Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-23836PUBLISHED: 2021-01-15
An issue was discovered in flatCore before 2.0.0 build 139. A stored XSS vulnerability was identified in the prefs_smtp_psw HTTP request body parameter for the acp interface. An admin user can inject malicious client-side script into the affected parameter without any form of input sanitization. The...
CVE-2021-23837PUBLISHED: 2021-01-15
An issue was discovered in flatCore before 2.0.0 build 139. A time-based blind SQL injection was identified in the selected_folder HTTP request body parameter for the acp interface. The affected parameter (which retrieves the file contents of the specified folder) was found to be accepting malicious...
CVE-2021-23838PUBLISHED: 2021-01-15
An issue was discovered in flatCore before 2.0.0 build 139. A reflected XSS vulnerability was identified in the media_filter HTTP request body parameter for the acp interface. The affected parameter accepts malicious client-side script without proper input sanitization. For example, a malicious user...
CVE-2020-35581PUBLISHED: 2021-01-15A stored cross-site scripting (XSS) issue in Envira Gallery Lite before 1.8.3.3 allows remote attackers to inject arbitrary JavaScript/HTML code via a POST /wp-admin/admin-ajax.php request with the meta[title] parameter.
CVE-2020-35582PUBLISHED: 2021-01-15A stored cross-site scripting (XSS) issue in Envira Gallery Lite before 1.8.3.3 allows remote attackers to inject arbitrary JavaScript/HTML code via a POST /wp-admin/post.php request with the post_title parameter.
User Rank: Ninja
7/27/2019 | 4:18:33 PM
With Comodo, it comes with an IPS, Firewall system that blocks the use of applications that starts up, it is a warning system that informs the user that there is something that could be considered problematic or intrusive. AVG provides another level of protection at the browser level and filesystem. Firefox with Ghostery stops tracking, NoScript (the one that looks like the snake) does not give outside users the ability to download files with scripting capability unless you tell it is ok.
All of the programs are free to use, of course, there are Pro/Prem editions but this is a good start for a small business.
Try it out, it works pretty well.
T