Back to directory
WRITEUP #6332

One company: 262 bugs, 100% acceptance, 2.57 priority, millions of user details saved.

XSSStored XSSBlind XSSCSRFAccount takeoverIDOR
by@zseano(Zseano)
Program
-
Published
Feb 25, 2017
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://medium.com/@sean.roesner/one-company-262-bugs-100-acceptance-2-57-priority-300million-user-details-saved-dd88ecb10f6f
RELATED WRITEUPS
Self-XSS to ATO via Site Features
XSSSelf-XSS
Basic HTTP Authentication Risk: Uncovering pyspider Vulnerabilities
XSSReflected XSS
CSRF Bypass Using Domain Confusion Leads To ATO
CSRFAccount takeover
Stored XSS in LibreOffice
XSSStored XSS
How I got my first $13500 bounty through Parameter Polluting (HPP)
IDORXSS

Built with ❤️ by Shubham Rawat