CVE

Id
4801  
CVE No.
CVE-2002-0409  
Status
Candidate  
Description
orderdetails.aspx, as made available to Microsoft .NET developers as example code and demonstrated on www.ibuyspystore.com, allows remote attackers to view the orders of other users by modifying the OrderID parameter.  
Phase
Proposed (20020611)  
Votes
ACCEPT(2) Alderson, Wall | NOOP(3) Cole, Cox, Foat | REVIEWING(1) Frech  
Comments
Alderson> This is a whole new breed of exposure... vulnerable example code | leading to cross industry and application exposure. This to a point made by | Gene Kim recently "they keep deploying problems faster than we can deploy | solutions".