BugSearch is an information portal focused on applications security, web oriented and not. We offer our services to disclose our registered users on security alerts found on the net, in order to warn them as soon as possible on bugs, system flaws, exploits and threats afflicting applications and possible patches.

New Feature: Post New Exploit

Register now to start receiving our security alerts of your favourite applications or try our new Android App which will keep you updated everywhere you are!


Last Advisories
Web Wiz Rich Text Editor 4.0 Multiple Remote Vulnerabilities23-01-2008
Web Wiz NewsPad 1.02 (sub) Remote Directory Traversal Vulnerability23-01-2008
Siteman 1.1.9 (cat) Remote File Disclosure Vulnerability23-01-2008
Comodo AntiVirus 2.0 ExecuteStr() Remote Command Execution Exploit23-01-2008
SLAED CMS 2.5 Lite (newlang) Local File Inclusion Vulnerability23-01-2008
Liquid-Silver CMS 0.1 (update) Local File Inclusion Vulnerability23-01-2008
Aconon Mail 2004 Remote Directory Traversal Vulnerability23-01-2008
aflog 1.01 comments.php XSS - SQL Injection Vulnerability22-01-2008
HP Virtual Rooms WebHPVCInstall Control Buffer Overflow Exploit22-01-2008
Easysitenetwork Recipe (categoryid) Remote SQL Injection Vulnerability22-01-2008
Coppermine Photo Gallery <= 1.4.14 Remote SQL Injection Exploit22-01-2008
SetCMS 3.6.5 (setcms.org) Remote Command Execution Exploit22-01-2008
YaBB SE <= 1.5.5 Remote Command Execution Exploit22-01-2008
PHP-Nuke < 8.0 (sid) Remote SQL Injection Exploit22-01-2008
PHP-Nuke <= 8.0 Final (sid) Remote SQL Injection Exploit22-01-2008
Invision Gallery <= 2.0.7 Remote SQL Injection Exploit22-01-2008
Lycos FileUploader Control ActiveX Remote Buffer Overflow Exploit22-01-2008
Axigen <= 5.0.2 AXIMilter Remote Format String Exploit21-01-2008
Windows RSH daemon <= 1.8 Remote Buffer Overflow Exploit21-01-2008
Citadel SMTP <= 7.10 Remote Overflow Exploit21-01-2008
Coppermine Photo Gallery 1.4.10 Remote SQL Injection Exploit21-01-2008
Mooseguy Blog System 1.0 (blog.php month) SQL Injection Vulnerability21-01-2008
boastMachine <= 3.1 (mail.php id) SQL Injection Vulnerability21-01-2008
OZJournals 2.1.1 (id) File Disclosure Vulnerability21-01-2008
IDM-OS 1.0 (download.php fileName) File Disclosure Vulnerability21-01-2008
Lama Software (14.12.2007) Multiple Remote File Inclusion Vulnerabilities21-01-2008
AlstraSoft Forum Pay Per Post Exchange 2.0 SQL Injection Vulnerability21-01-2008
MoinMoin 1.5.x MOIND_ID cookie Bug Remote Exploit21-01-2008
Citadel SMTP <= 7.10 Remote Overflow Exploit21-01-2008
Mini File Host 1.2.1 (upload.php language) Local File Inclusion Exploit20-01-2008