BugSearch is an information portal focused on applications security, web oriented and not. We offer our services to disclose our registered users on security alerts found on the net, in order to warn them as soon as possible on bugs, system flaws, exploits and threats afflicting applications and possible patches.

New Feature: Post New Exploit

Register now to start receiving our security alerts of your favourite applications or try our new Android App which will keep you updated everywhere you are!


Last Advisories
iGaming CMS 2.0 Alpha 1 (search.php) Remote SQL Injection Exploit16-10-2008
Mantis Bug Tracker <= 1.1.3 Remote Code Execution Exploit16-10-2008
Calendars for the Web 4.02 Admin Auth Bypass Vulnerability16-10-2008
PHP Easy Downloader 1.5 (file) File Disclosure Vulnerability16-10-2008
Post Affiliate Pro 2.0 (index.php md) Local File Inclusion Vulnerability16-10-2008
myStats (hits.php) Multiple Remote Vulnerabilities Exploit15-10-2008
myEvent 1.6 (viewevent.php) Remote SQL Injection Vulnerability15-10-2008
MS Windows XP-2003 AFD.sys Privilege Escalation Exploit (K-plugin)15-10-2008
AstroSPACES (id) Remote SQL Injection Vulnerability15-10-2008
Titan FTP server 6.26 build 630 Remote Denial of Service Exploit14-10-2008
Eserv 3.x FTP Server (ABOR) Remote Stack Overflow PoC14-10-2008
SezHoo 0.1 (IP) Remote File Inclusion Vulnerability14-10-2008
Nuked-klaN <= 1.7.7 - <= SP4.4 Multiple Vulnerabilities Exploit14-10-2008
Telecom Italia Alice Pirelli routers Backdoor from internal LAN-WAN14-10-2008
WP Comment Remix 1.4.3 Remote SQL Injection Exploit14-10-2008
XOOPS Module xhresim (index.php no) Remote SQL Injection Vuln14-10-2008
My PHP Dating (success_story.php id) SQL Injection Vulnerability14-10-2008
PhpWebGallery <= 1.7.2 Session Hijacking - Code Execution Exploit14-10-2008
VLC 0.9.2 Media Player XSPF Memory Corruption Vulnerability14-10-2008
LokiCMS 0.3.4 writeconfig() Remote Command Execution Exploit13-10-2008
XM Easy Personal FTP Server 5.6.0 Remote Denial of Service Exploit13-10-2008
RaidenFTPD 2.4 build 3620 Remote Denial of Service Exploit13-10-2008
IndexScript 3.0 (sug_cat.php parent_id) SQL Injection Vulnerability13-10-2008
ParsBlogger (links.asp id) Remote SQL Injection Vulnerability13-10-2008
LokiCMS 0.3.4 (admin.php) Create Local File Inclusion Exploit13-10-2008
Globsy <= 1.0 Remote File Rewriting Exploit12-10-2008
mini-pub 0.3 (LFD-CE) Multiple Remote Vulnerabilities12-10-2008
mini-pub 0.3 Local Directory Traversal - File Disclosure Vulnerabilities12-10-2008
MS Windows InternalOpenColorProfile Heap Overflow PoC (MS08-046)12-10-2008
GuildFTPd 0.999.8.11-0.999.14 Heap Corruption PoC-DoS Exploit12-10-2008