The Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 allows remote authenticated users to obtain access to arbitrary user accounts via a crafted username, aka "ASP.Net Forms Authentication Bypass Vulnerability."
References
Configurations
Configuration 1 (hide)
|
History
07 Dec 2023, 18:38
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:* |
Information
Published : 2011-12-30 01:55
Updated : 2024-02-04 17:54
NVD link : CVE-2011-3416
Mitre link : CVE-2011-3416
CVE.ORG link : CVE-2011-3416
JSON object : View
Products Affected
microsoft
- windows_7
- windows_xp
- windows_server_2008
- windows_vista
- windows_server_2003
CWE
CWE-264
Permissions, Privileges, and Access Controls