BugSearch is an information portal focused on applications security, web oriented and not. We offer our services to disclose our registered users on security alerts found on the net, in order to warn them as soon as possible on bugs, system flaws, exploits and threats afflicting applications and possible patches.

New Feature: Post New Exploit

Register now to start receiving our security alerts of your favourite applications or try our new Android App which will keep you updated everywhere you are!


Last Advisories
DM FileManager 3.9.2 (Auth Bypass) SQL Injection Vulnerability19-05-2009
KingSoft Web Shield <= 1.1.0.62 XSS-Code Execution Vulnerability19-05-2009
Coppermine Photo Gallery <= 1.4.22 Remote Exploit19-05-2009
VidShare Pro (SQL-XSS) Multiple Remote Vulnerabilities19-05-2009
Dog Pedigree Online Database 1.0.1b Multiple SQL Injection Vulns19-05-2009
Dog Pedigree Online Database 1.0.1b Insecure Cookie Handling Vuln19-05-2009
Dog Pedigree Online Database 1.0.1b Blind SQL Injection Exploit19-05-2009
LightOpenCMS 0.1 (id) Remote SQL Injection Vulnerability18-05-2009
OpenSSL <= 0.9.8k, 1.0.0-beta2 DTLS Remote Memory Exhaustion DoS18-05-2009
Zervit Webserver 0.04 (GET Request) Remote Buffer Overflow PoC18-05-2009
Mereo 1.8.0 (Get Request) Remote Denial of Service Exploit18-05-2009
ClanWeb 1.4.2 Remote Change Password - Add Admin Exploit18-05-2009
DOURAN Portal <= 3.9.0.23 Multiple Remote Vulnerabilities18-05-2009
Dana Portal Remote Change Admin Password Exploit18-05-2009
httpdx <= 0.5b FTP Server (USER) Remote BOF Exploit (SEH)18-05-2009
httpdx <= 0.5b Multiple Remote Denial of Service Vulnerabilities18-05-2009
Coppermine Photo Gallery <= 1.4.22 Multiple Remote Vulnerabilities18-05-2009
Flyspeck CMS 6.8 Remote LFI - Change Add Admin Exploit18-05-2009
Pluck 4.6.2 (langpref) Local File Inclusion Vulnerabilities18-05-2009
Online Rental Property Script <= 5.0 (pid) SQL Injection Vulnerability18-05-2009
Pc4Uploader 9.0 Remote Blind SQL Injection Vulnerability18-05-2009
PHP Dir Submit (Auth Bypass) SQL Injection Vulnerability18-05-2009
Jieqi CMS <= 1.5 Remote Code Execution Exploit18-05-2009
MaxCMS 2.0 (inc-ajax.asp) Remote SQL Injection Vulnerability18-05-2009
DGNews 3.0 Beta (id) Remote SQL Injection Vulnerability18-05-2009
PHP Article Publisher Remote Change Admin Password Exploit18-05-2009
DMXReady Registration Manager 1.1 Database Disclosure Vulnerability15-05-2009
PHPenpals <= 1.1 (mail.php ID) Remote SQL Injection Exploit15-05-2009
my-colex 1.4.2 (AB-XSS-SQL) Multiple Remote Vulnerabilities15-05-2009
my-Gesuad 0.9.14 (AB-SQL-XSS) Multiple Remote Vulnerabilities15-05-2009