didsec


Rank #37 Level 5



101
unique bugs discovered
74 hours, 35 minutes and 50 seconds active hacking time

90
reports accepted
100 Accuracy

Vulnerability Types Found

Bug Submissions & total bug count


Hackevent (FirstBlood) Activity

Report Title Event ID Severity Vulnerability Type
Admin Account takeover FirstBlood v3 CRITICAL Auth issues
xss on about.html FirstBlood v3 Medium Reflective XSS
CSRF in Modify Doctor FirstBlood v3 Low Cross Site Request Forgery
Open Redirect on logout.php FirstBlood v3 Low Open Redirect
Stored xss in HackerBack sign up phone number to Account takeover FirstBlood v3 CRITICAL Stored XSS
Reflected xss on doctors.php FirstBlood v3 Medium Reflective XSS
Blind xss on FirstBloodHackers INTERNAL ADMIN PANEL FirstBlood v3 CRITICAL Stored XSS
Stored xss in doctors name FirstBlood v3 High Stored XSS
Reflected xss on edit-doctor.php FirstBlood v3 Medium Reflective XSS
Stored xss on api/ambulances.php FirstBlood v3 High Stored XSS
Stored xss in doctors tagline FirstBlood v3 High Stored XSS
Stored xss in ambulance driver name FirstBlood v3 High Stored XSS
Unauthenticated user is able to change a doctors profile FirstBlood v3 High Access control
Able to delete an ambulance from an appointment FirstBlood v3 High Access control
Stored xss in doctors photo on meet_drs.php FirstBlood v3 High Stored XSS
Stored xss in doctors bio via about.php FirstBlood v3 High Stored XSS