001
↗
002
↗
003
↗
004
↗
005
↗
006
↗
007
↗
008
↗
009
↗
010
↗
Account Takeover
A clean path straight to full account takeover.
Account Takeover via Chained IDORs
Two IDORs that looked minor alone, chained into a full takeover.
Privilege Escalation via Stored XSS
A stored payload pushed past an alert box into real privilege escalation.
From AWS S3 Bucket Misconfiguration to Sensitive Data Exposure
A misconfigured bucket that quietly exposed sensitive data.
Escalating Self-XSS to Stored XSS via Image Injection + IDOR
Turning a self-only XSS into a stored, victim-facing one.
Wayback Machine to Account Takeover
Recon through archived pages, ending in a full account takeover.
Stored XSS in Deskpro
Three published CVEs from a stored XSS in Deskpro.
SSTI to Local File Read
A template injection escalated into reading files off the host.
CSRF + Open Redirect Chained to Account Takeover
A CSRF and an open redirect chained into account takeover.
IDOR: Unauthorized Access to Support Tickets
An IDOR exposing other users' support tickets.