orderdetails.aspx, as made available to Microsoft .NET developers as example code and demonstrated on www.ibuyspystore.com, allows remote attackers to view the orders of other users by modifying the OrderID parameter.
| Software | From | Fixed in |
|---|---|---|
| microsoft / .net_framework | 1.0 | 1.0.x |