PT-2006-2273 · Microsoft · Commerce Server 2002
Dimitri Van De Giessen
·
Published
2006-03-19
·
Updated
2018-10-18
·
CVE-2006-1257
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Commerce Server 2002 versions prior to SP2
Description
The issue allows remote attackers to bypass authentication. This can be achieved by logging in to "authfiles/login.asp" with a valid
username and any password, then accessing the main site twice.Recommendations
For Microsoft Commerce Server 2002 versions prior to SP2, apply Service Pack 2 to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Commerce Server 2002