CVE-2006-1257 Information
Feb 14, 2021
cve
Description
The sample files in the authfiles directory in Microsoft Commerce Server 2002 before SP2 allow remote attackers to bypass authentication by logging in to authfiles/login.asp with a valid username and any password then going to the main site twice.
Reference
http://msdn.microsoft.com/library/default.asp?url=/library/en-us/csvr2002/htm/cs_se_securityconcepts_cbgw.asp http://msdn.microsoft.com/library/default.asp?url=/library/en-us/csvr2002/htm/cs_se_securityconcepts_cbgw.asp http://securityreason.com/securityalert/594 http://www.osvdb.org/24121 http://www.securityfocus.com/archive/1/427974/100/0/threaded http://www.securityfocus.com/bid/17134 https://exchange.xforce.ibmcloud.com/vulnerabilities/25330
Share on: