Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2023-24065PUBLISHED: 2023-01-29
NOSH 4a5cfdb allows stored XSS via the create user page. For example, a first name (of a physician, assistant, or billing user) can have a JavaScript payload that is executed upon visiting the /users/2/1 page. This may allow attackers to steal Protected Health Information because the product is for ...
CVE-2023-0565PUBLISHED: 2023-01-29Business Logic Errors in GitHub repository froxlor/froxlor prior to 2.0.10.
CVE-2023-0566PUBLISHED: 2023-01-29Static Code Injection in GitHub repository froxlor/froxlor prior to 2.0.10.
CVE-2009-10003PUBLISHED: 2023-01-29
A vulnerability was found in capnsquarepants wordcraft up to 0.6. It has been classified as problematic. Affected is an unknown function of the file tag.php. The manipulation of the argument tag leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 0.7 is ...
CVE-2016-15022PUBLISHED: 2023-01-29
A vulnerability was found in mosbth cimage up to 0.7.18. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file check_system.php. The manipulation of the argument $_SERVER['SERVER_SOFTWARE'] leads to cross site scripting. The attack can be launche...
User Rank: Strategist
1/24/2019 | 11:37:10 AM
This kind of security theater crap masquerading as vigilance gives us a bad name as a profession and contributes to alert fatigue.
How about this? If your DNS MX record or SOA record changes, and you don't notice, that might be a problem.
If you expose personal data from your DNS registrar and that person is also on Facebook and Linked In, you might have a problem.
If your DNS stops working right and you don't notice, you might have a problem.
Yes indeed, you might a have a problem, but it's not the one DHS exposes in this overblown cry of "WOLF! WOLF!", the problem is you're doing security theater, not security.
If your organization does security as a compliance checkbox for HIPAA or SOX, or just as a safe harbor for liability, you deserve to get Pwned by something as lame as social engineering your DNS registration.
Meanwhile spare the rest of us warnings about the sky falling when it's just a fog bank.