Page 6 of 26 results (0.004 seconds)

CVSS: 5.0EPSS: 94%CPEs: 1EXPL: 0

orderdetails.aspx, as made available to Microsoft .NET developers as example code and demonstrated on www.ibuyspystore.com, allows remote attackers to view the orders of other users by modifying the OrderID parameter. • http://marc.info/?l=bugtraq&m=101518860823788&w=2 •