CVE Vulnerabilities

CVE-2005-4337

Published: Dec 19, 2005 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The login page in Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to bypass authentication and gain privileges as other users via a modified user_id parameter and a / in the encoded_pw parameter.

Affected Software

Name Vendor Start Version End Version
Academic_suite Blackboard * *
Academic_suite Blackboard 6.2.3.23 (including) 6.2.3.23 (including)
Academic_suite Blackboard 6.3.1.424 (including) 6.3.1.424 (including)

References