10 lines
No EOL
705 B
Text
10 lines
No EOL
705 B
Text
source: https://www.securityfocus.com/bid/10506/info
|
|
|
|
AspDotNetStorefront is reportedly prone to an access validation vulnerability that may allow a remote attacker to delete arbitrary contents from a vulnerable Web site. The issue occurs because the 'deleteicon.aspx' script does not validate access before allowing an unprivileged user to delete contents such as icons and images from the site.
|
|
|
|
Other attacks may be possible as well, however, this has not been confirmed.
|
|
|
|
AspDotNetStorefront 3.3 is reportedly affected by this issue, however, it is possible that other versions are affected as well.
|
|
|
|
http://www.example.com/aspdotnetcart/admin/deleteicon.aspx?ProductID=1&Fo
|
|
rmImageName=Pic1&size=icon |