Threat Intelligence

8/22/2016
03:00 PM
Steve Zurier
Steve Zurier
Slideshows
Connect Directly
Twitter
RSS
E-Mail

Meet The 2016 PWNIE Award Winners

Contest celebrating the best and worst in information security celebrates its 10th year.
11 of 16

10. Lamest Vendor Response

This award recognizes the vendor that most poorly responded to a security issue. 

'WD MyPassword Drive'

Credit: Western Digital

'When serious flaws were discovered in its hard drive encryption Western Digital could only say it would 'continue to evaluate the observations' and did not say whether it would issue a fix - you know, like most normal tech companies would.' - The Pwnie Awards  

Image Source: www.forbes.com

10. Lamest Vendor Response

This award recognizes the vendor that most poorly responded to a security issue.

WD MyPassword Drive

Credit: Western Digital

When serious flaws were discovered in its hard drive encryption Western Digital could only say it would continue to evaluate the observations and did not say whether it would issue a fix you know, like most normal tech companies would. The Pwnie Awards

Image Source: www.forbes.com

11 of 16
Comment  | 
Print  | 
Comments
Oldest First  |  Newest First  |  Threaded View
New Bluetooth Hack Affects Millions of Vehicles
Dark Reading Staff 11/16/2018
Vulnerabilities Dip 7%, but Researchers Are Cautious
Kelly Sheridan, Staff Editor, Dark Reading,  11/19/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Genius! Only a Big Brother can control another.
Current Issue
Flash Poll
How Enterprises Are Attacking the Cybersecurity Problem
How Enterprises Are Attacking the Cybersecurity Problem
Data breach fears and the need to comply with regulations such as GDPR are two major drivers increased spending on security products and technologies. But other factors are contributing to the trend as well. Find out more about how enterprises are attacking the cybersecurity problem by reading our report today.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-19433
PUBLISHED: 2018-11-22
ShowDoc 2.4.1 has XSS via the lang parameter because install/database.php mishandles the $cur_lang value.
CVE-2018-19434
PUBLISHED: 2018-11-22
An issue was discovered on the "Bank Account Matching - Receipts" screen of the General Ledger component in webERP 4.15. BankMatching.php has Blind SQL injection via the AmtClear_ parameter.
CVE-2018-19435
PUBLISHED: 2018-11-22
An issue was discovered in the Sales component in webERP 4.15. SalesInquiry.php has SQL Injection via the SortBy parameter.
CVE-2018-19436
PUBLISHED: 2018-11-22
An issue was discovered in the Manufacturing component in webERP 4.15. CollectiveWorkOrderCost.php has Blind SQL Injection via the SearchParts parameter.
CVE-2018-19437
PUBLISHED: 2018-11-22
UCMS 1.4.7 allows remote authenticated users to change the administrator password because $_COOKIE['admin_'.cookiehash] is used for arbitrary cookie values that are set and not empty.