Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
821CVE-2022-41622 and CVE-2022-41800 (FIXED): F5 BIG-IP and iControl REST Vulnerabilities and Exposures CSRF RCE RPM Spec Injection F5 Ron Bowes (@iagox86) Bug Bounty2022-11-162023-06-13
820The Story Of A Strange / Stored IDOR. IDOR NA Hassan Farooq Bug Bounty2022-11-162023-06-13
819Account Takeover Worth of $2500 Account takeover IDOR NA Jefferson Gonzales (@gonzxph) Bug Bounty2022-11-162023-06-13
818Information Exposure — My Fourth Finding on Hackerone! Directory listing Information disclosure NA mehedishakeel (@mehedishakeel) Bug Bounty2022-11-172023-06-13
817Got Another XSS using Double Encoding XSS NA ag3n7 Bug Bounty2022-11-172023-06-13
816Security concerns with the e-Tugra certificate authority Default credentials Exposed registration page e-Tugra Ian Carroll (@iangcarroll) Bug Bounty2022-11-172023-06-13
814[RE:SCRUTINY] Delay Then Migrate Your Meterpreter Internal pentest Lateral movement NA RE:HACK (@rehackxyz) Bug Bounty2022-11-172023-06-13
813Bypassing XSS filters using Double Encoding XSS WAF bypass NA ag3n7 (@ag3n7apk) Bug Bounty2022-11-182023-06-13
812How i found 8 vulnerabilities in 24h? Logic flaw NA Mohamed Anani (@0xM5awy) Bug Bounty2022-11-182023-06-13
811$250 for Email account enumeration using “NameToMail” tool Username enumeration NA snoopy (@snoopy101101) Bug Bounty2022-11-182023-06-13
808Remote Command Execution in a Bank Server RCE Arbitrary file read Unrestricted file upload NA Bipin Jitiya (@win3zz) Bug Bounty2022-11-182023-06-13
807From Static domain to Account Takeover Account takeover Logic flaw NA Demon (@R29k_) Bug Bounty2022-11-182023-06-13
806Remediation Archeology — Finding and Decoding an Ancient XSS XSS NA Bend Theory (@bendtheory) Bug Bounty2022-11-182023-06-13
805Russian roulette XSS Blind XSS NA Splintersec (@splint3rsec) Bug Bounty2022-11-192023-06-13
803How i found 29 stored XSS in modern framework Stored XSS NA Dewanand Vishal (@dewcode91) Bug Bounty2022-11-202023-06-13
801Hacking Smartwatches for Spear Phishing IoT Phishing Android NA Cybervelia (@cybervelia) Bug Bounty2022-11-202023-06-13
800My Account Takeover Writeup: $5000 Lack of rate limiting Bruteforce NA MRD7 (@_mrd7_) Bug Bounty2022-11-212023-06-13
799Fastly Subdomain Takeover $2000 Subdomain takeover NA ValluvarSploit (@ValluvarSploit) Bug Bounty2022-11-212023-06-13
795SSD Advisory – NETGEAR R7800 AFPD PreAuth Memory corruption Buffer Overflow Netgear - Bug Bounty2022-11-222023-06-13
794Interesting Stored XSS via meta data Stored XSS NA Veshraj Ghimire (@GhimireVeshraj) Bug Bounty2022-11-222023-06-13
793SSRF via DNS Rebinding (CVE-2022–4096) SSRF DNS rebinding TOCTOU Appsmith Basavaraj Banakar (@basu_banakar) Bug Bounty2022-11-222023-06-13
792CVE-2022-41924 - RCE in Tailscale, DNS Rebinding, and You RCE DNS rebinding Information disclosure Tailscale Jamie McClymont (@JJJollyjim) Bug Bounty2022-11-222023-06-13
791CVE-2021-40662 Chamilo LMS 1.11.14 RCE Stored XSS CSRF RCE Chamilo LMS Febin Bug Bounty2021-11-232023-06-13
789CVE-2022-32898: ANE_ProgramCreate() multiple kernel memory corruption Memory corruption iOS Kernel hacking Apple simo (@_simo36) Bug Bounty2022-11-232023-06-13
788How I get +10 SQLi and +30 XSS via Automation Tool SQL injection XSS NA Mahmoud Attia (@0xElkot) Bug Bounty2022-11-232023-06-13