Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2023-1172PUBLISHED: 2023-03-17
The Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the full name value in versions up to, and including, 21.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that w...
CVE-2023-1469PUBLISHED: 2023-03-17
The WP Express Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘pec_coupon[code]’ parameter in versions up to, and including, 2.2.8 due to insufficient input sanitization and output escaping. This makes it possible for authenti...
CVE-2023-1466PUBLISHED: 2023-03-17
A vulnerability was found in SourceCodester Student Study Center Desk Management System 1.0. It has been rated as critical. This issue affects the function view_student of the file admin/?page=students/view_student. The manipulation of the argument id with the input 3' AND (SELECT 2100 FROM (SELECT(...
CVE-2023-1467PUBLISHED: 2023-03-17
A vulnerability classified as critical has been found in SourceCodester Student Study Center Desk Management System 1.0. Affected is an unknown function of the file Master.php?f=delete_img of the component POST Parameter Handler. The manipulation of the argument path with the input C%3A%2Ffoo.txt le...
CVE-2023-1468PUBLISHED: 2023-03-17
A vulnerability classified as critical was found in SourceCodester Student Study Center Desk Management System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/?page=reports&date_from=2023-02-17&date_to=2023-03-17 of the component Report Handler. The manipula...
User Rank: Author
11/26/2015 | 1:54:33 AM
your pardon is granted. as with spam before it, spoofed source ddos and irresponsibly open servers have brought out every possible form of apologist. i have heard "there is no problem" and "it is not my problem" literally hundreds of times now. i won't take it personally, and i hope you won't take it personally when i tell you that you're plain and simply and completely wrong.
argument by analogy is fraught with error. as in this case, choosing the wrong analogy leads to absurd results. closer to the situation at hand would be holding the builder and architect of a house responsible if the house catches fire and burns the whole neighborhood down because somebody rang the doorbell too hard.
<< This all seems very huffy. The reality of crime is that bad guys often get away with their behavior, and we have to live with this unfairness lest we create even more unfairness. >>
you can live with whatever impositions you wish, but, you can't insist that i do the same. "the reality" as you call it is that in the real world, creating or operating a public nuisance is an actionable offense if someone is injured by it, and the internet has thus far yelled and screamed about "stifling innovation" whenever similar accountability and recourse has been proposed. well, i am not here to censor any content or demand that software creators be licensed or anything else that might stifle innovation.
rather, i'm saying that the collective nuisance cost of the internet's irresponsible device makers and server and network operators is now so high that even the most self deceiving apologist cannot successfully pretend that everything will be ok without giving the lawyers and insurance companies a more defined role.
vixie