BugSearch is an information portal focused on applications security, web oriented and not. We offer our services to disclose our registered users on security alerts found on the net, in order to warn them as soon as possible on bugs, system flaws, exploits and threats afflicting applications and possible patches.

New Feature: Post New Exploit

Register now to start receiving our security alerts of your favourite applications or try our new Android App which will keep you updated everywhere you are!


Last Advisories
MyFWB 1.0 (index.php page) Remote SQL Injection Vulnerability20-09-2008
Explay CMS <= 2.1 Insecure Cookie Handling Vulnerability20-09-2008
Plaincart 1.1.2 (p) Remote SQL Injection Vulnerability20-09-2008
Diesel Pay Script (area) Remote SQL Injection Vulnerability20-09-2008
Oceandir <= 2.9 (show_vote.php id) Remote SQL Injection Vulnerability20-09-2008
DESlock+ <= 3.2.7 Local Kernel Overflow PoC20-09-2008
DESlock+ <= 3.2.7 (probe read) Local Kernel Denial of Service PoC20-09-2008
DESlock+ <= 3.2.7 Local Kernel Race Condition Denial of Service PoC20-09-2008
Advanced Electron Forum <= 1.0.6 Remote Code Execution Vulnerability20-09-2008
jPORTAL 2 (humor.php id) Remote SQL Injection Vulnerability20-09-2008
easyLink 1.1.0 (detail.php) Remote SQL Injection Vulnerability19-09-2008
fhttpd 0.4.2 un64() Remote Denial of Service Exploit19-09-2008
NuMedia Soft NMS DVD Burning SDK Activex (NMSDVDX.dll) Exploit19-09-2008
Pluck 4.5.3 (update.php) Remote File Corruption Exploit19-09-2008
Explay CMS <= 2.1 Persistent XSS and CSRF Vulnerability19-09-2008
ProActive CMS (template) Local File Inclusion Vulnerability18-09-2008
Diesel Joke Site (picture_category.php id) SQL Injection Vulnerability18-09-2008
ProArcadeScript 1.3 (random) Remote SQL Injection Vulnerability18-09-2008
CYASK 3.x (collect.php neturl) Local File Disclosure Vulnerability18-09-2008
E-Php CMS (article.php es_id) Remote SQL Injection Vulnerability18-09-2008
addalink <= 4 (category_id) Remote SQL Injection Vulnerability18-09-2008
addalink <= 4 Arbitrary Admin Access Vulnerability Exploit18-09-2008
AssetMan v2.5-b SQL Injection using Session Fixation Attack18-09-2008
Technote 7 (shop_this_skin_path) Remote File Inclusion Vulnerability17-09-2008
Cisco Router HTTP Administration CSRF Command Execution Exploit17-09-2008
Cisco Router HTTP Administration CSRF Command Execution Exploit 217-09-2008
WonderWare SuiteLink 2.0 Remote Denial of Service Exploit (meta)17-09-2008
PHP Crawler 0.8 (footer) Remote File Inclusion Vulnerability17-09-2008
WonderWare SuiteLink < 2.0 Remote Denial of Service Exploit (meta)17-09-2008
phpRealty 0.3 (INC) Remote File Inclusion Vulnerability17-09-2008