writeups.xyz writeups.xyz / Jonathan Bouman (@JonathanBouman)

Title Vulnerabilities Programs Authors
Remote Code execution at ws1.aholdusa.com — Compromising logins of Ahold Delhaize USA employees for >3.5 years (or even 18 years?)
Laravel debug mode left on at Zouikwatzeggen.nl leaks admin credentials & potentially submitted reports of improper behaviour at Amsterdam University Medical Centers
Unprotected API endpoint at HAwebsso.nl leads to data leak of +15k medical doctor usernames & password hashes
Blind SQL Injection at fasteditor.hema.com
Reflected XSS at fotoservice.hema.nl
Email content spoofing at IKEA.com
Leaked Salesforce API access token at IKEA.com
Persistent XSS (unvalidated Open Graph embed) at LinkedIn.com
Persistent XSS (Unvalidated oEmbed) at Medium.com
Local file inclusion at IKEA.com
Reflected XSS at Philips.com
XXE at Bol.com
Persistent XSS at AH.nl
How I hacked Apple.com (Unrestricted File Upload)
Reflected Client XSS at Amazon.com
Unvalidated Open Redirect Bol.com