CVE Vulnerabilities

CVE-2002-0409

Published: Jul 26, 2002 | Modified: Nov 20, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

orderdetails.aspx, as made available to Microsoft .NET developers as example code and demonstrated on www.ibuyspystore.com, allows remote attackers to view the orders of other users by modifying the OrderID parameter.

Affected Software

Name Vendor Start Version End Version
.net_framework Microsoft 1.0 (including) 1.0 (including)

References