Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2022-25396

Disclosure Date: March 02, 2022 (last updated February 23, 2025)
Cosmetics and Beauty Product Online Store v1.0 was discovered to contain a SQL injection vulnerability via the search parameter.
Attacker Value
Unknown

CVE-2022-25395

Disclosure Date: March 02, 2022 (last updated February 23, 2025)
Cosmetics and Beauty Product Online Store v1.0 was discovered to contain multiple reflected cross-site scripting (XSS) attacks via the search parameter under the /cbpos/ app.
Attacker Value
Unknown

CVE-2018-10299

Disclosure Date: April 23, 2018 (last updated November 26, 2024)
An integer overflow in the batchTransfer function of a smart contract implementation for Beauty Ecosystem Coin (BEC), the Ethereum ERC20 token used in the Beauty Chain economic system, allows attackers to accomplish an unauthorized increase of digital assets by providing two _receivers arguments in conjunction with a large _value argument, as exploited in the wild in April 2018, aka the "batchOverflow" issue.
0
Attacker Value
Unknown

CVE-2017-17595

Disclosure Date: December 13, 2017 (last updated November 26, 2024)
Beauty Parlour Booking Script 1.0 has SQL Injection via the /list gender or city parameter.
0
Attacker Value
Unknown

CVE-2016-1222

Disclosure Date: June 05, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in Kobe Beauty php-contact-form before 2016-05-18 allows remote attackers to inject arbitrary web script or HTML via a crafted URI.
Attacker Value
Unknown

CVE-2014-6018

Disclosure Date: September 22, 2014 (last updated October 05, 2023)
The global beauty research (aka com.appems.topgirl) application 1.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-5577

Disclosure Date: September 09, 2014 (last updated October 05, 2023)
The AVON Buy & Sell (aka com.AVONBeautyntheRep) application 0.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0