writeups.xyz writeups.xyz / Omar Hashem (@OmarHashem666)

Title Vulnerabilities Programs Authors
HubSpot Full Account Takeover in Bug Bounty
CVE-2022-38627: A journey through SQLite Injection to compromise the whole enterprise building
CVE-2022-42710: A journey through XXE to Stored-XSS
Full Company Building Takeover
Orange Arbitrary Command Execution
How I Found Multiple SQL Injections in 5 Minutes in Bug Bounty
How I abused the file upload function to get a high severity vulnerability in Bug Bounty
How I found 3 RXSS on the Lululemon bug bounty program
How to prevent more than 200 million users from using Google services