Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-31856PUBLISHED: 2022-07-05Newsletter Module v3.x was discovered to contain a SQL injection vulnerability via the zemez_newsletter_email parameter at /index.php.
CVE-2022-32310PUBLISHED: 2022-07-05An access control issue in Ingredient Stock Management System v1.0 allows attackers to take over user accounts via a crafted POST request to /isms/classes/Users.php.
CVE-2022-32311PUBLISHED: 2022-07-05Ingredient Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /isms/admin/stocks/view_stock.php.
CVE-2022-32413PUBLISHED: 2022-07-05An arbitrary file upload vulnerability in Dice v4.2.0 allows attackers to execute arbitrary code via a crafted file.
CVE-2022-34972PUBLISHED: 2022-07-05So Filter Shop v3.x was discovered to contain multiple blind SQL injection vulnerabilities via the att_value_id , manu_value_id , opt_value_id , and subcate_value_id parameters at /index.php?route=extension/module/so_filter_shop_by/filter_data.
User Rank: Author
11/26/2015 | 1:54:33 AM
your pardon is granted. as with spam before it, spoofed source ddos and irresponsibly open servers have brought out every possible form of apologist. i have heard "there is no problem" and "it is not my problem" literally hundreds of times now. i won't take it personally, and i hope you won't take it personally when i tell you that you're plain and simply and completely wrong.
argument by analogy is fraught with error. as in this case, choosing the wrong analogy leads to absurd results. closer to the situation at hand would be holding the builder and architect of a house responsible if the house catches fire and burns the whole neighborhood down because somebody rang the doorbell too hard.
<< This all seems very huffy. The reality of crime is that bad guys often get away with their behavior, and we have to live with this unfairness lest we create even more unfairness. >>
you can live with whatever impositions you wish, but, you can't insist that i do the same. "the reality" as you call it is that in the real world, creating or operating a public nuisance is an actionable offense if someone is injured by it, and the internet has thus far yelled and screamed about "stifling innovation" whenever similar accountability and recourse has been proposed. well, i am not here to censor any content or demand that software creators be licensed or anything else that might stifle innovation.
rather, i'm saying that the collective nuisance cost of the internet's irresponsible device makers and server and network operators is now so high that even the most self deceiving apologist cannot successfully pretend that everything will be ok without giving the lawyers and insurance companies a more defined role.
vixie