VYPR

Aspdotnetstorefront

Sign in to watch

by Aspdotnetstorefront

CVEs (3)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2004-26990.030.06Dec 31, 2004deleteicon.aspx in AspDotNetStorefront 3.3 allows remote attackers to delete arbitrary product images via a modified ProductID parameter.
CVE-2004-27010.030.01Dec 31, 2004Cross-site scripting (XSS) vulnerability in signin.aspx for AspDotNetStorefront 3.3 allows remote attackers to inject arbitrary web script or HTML via the returnurl parameter.
CVE-2004-27000.000.00Dec 31, 2004Unrestricted file upload vulnerability in AspDotNetStorefront 3.3 allows remote authenticated administrators to upload arbitrary files with executable extensions via admin/images.aspx.