orderdetails.aspx, as made available to Microsoft .NET developers as example code and demonstrated on www.ibuyspystore.com, allows remote attackers to view the orders of other users by modifying the OrderID parameter.
References
Configurations
History
20 Nov 2024, 23:39
Type | Values Removed | Values Added |
---|---|---|
References | () http://marc.info/?l=bugtraq&m=101518860823788&w=2 - |
Information
Published : 2002-07-26 04:00
Updated : 2024-11-20 23:39
NVD link : CVE-2002-0409
Mitre link : CVE-2002-0409
CVE.ORG link : CVE-2002-0409
JSON object : View
Products Affected
microsoft
- .net_framework
CWE