CVE-2004-2699
AspDotNetStorefront 3.3 - Arbitrary Product Image Deletion via deleteicon.aspx ProductID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-2699. PoCs published by Thomas Ryan.
AI-analyzed exploit summary This is a writeup describing an access validation vulnerability in AspDotNetStorefront's 'deleteicon.aspx' script, allowing unauthenticated deletion of arbitrary icons/images. No exploit code is provided, only a URL example demonstrating the issue.
Description
deleteicon.aspx in AspDotNetStorefront 3.3 allows remote attackers to delete arbitrary product images via a modified ProductID parameter.
Exploits (1)
This is a writeup describing an access validation vulnerability in AspDotNetStorefront's 'deleteicon.aspx' script, allowing unauthenticated deletion of arbitrary icons/images. No exploit code is provided, only a URL example demonstrating the issue.