BugSearch is an information portal focused on applications security, web oriented and not. We offer our services to disclose our registered users on security alerts found on the net, in order to warn them as soon as possible on bugs, system flaws, exploits and threats afflicting applications and possible patches.

New Feature: Post New Exploit

Register now to start receiving our security alerts of your favourite applications or try our new Android App which will keep you updated everywhere you are!


Last Advisories
Ultrastats <= 0.2.142 (players-detail.php) Blind SQL Injection Exploit13-07-2008
MFORUM 0.1a Arbitrary Add-Admin Vulnerability13-07-2008
ITechBids 7.0 Gold (XSS-SQL) Multiple Remote Vulnerabilities13-07-2008
Scripteen Free Image Hosting Script 1.2 (cookie) Pass Grabber Exploit13-07-2008
trixbox 2.6.1 (langChoice) Remote Root Exploit (py)12-07-2008
reSIProcate 1.3.2 Remote Denial of Service PoC12-07-2008
Maian Cart 1.1 Insecure Cookie Handling Vulnerability12-07-2008
Maian Events 2.0 Insecure Cookie Handling Vulnerability12-07-2008
Maian Gallery 2.0 Insecure Cookie Handling Vulnerability12-07-2008
Maian Greetings 2.1 Insecure Cookie Handling Vulnerability12-07-2008
Maian Music 1.0 Insecure Cookie Handling Vulnerability12-07-2008
Wizi Wiki Wig 1.0 (index.php c) Local File Inclusion Vulnerability12-07-2008
fuzzylime cms 3.01 (polladd.php poll) Remote Code Execution Exploit (php)12-07-2008
fuzzylime cms 3.01 (polladd.php poll) Remote Code Execution Exploit (pl)12-07-2008
Joomla Component n-forms 1.01 Blind SQL Injection Exploit12-07-2008
WebCMS Portal Edition (id) Remote SQL Injection Vulnerability12-07-2008
jSite 1.0 OE (SQL-LFI) Multiple Remote Vulnerabilities12-07-2008
Avlc Forum (vlc_forum.php id) Remote SQL Injection Vulnerability12-07-2008
trixbox 2.6.1 (langChoice) Remote Root Exploit (py)12-07-2008
Download Accelerator Plus - DAP 8.x m3u File Buffer Overflow Exploit (c)11-07-2008
File Store PRO 3.2 Multiple Blind SQL Injection Vulnerabilities11-07-2008
Facebook Newsroom CMS 0.5.0 Beta 1 Remote File Inclusion Vulnerability11-07-2008
Wysi Wiki Wyg 1.0 (index.php c) Local File Inclusion Vulnerability11-07-2008
Core Image Fun House <= 2.0 Arbitrary Code Execution PoC (OSX)11-07-2008
Million Pixels 3 (id_cat) Remote SQL Injection Vulnerability11-07-2008
DreamNews Manager (id) Remote SQL Injection Vulnerability10-07-2008
gapicms 9.0.2 (dirDepth) Remote File Inclusion Vulnerability10-07-2008
phpDatingClub (website.php page) Local File Inclusion Vulnerability10-07-2008
Zen Cart 1.3.8 Multiple Local File Inclusion Vulnerabilities10-07-2008
trixbox (langChoice) Local File Inclusion Exploit (connect-back) v209-07-2008