Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
2700Cross Site Port Attack - A Stranger’s Call XSPA NA Jerry Shah (@Jerry) Bug Bounty2021-03-212023-06-13
2699OTP brute-force via rate limit bypass Bruteforce Lack of rate limiting OTP bypass NA Bilal Muqeet (@blmqt) Bug Bounty2021-03-212023-06-13
2698Finding My First Critical Vulnerability Information disclosure NA Thexssrat (@theXSSrat) Bug Bounty2021-03-212023-06-13
2697How I made it to Google HOF? IDOR Google Sudhanshu Rajbhar (@sudhanshur705) Bug Bounty2021-03-212023-06-13
2696Finding and exploiting race condition vulnerability on facebook server Race condition Meta / Facebook Dewanand Vishal (@dewcode91) Bug Bounty2021-03-242023-06-13
2695Bypass rate limit to enumeration users through Google Drive Rate limiting bypass Google Abdullah Mohamed (@3bodymo_) Bug Bounty2021-03-242023-06-13
2694Multiple Authorization bypass issues in Google%27s Richmedia Studio Authorization flaw Google Zohar Shachar Bug Bounty2021-03-242023-06-13
2693How I leveraged XSS to make Privilege Escalation to be Super Admin! XSS Privilege escalation NA Asem Eleraky (@melotover) Bug Bounty2021-03-252023-06-13
2692PoC: The easiest 125 Euro’s I Ever made Logic flaw NA Thexssrat (@theXSSrat) Bug Bounty2021-03-252023-06-13
2691Encrypted Payload -> Decrypted Execution ($600) : Stored XSS Stored XSS NA Shrirang Diwakar Bug Bounty2021-03-252023-06-13
2690How I was able to see likes and dislikes count even though is hidden by victim | YouTube #2 Broken Access Control IDOR Google R ando (@Rando02355205) Bug Bounty2021-03-262023-06-13
2689Increasing impact of Information Disclosure — Full Account Takeover ! Information disclosure Password reset NA Abhisek R (@abh1sek_r) Bug Bounty2021-03-262023-06-13
2688How to bypass CloudFlare bot protection ? Logic flaw Cloudflare jychp (@jychp_fr) Bug Bounty2021-03-272023-06-13
2687How I was able to see likes and dislikes count even though is hidden by victim | YouTube #1 Broken Access Control IDOR Google R ando (@Rando02355205) Bug Bounty2021-03-282023-06-13
2686How I made to Paypal Bug Bounty $750 Open redirect Paypal Pethuraj (@Pethuraj) Bug Bounty2021-03-282023-06-13
2685PHP fopen() function to local file inclusion LFI NA أنس روبي (@xhzeem) Bug Bounty2021-03-282023-06-13
2684CSRF to Full Account Takeover CSRF Account takeover NA Ashraf Harb (@ashrafharb97) Bug Bounty2021-03-292023-06-13
2683A weird XSS Reflected XSS NA gato the wizard Bug Bounty2021-03-302023-06-13
2682I felt like there were no more bugs left after winning € 2000 … But an email worth €750 changed my mind Broken Access Control IDOR NA Thexssrat (@theXSSrat) Bug Bounty2021-03-312023-06-13
2681Missing CORS leads to Complete Account Takeover Missing CORS CSRF Account takeover NA Niraj Modi (@nirajmodi51) Bug Bounty2021-03-302023-06-13
2680My first Bug report at Facebook 2021 Logic flaw Authorization flaw Meta / Facebook Kent Jarold Abulag (@wkemenhehehegsg) Bug Bounty2021-03-312023-06-13
2678GKE Autopilot Node Compromise via Race Condition Container escape Google Anthony Weems Bug Bounty2021-04-012023-06-13
2677Zero click vulnerability in Apple’s macOS Mail Account takeover Information disclosure RCE Apple Mikko Kenttälä (@Turmio_) Bug Bounty2021-04-012023-06-13
2674Who Contains the Containers? Local Privilege Escalation Microsoft James Forshaw (@tiraniddo) Bug Bounty2021-04-012023-06-13
2673Play a game, get Subscribed to my channel - YouTube Clickjacking Bug | #GoogleVRP Clickjacking Google Sriram Kesavan (@sriramoffcl) Bug Bounty2021-04-022023-06-13