BugSearch is an information portal focused on applications security, web oriented and not. We offer our services to disclose our registered users on security alerts found on the net, in order to warn them as soon as possible on bugs, system flaws, exploits and threats afflicting applications and possible patches.

New Feature: Post New Exploit

Register now to start receiving our security alerts of your favourite applications or try our new Android App which will keep you updated everywhere you are!


Last Advisories
Gravity Board X 2.0b SQL Injection - Post Auth Code Execution03-04-2009
AdaptBB 1.0 (topic_id) SQL Injection - Credentials Disclosure Exploit03-04-2009
Family Connections <= 1.8.2 Remote Shell Upload Exploit03-04-2009
form2list (page.php id) Remote SQL Injection Vulnerability03-04-2009
glFusion <= 1.1.2 COM_applyFilter()-cookies Blind SQL Injection Exploit03-04-2009
UltraISO <= 9.3.3.2685 CCD-IMG Universal Buffer Overflow Exploit03-04-2009
IBM DB2 < 9.5 pack 3a Malicious Connect Denial of Service Exploit03-04-2009
IBM DB2 < 9.5 pack 3a Malicious Data Stream Denial of Service Exploit03-04-2009
ActiveKB Knowledgebase (loadpanel.php Panel) Local File Inclusion Vuln03-04-2009
XBMC 8.10 (Get Request) Remote Buffer Overflow Exploit (win)01-04-2009
XBMC 8.10 (takescreenshot) Remote Buffer Overflow Exploit01-04-2009
XBMC 8.10 (get tag from file name) Remote Buffer Overflow Exploit01-04-2009
XBMC 8.10 (GET Requests) Multiple Remote Buffer Overflow PoC01-04-2009
Oracle WebLogic IIS connector JSESSIONID Remote Overflow Exploit01-04-2009
Koschtit Image Gallery 1.82 Multiple Local File Inclusion Vulnerabilities01-04-2009
DeepBurner 1.9.0.228 Stack Buffer Overflow (SEH) PoC01-04-2009
MyioSoft Ajax Portal 3.0 (page) SQL Injection Vulnerability01-04-2009
TinyPHPForum 3.61 File Disclosure - Code Execution Vulnerabilities01-04-2009
PrecisionID Datamatrix ActiveX Arbitrary File Overwrite Vuln31-03-2009
vsp stats processor 0.45 (gamestat.php gameID) SQL Injection Vuln31-03-2009
JobHut 1.2 Remote Password Change-Delete-Activate User Vulnerability31-03-2009
PHPRecipeBook 2.39 (course_id) Remote SQL Injection Vulnerability31-03-2009
Podcast Generator <= 1.1 Remote Code Execution Exploit31-03-2009
Safari 3.2.2-4b (nested elements) XML Parsing Remote Crash Exploit31-03-2009
VirtueMart <= 1.1.2 Remote SQL Injection Exploit (meta)31-03-2009
VirtueMart <= 1.1.2 Multiple Remote Vulnerabilities31-03-2009
webEdition <= 6.0.0.4 (WE_LANGUAGE) Local File Inclusion Vulnerability31-03-2009
Community CMS 0.5 Multiple SQL Injection Vulnerabilities31-03-2009
Sun Calendar Express Web Server (DoS-XSS) Multiple Remote Vulns31-03-2009
Trend Micro Internet Security Pro 2009 Priviliege Escalation PoC30-03-2009