Vulnerabilities > CVE-2002-0409 - Remote Security vulnerability in Microsoft .Net Framework 1.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
NONE Availability impact
NONE Summary
orderdetails.aspx, as made available to Microsoft .NET developers as example code and demonstrated on www.ibuyspystore.com, allows remote attackers to view the orders of other users by modifying the OrderID parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |