BugSearch is an information portal focused on applications security, web oriented and not. We offer our services to disclose our registered users on security alerts found on the net, in order to warn them as soon as possible on bugs, system flaws, exploits and threats afflicting applications and possible patches.

New Feature: Post New Exploit

Register now to start receiving our security alerts of your favourite applications or try our new Android App which will keep you updated everywhere you are!


Last Advisories
CCLeague Pro <= 1.2 Insecure Cookie Authentication Vulnerability21-06-2008
OFFL <= 0.2.6 (teams.php fflteam) Remote SQL Injection Vulnerability21-06-2008
AJ HYIP ACME (news.php id) Remote SQL Injection Vulnerability21-06-2008
Top Auction Pro (category) Remote SQL Injection Vulnerability21-06-2008
phpAuction 3.2.1 (item.php id) Remote SQL Injection Vulnerability21-06-2008
Virtual Support Office-XP <= 3.0.29 Multiple Remote Vulnerabilities20-06-2008
GL-SH Deaf Forum <= 6.5.5 Multiple Remote Vulnerabilities20-06-2008
FireAnt 1.3 (index.php page) Local File Inclusion Vulnerability20-06-2008
FubarForum 1.5 (index.php page) Local File Inclusion Vulnerability20-06-2008
Lightweight News Portal [LNP] 1.0b Multiple Remote Vulnerabilities20-06-2008
IPTBB 0.5.6 (index.php act) Local File Inclusion Vulnerability20-06-2008
CiBlog 3.1 (links-extern.php id) Remote SQL Injection Vulnerability20-06-2008
Jamroom 3.3.5 Remote File Inclusion Vulnerabilities20-06-2008
JaxUltraBB <= 2.0 (LFI-XSS) Multiple Remote Vulnerabilities20-06-2008
emuCMS 0.3 (cat_id) Remote SQL Injection Vulnerability20-06-2008
PHPAuction (profile.php user_id) Remote SQL Injection Vulnerability20-06-2008
eLineStudio Site Composer (ESC) <= 2.6 Multiple Vulnerabilities19-06-2008
OwnRS Blog beta3 (SQL-XSS) Multiple Remote Vulnerabilities19-06-2008
Academic Web Tools CMS <= 1.4.2.8 Multiple Vulnerabilities19-06-2008
samart-cms 2.0 (contentsid) Remote SQL Injection Vulnerability19-06-2008
CMS-BRD (menuclick) Remote SQL Injection Vulnerability19-06-2008
Orlando CMS 0.6 Remote File Inclusion Vulnerabilities19-06-2008
CaupoShop Classic 1.3 (saArticle[ID]) Remote SQL Injection Vulnerability19-06-2008
Lotus Core CMS 1.0.1 Remote File Inclusion Vulnerabilities19-06-2008
AJ Auction Web 2.0 (cate_id) SQL Injection Vulnerability19-06-2008
AJ Auction v1 (id) Remote SQL Injection Vulnerability19-06-2008
screen 4.0.3 Local Authentication Bypass Vulnerability (OpenBSD)18-06-2008
Traindepot 0.1 (LFI-XSS) Multiple Remote Vulnerabilities18-06-2008
doITlive CMS <= 2.50 (SQL Injection-XSS) Multiple Vulnerabilities18-06-2008
AspWebCalendar 2008 Remote File Upload Vulnerability18-06-2008