Vulnerability Name: | CVE-2006-1257 (CCN-25330) | ||||||||
Assigned: | 2006-03-16 | ||||||||
Published: | 2006-03-16 | ||||||||
Updated: | 2018-10-18 | ||||||||
Summary: | The sample files in the authfiles directory in Microsoft Commerce Server 2002 before SP2 allow remote attackers to bypass authentication by logging in to authfiles/login.asp with a valid username and any password, then going to the main site twice. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Thu Mar 16 2006 - 17:59:51 CST Microsoft Commerce Server 2002: Logon as known user with a false password Source: MITRE Type: CNA CVE-2006-1257 Source: CONFIRM Type: UNKNOWN http://msdn.microsoft.com/library/default.asp?url=/library/en-us/csvr2002/htm/cs_se_securityconcepts_cbgw.asp Source: CCN Type: SA9176 Microsoft Commerce Server Registry Permissions and Authentication Bypass Source: SREASON Type: UNKNOWN 594 Source: CCN Type: Microsoft Corporation Web site Commerce Server 2002 Service Pack 2 (SP2) - English Source: OSVDB Type: UNKNOWN 24121 Source: CCN Type: OSVDB ID: 24121 Microsoft Commerce Server 2002 authfiles/login.asp Authentication Bypass Source: BUGTRAQ Type: UNKNOWN 20060316 Microsoft Commerce Server 2002: Logon as known user with a false password Source: BID Type: Patch 17134 Source: CCN Type: BID-17134 Microsoft Commerce Server 2002 Authentication Bypass Vulnerability Source: XF Type: UNKNOWN mscs-authfiles-authentication-bypass(25330) Source: XF Type: UNKNOWN mscs-authfiles-authentication-bypass(25330) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |