orderdetails.aspx, as made available to Microsoft .NET developers as example code and demonstrated on www.ibuyspystore.com, allows remote attackers to view the orders of other users by modifying the OrderID parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
.net_framework | Microsoft | 1.0 (including) | 1.0 (including) |