BugSearch is an information portal focused on applications security, web oriented and not. We offer our services to disclose our registered users on security alerts found on the net, in order to warn them as soon as possible on bugs, system flaws, exploits and threats afflicting applications and possible patches.

New Feature: Post New Exploit

Register now to start receiving our security alerts of your favourite applications or try our new Android App which will keep you updated everywhere you are!


Last Advisories
Zen Cart 1.3.8 Remote SQL Execution Exploit23-06-2009
Linux/x86 - setuid(0) + execve(/bin/sh,0) Shellcode (25 bytes)23-06-2009
Linux/x86 - setuid(0) + setgid(0) + execve(/bin/sh,)) Shellcode (25 bytes)23-06-2009
RS-CMS 2.1 (key) Remote SQL Injection Vulnerability22-06-2009
MyBB <= 1.4.6 Remote Code Execution Exploit22-06-2009
Bopup Communications Server 3.2.26.5460 Remote SYSTEM Exploit22-06-2009
Campsite 3.3.0 RC1 Multiple Remote File Inclusion Vulnerabilities22-06-2009
Gravy Media Photo Host 1.0.8 Local File Disclosure Vulnerability22-06-2009
Kasseler CMS (FD-XSS) Multiple Remote Vulnerabilities22-06-2009
Sourcebans <= 1.4.2 Arbitrary Change Admin Email Vulnerability22-06-2009
Joomla Component com_tickets <= 2.1 (id) SQL Injection Vuln22-06-2009
Elgg (XSS-CSRF-Change Password) Multiple Remote Vulnerabilities22-06-2009
AWScripts Gallery Search Engine 1.x Insecure Cookie Vulnerability22-06-2009
phpDatingClub 3.7 Remote SQL-XSS Injection Vulnerabilities22-06-2009
Multiple HTTP Server Low Bandwidth Denial of Service #222-06-2009
pmaPWN! - phpMyAdmin Code Injection RCE Scanner & Exploit22-06-2009
MIDAS 1.43 (Auth Bypass) Insecure Cookie Handling Vulnerability22-06-2009
pc4 Uploader <= 10.0 Remote File Disclosure Vulnerability22-06-2009
Edraw PDF Viewer Component < 3.2.0.126 ActiveX Insecure Method Vuln18-06-2009
DESlock+ 4.0.2 dlpcrypt.sys Local Kernel ring0 Code Execution Exploit18-06-2009
CMS Buzz (XSS-PC-HI) Multiple Remote Vulnerabilities18-06-2009
Linux/x86 - exit(0) / exit(1) Shellcode (3/4 bytes)18-06-2009
phportal 1.0 Insecure Cookie Handling Vulnerability17-06-2009
compface <= 1.5.2 (XBM File) Local Buffer Overflow PoC17-06-2009
FretsWeb 1.2 Multiple Local File Inclusion Vulnerabilities17-06-2009
FretsWeb 1.2 (name) Remote Blind SQL Injection Exploit17-06-2009
TekBase All-in-One 3.1 Multiple SQL Injection Vulnerabilities17-06-2009
fuzzylime cms <= 3.03a Local Inclusion - Arbitrary File Corruption PoC17-06-2009
Multiple HTTP Server Low Bandwidth Denial of Service (slowloris.pl)17-06-2009
phpFK 7.03 (page_bottom.php) Local File Inclusion Vulnerability17-06-2009