orderdetails.aspx, as made available to Microsoft .NET developers as example code and demonstrated on www.ibuyspystore.com, allows remote attackers to view the orders of other users by modifying the OrderID parameter.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| .net_framework | Microsoft | 1.0 (including) | 1.0 (including) |