writeups.xyz
/
Sayaan Alam (@Ehsayaan)
Title
Vulnerabilities
Programs
Authors
Mail Server Misconfiguration leads to sending a fax from anyone’s account on HelloFax (Dropbox BBP) for a bounty of $4,913
Email Spoofing
Dropbox
Sayaan Alam (@Ehsayaan)
SSRF (Server Side Request Forgery) worth $4,913 | My Highest Bounty Ever !
SSRF
Dropbox
Sayaan Alam (@Ehsayaan)
Accidental IDOR that Deleted Admin Account.
IDOR
Undisclosed
Sayaan Alam (@Ehsayaan)
Page 1 of 1