Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown

CVE-2025-23917

Disclosure Date: January 16, 2025 (last updated February 27, 2025)
Missing Authorization vulnerability in Chandrika Guntur, Morgan Kay Chamber Dashboard Business Directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Chamber Dashboard Business Directory: from n/a through 3.3.8.
0
Attacker Value
Unknown

CVE-2024-11452

Disclosure Date: January 16, 2025 (last updated February 27, 2025)
The Chamber Dashboard Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'business_categories' shortcode in all versions up to, and including, 3.3.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2025-22754

Disclosure Date: January 15, 2025 (last updated February 27, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Berkman Center for Internet & Society Amber allows Reflected XSS.This issue affects Amber: from n/a through 1.4.4.
0
Attacker Value
Unknown

CVE-2020-24699

Disclosure Date: August 31, 2020 (last updated February 22, 2025)
The Chamber Dashboard Business Directory plugin 3.2.8 for WordPress allows XSS.
Attacker Value
Unknown

CVE-2014-5920

Disclosure Date: September 18, 2014 (last updated October 05, 2023)
The VK Amberfog (aka com.amberfog.vkfree) application 3.5.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2010-5292

Disclosure Date: January 10, 2014 (last updated October 05, 2023)
Amberdms Billing System (ABS) before 1.4.1, when a multi-instance installation is configured, might allow local users to obtain sensitive information by reading the cache in between runs of the include/cron/services_usage.php cron job.
0
Attacker Value
Unknown

CVE-2010-5291

Disclosure Date: January 10, 2014 (last updated October 05, 2023)
Amberdms Billing System (ABS) before 1.4.1 does not properly implement blacklisting after detection of invalid login attempts, which makes it easier for remote attackers to obtain access via a brute-force approach.
0
Attacker Value
Unknown

CVE-2007-6129

Disclosure Date: November 26, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in scripts/include/show_content.php in Amber Script 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the id parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.
0
Attacker Value
Unknown

CVE-2006-2674

Disclosure Date: May 30, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Tamber Forum 1.9.13 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) frm_id parameter to (a) show_forum.asp, (2) a search field to (b) forum_search.asp, (3) Email address or (4) Password to (c) admin/index.asp, (5) frm_cat_id parameter to (d) browse_forum_cat.asp, or (6) Message Subject or (7) Message Text field to (e) post_message.asp.
0
Attacker Value
Unknown

CVE-2006-0152

Disclosure Date: January 10, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) in search_result.php in phpChamber 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the needle parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0