AspDotNetStorefront ReturnURL...

- AV AC AU C I A
发布: 2004-06-09
修订: 2025-04-13

AspDotNetStorefront is prone to a cross-site scripting vulnerability. This issue exists due to insufficient sanitization of user-supplied data. The problem presents itself in the 'returnurl' parameter of the 'signin.aspx' script of the application and can allow remote attackers to steal cookie-based authentication credentials and carry out other attacks. AspDotNetStorefront 3.3 is reportedly affected by this issue, however, it is possible that other versions are affected as well.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息