-06-13
1135How I found my first SSRF to RCE! IDOR SSRF RCE NA Md. Asif Hossain (@0x0asif) Bug Bounty2022-09-042023-06-13
1133Simple IBM I (AS/400) Hacking Local Privilege Escalation Midrange system Menu security NA pz Bug Bounty2022-09-052023-06-13
1132SSD Advisory – Linux CONFIG_WATCH_QUEUE LPE Memory corruption Race condition Local Privilege Escalation Ubuntu Linux Kernel Organization - Bug Bounty2022-09-052023-06-13
1129IDOR “Insecure direct object references”, my first P1 in Bugbounty IDOR NA jedus0r Bug Bounty2022-09-052023-06-13
1128How to Decrypt Manage Engine PMP Passwords for Fun and Domain Admin - a Red Teaming Tale Cryptographic issues Zoho (ManageEngine) smaury (@smaury92) Bug Bounty2022-09-052023-06-13
1127CVE-2022-34715: More Microsoft Windows NFS V4 Remote Code Execution RCE Memory corruption Microsoft Quintin Crist Bug Bounty2022-09-062023-06-13
1126Bug Bounty { How I found an SSRF ( Reconnaissance ) } SSRF NA S Rahul (@7srambo) Bug Bounty2022-09-062023-06-13
1125CVE-2022-35405 Manage engines RCE (Password Manager Pro, PAM360 and Access Manager Plus) RCE Zoho Vinicius Pereira (@big0x75) Bug Bounty2022-09-082023-06-13
1123WordPress Core - Unauthenticated Blind SSRF SSRF WordPress Simon Scannell (@scannell_simon) Bug Bounty2022-09-062023-06-13
1122Exploiting Out-of-Band XXE in the Wild XXE SSRF NA Mahmoud Youssef (@0xmahmoudjo0) Bug Bounty2022-09-062023-06-13
1121How to turn security research into profit: a CL.0 case study HTTP request smuggling Desync attack NA James Kettle (@albinowax) Bug Bounty2022-09-082023-06-13
1116Zuckerpunch - Abusing Self Hosted Github Runners at Facebook CI/CD Meta / Facebook Marcus Young Bug Bounty2022-09-062023-06-13
1114Groovy Template Engine Exploitation – Notes from a real case scenario RCE NA Gianluca Baldi (@0x_nope) Bug Bounty2022-09-072023-06-13
1112Exploiting Laravel based applications with leaked APP_KEYs and Queues RCE NA Timo Müller (@mtimo44) Bug Bounty2022-09-072023-06-13
1111$900 Blind XSS Blind XSS NA ѕнín (@shinchina_) Bug Bounty2022-09-072023-06-13
1110Groovy Template Engine Exploitation – Notes from a real case scenario RCE Code injection NA Gianluca Baldi (@0x_nope) Bug Bounty2022-09-072023-06-13
1109Step-by-Step Walkthrough of CVE-2022-32792 - WebKit B3ReduceStrength Out-of-Bounds Write Memory corruption Browser hacking Out-of-bounds Write Apple Daniel Lim (@daniellimws) Bug Bounty2022-09-082023-06-13
1105QUEST KACE Desktop Authority Pre-Auth Remote Code Execution (CVE-2021-44031) RCE Path traversal Quest Tom Ellson (@tde_sec) Bug Bounty2022-09-082023-06-13
1104Fun With CORS CORS misconfiguration Token leak NA Talis Ozols Bug Bounty2022-09-082023-06-13
1096How I found 3 rare security bug in a day Session expiration issue Payment bypass Lack of rate limiting NA zer0d Bug Bounty2022-09-102023-06-13
1095Privacy Violation In Chat System Privacy issue NA Inderjeet Singh - rashahacks Bug Bounty2022-09-122023-06-13