Lucene search

K
cve[email protected]CVE-2002-0409
HistoryJul 26, 2002 - 4:00 a.m.

CVE-2002-0409

2002-07-2604:00:00
web.nvd.nist.gov
29
cve-2002-0409
microsoft .net
orderid parameter
data leak
remote attack

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

7.2 High

AI Score

Confidence

Low

0.946 High

EPSS

Percentile

99.3%

orderdetails.aspx, as made available to Microsoft .NET developers as example code and demonstrated on www.ibuyspystore.com, allows remote attackers to view the orders of other users by modifying the OrderID parameter.

Affected configurations

NVD
Node
microsoft.net_frameworkMatch1.0

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

7.2 High

AI Score

Confidence

Low

0.946 High

EPSS

Percentile

99.3%

Related for CVE-2002-0409