PT-2006-2273 · Microsoft · Commerce Server 2002

Dimitri Van De Giessen

·

Published

2006-03-19

·

Updated

2018-10-18

·

CVE-2006-1257

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Commerce Server 2002 versions prior to SP2
Description The issue allows remote attackers to bypass authentication. This can be achieved by logging in to "authfiles/login.asp" with a valid username and any password, then accessing the main site twice.
Recommendations For Microsoft Commerce Server 2002 versions prior to SP2, apply Service Pack 2 to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1257

Affected Products

Commerce Server 2002