BugSearch is an information portal focused on applications security, web oriented and not. We offer our services to disclose our registered users on security alerts found on the net, in order to warn them as soon as possible on bugs, system flaws, exploits and threats afflicting applications and possible patches.

New Feature: Post New Exploit

Register now to start receiving our security alerts of your favourite applications or try our new Android App which will keep you updated everywhere you are!


Last Advisories
Mambo Component Newsletter (listid) Remote SQL Injection Vulnerability29-01-2008
Mambo Component Fq (listid) Remote SQL Injection Vulnerability29-01-2008
Mambo Component MaMML (listid) Remote SQL Injection Vulnerability29-01-2008
Oracle 10g R1 pitrig_drop PLSQL Injection (get users hash)28-01-2008
Oracle 10g R1 pitrig_truncate PLSQL Injection (get users hash)28-01-2008
Oracle 10g R1 xdb.xdb_pitrig_pkg PLSQL Injection (change sys password)28-01-2008
Oracle 10g R1 xdb.xdb_pitrig_pkg Buffer Overflow Exploit (PoC)28-01-2008
IrfanView 4.10 .FPX File Memory Corruption Exploit28-01-2008
MailBee Objects 5.5 (MailBee.dll) Remote Insecure Method Exploit28-01-2008
phpMyClub 0.0.1 (page_courante) Local File Inclusion Vulnerability28-01-2008
bubbling library 1.32 dispatcher.php Remote File Disclosure Vulnerabilities28-01-2008
Wordpress Plugin WP-Cal 0.3 editevent.php SQL Injection Vulnerability27-01-2008
Wordpress plugin fGallery 2.4.1 fimrss.php SQL Injection Vulnerability27-01-2008
Simple Forum 3.2 (FD-XSS) Multiple Remote Vulnerabilities26-01-2008
phpIP 4.3.2 Numerous Remote SQL Injection Vulnerabilities26-01-2008
Bubbling Library 1.32 Multiple Local File Inclusion Vulnerabilities26-01-2008
Gateway WebLaunch ActiveX Remote Buffer Overflow Exploit25-01-2008
PageTool 1.07 news_id Remote SQL Injection Vulnerability25-01-2008
Tiger PHP News System 1.0b build 39 Remote SQL Injection Vulnerability25-01-2008
flinx <= 1.3 (category.php id) Remote SQL Injection Vulnerability25-01-2008
Sejoong Namo ActiveSquare 6 NamoInstaller.dll install Method Exploit25-01-2008
Persits XUpload 3.0 AddFile() Remote Buffer Overflow Exploit25-01-2008
CandyPress eCommerce suite 4.1.1.26 Multiple Remote Vulnerabilities25-01-2008
Apple iPhone 1.1.2 Remote Denial of Service Exploit24-01-2008
Move Networks Upgrade Manager Control Buffer Overflow Exploit24-01-2008
Seagull 0.6.3 (optimizer.php files) Remote File Disclosure Vulnerability24-01-2008
ImageShack Toolbar 4.5.7 FileUploader Class InsecureMethod PoC24-01-2008
Foojan WMS 1.0 (index.php story) Remote SQL Injection Vulnerability23-01-2008
LulieBlog 1.02 (voircom.php id) Remote SQL Injection Vulnerability23-01-2008
Web Wiz Forums <= 9.07 (sub) Remote Directory Traversal Vulnerability23-01-2008