| CVE-2004-2699 | | 0.03 | — | 0.06 | | Dec 31, 2004 | deleteicon.aspx in AspDotNetStorefront 3.3 allows remote attackers to delete arbitrary product images via a modified ProductID parameter. |
| CVE-2004-2701 | | 0.03 | — | 0.01 | | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in signin.aspx for AspDotNetStorefront 3.3 allows remote attackers to inject arbitrary web script or HTML via the returnurl parameter. |
| CVE-2004-2700 | | 0.00 | — | 0.00 | | Dec 31, 2004 | Unrestricted file upload vulnerability in AspDotNetStorefront 3.3 allows remote authenticated administrators to upload arbitrary files with executable extensions via admin/images.aspx. |