CVE-2006-1257
15Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 30%
exploitation probability
30%top 2% of all CVEs
observed exploitation
nono source reports it
The sample files in the authfiles directory in Microsoft Commerce Server 2002 before SP2 allow remote attackers to bypass authentication by logging in to authfiles/login.asp with a valid username and any password, then going to the main site twice.
Affected products
n/a · n/aReferences
http://msdn.microsoft.com/library/default.asp?url=/library/en-us/csvr2002/htm/cs_se_securityconcepts_cbgw.asphttp://securityreason.com/securityalert/594https://exchange.xforce.ibmcloud.com/vulnerabilities/25330http://www.osvdb.org/24121http://www.securityfocus.com/archive/1/427974/100/0/threadedhttp://www.securityfocus.com/bid/17134