BugSearch is an information portal focused on applications security, web oriented and not. We offer our services to disclose our registered users on security alerts found on the net, in order to warn them as soon as possible on bugs, system flaws, exploits and threats afflicting applications and possible patches.

New Feature: Post New Exploit

Register now to start receiving our security alerts of your favourite applications or try our new Android App which will keep you updated everywhere you are!


Last Advisories
Joomla Component ongumatimesheet20 4b RFI Vulnerability04-11-2008
Simple Machines Forum (SMF) 1.1.6 Code Execution Exploit04-11-2008
TBmnetCMS 1.0 (index.php content) Local File Inclusion Vulnerability04-11-2008
TR News <= 2.1 (login.php) Remote Login Bypass Exploit04-11-2008
wotw <= 5.0 Local-Remote File Inclusion Vulnerability04-11-2008
Simple Machines Forum (SMF) 1.1.6 Remote Code Execution Exploit04-11-2008
nicLOR Sito includefile Local File Inclusion Vulnerabilities04-11-2008
Agavi 1.0.0 beta 5 (cmplang) Remote File Disclosure Vulnerability03-11-2008
pppBlog <= 0.3.11 (randompic.php) File Disclosure Vulnerability03-11-2008
MatPo Link 1.2b (Blind SQL Injection-XSS) Multiple Vulnerabilities03-11-2008
MatPo Link 1.2b (view.php id) Remote SQL Injection Vulnerability03-11-2008
Acc Autos 4.0 Insecure Cookie Handling Vulnerability03-11-2008
Apoll 0.7b (SQL Injection) Remote Auth Bypass Vulnerability03-11-2008
Chilkat Crypt Activex Arbitrary File Creation-Execution PoC03-11-2008
Acc Real Estate 4.0 Insecure Cookie Handling Vulnerability03-11-2008
Acc Statistics 1.1Insecure Cookie Handling Vulnerability03-11-2008
Acc PHP eMail 1.1Insecure Cookie Handling Vulnerability03-11-2008
BosDev BosClassifieds (cat_id) SQL Injection Vulnerability03-11-2008
Maran PHP Shop (admin.php) Insecure Cookie Handling Vulnerability02-11-2008
Maran PHP Shop (prod.php cat) SQL Injection Vulnerability02-11-2008
Joovili 3.1.4 Insecure Cookie Handling Vulnerability02-11-2008
Apartment Search Script (RFU-XSS) Multiple Remote Vulnerabilities02-11-2008
NetRisk <= 2.0 (XSS-SQL Injection) Remote Vulnerabilities02-11-2008
Downline Goldmine newdownlinebuilder (tr.php id) SQL Injection Vuln02-11-2008
Downline Goldmine paidversion (tr.php id) SQL Injection Vulnerability02-11-2008
YourFreeWorld Shopping Cart (index.php c) Blind SQL Injection Vuln02-11-2008
1st News (products.php id) Remote SQL Injection Vulnerability02-11-2008
Chipmunk CMS (reguser.php) Add Admin Exploit (html)02-11-2008
deV!Lz Clanportal [DZCP] <= 1.4.9.6 Blind SQL Injection Exploit02-11-2008
Maran PHP Shop (prodshow.php) SQL Injection Vulnerability02-11-2008