Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-35606PUBLISHED: 2022-08-18A SQL injection vulnerability in CustomerDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameter 'customerCode.'
CVE-2022-35598PUBLISHED: 2022-08-18A SQL injection vulnerability in ConnectionFactoryDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter username.
CVE-2022-35599PUBLISHED: 2022-08-18A SQL injection vulnerability in Stocks.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter productcode.
CVE-2022-35601PUBLISHED: 2022-08-18A SQL injection vulnerability in SupplierDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter searchTxt.
CVE-2022-35602PUBLISHED: 2022-08-18A SQL injection vulnerability in UserDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter user.
User Rank: Ninja
2/14/2016 | 1:49:26 PM
Calls for article submissions would be nice, too, with a modest prize for the winners (outside publication, which is already a pretty nice reward), and perhaps more contributor exposure through media, such as spotlights on writers who are less-known.
Anyway, this is a great opportunity for the humor and sarcasm of the hacker community to shine. A little levity to soften the all-too-miserable reality of InfoSec.