CVE-2004-2701
AspDotNetStorefront 3.3 - Cross-Site Scripting via signin.aspx returnurl Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-2701. PoCs published by Thomas Ryan.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in AspDotNetStorefront 3.3 via the 'returnurl' parameter in 'signin.aspx'. The PoC includes multiple payloads to trigger XSS, confirming insufficient input sanitization.
Description
Cross-site scripting (XSS) vulnerability in signin.aspx for AspDotNetStorefront 3.3 allows remote attackers to inject arbitrary web script or HTML via the returnurl parameter.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in AspDotNetStorefront 3.3 via the 'returnurl' parameter in 'signin.aspx'. The PoC includes multiple payloads to trigger XSS, confirming insufficient input sanitization.