The sample files in the authfiles directory in Microsoft Commerce Server 2002 before SP2 allow remote attackers to bypass authentication by logging in to authfiles/login.asp with a valid username and any password, then going to the main site twice.
https://exchange.xforce.ibmcloud.com/vulnerabilities/25330
http://www.securityfocus.com/bid/17134
http://www.securityfocus.com/archive/1/427974/100/0/threaded