The Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 allows remote authenticated users to obtain access to arbitrary user accounts via a crafted username, aka "ASP.Net Forms Authentication Bypass Vulnerability."
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2011-12-29 17:55
Updated : 2020-09-28 05:58
NVD link : CVE-2011-3416
Mitre link : CVE-2011-3416
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
microsoft
- windows_7
- windows_vista
- windows_xp
- windows_server_2008
- windows_server_2003