Vulnerabilities > Aspdotnetstorefront

DATE CVE VULNERABILITY TITLE RISK
2004-12-31 CVE-2004-2701 Cross-Site Scripting vulnerability in Aspdotnetstorefront 3.3
Cross-site scripting (XSS) vulnerability in signin.aspx for AspDotNetStorefront 3.3 allows remote attackers to inject arbitrary web script or HTML via the returnurl parameter.
4.3
2004-12-31 CVE-2004-2700 Permissions, Privileges, and Access Controls vulnerability in Aspdotnetstorefront 3.3
Unrestricted file upload vulnerability in AspDotNetStorefront 3.3 allows remote authenticated administrators to upload arbitrary files with executable extensions via admin/images.aspx.
network
low complexity
aspdotnetstorefront CWE-264
critical
9.0
2004-12-31 CVE-2004-2699 Permissions, Privileges, and Access Controls vulnerability in Aspdotnetstorefront 3.3
deleteicon.aspx in AspDotNetStorefront 3.3 allows remote attackers to delete arbitrary product images via a modified ProductID parameter.
4.3