writeups.xyz writeups.xyz / Ahmed Hassan

Title Vulnerabilities Programs Authors
UN United Nations Host Header Injection leads to any Full Account Takeover (ATO)
stored XSS and stored HTML Injection in United Nations Website
IDOR (Insecure Direct Object Reference) leads to listing all valid Users and edit their Profiles
XSS | HTML Injection and File Upload Bypass in HUAWEI Subdomain