Vulnerabilities > CVE-2006-1257 - Unspecified vulnerability in Microsoft Commerce Server 2002
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN microsoft
nessus
Summary
The sample files in the authfiles directory in Microsoft Commerce Server 2002 before SP2 allow remote attackers to bypass authentication by logging in to authfiles/login.asp with a valid username and any password, then going to the main site twice.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Nessus
NASL family | CGI abuses |
NASL id | COMMERCESERVER2002_AUTH_BYPASS.NASL |
description | The version of Microsoft Commerce Server 2002 installed on the remote host may enable an attacker to bypass authentication if the sample files from the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 21205 |
published | 2006-04-10 |
reporter | This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/21205 |
title | Microsoft Commerce Server 2002 authfiles/login.asp Authentication Bypass |
code |
|
References
- http://msdn.microsoft.com/library/default.asp?url=/library/en-us/csvr2002/htm/cs_se_securityconcepts_cbgw.asp
- http://msdn.microsoft.com/library/default.asp?url=/library/en-us/csvr2002/htm/cs_se_securityconcepts_cbgw.asp
- http://securityreason.com/securityalert/594
- http://securityreason.com/securityalert/594
- http://www.osvdb.org/24121
- http://www.osvdb.org/24121
- http://www.securityfocus.com/archive/1/427974/100/0/threaded
- http://www.securityfocus.com/archive/1/427974/100/0/threaded
- http://www.securityfocus.com/bid/17134
- http://www.securityfocus.com/bid/17134
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25330
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25330