CVE-2008-1795
- EPSS 10.91%
- Veröffentlicht 15.04.2008 17:05:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple cross-site scripting (XSS) vulnerabilities in Blackboard Academic Suite 7.x and earlier, and possibly some 8.0 versions, allow remote attackers to inject arbitrary web script or HTML via (1) the searchText parameter in a Course action to web...
CVE-2005-4337
- EPSS 0.68%
- Veröffentlicht 19.12.2005 03:47:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The login page in Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to bypass authentication and gain privileges as other users via a modified user_id parameter ...
- EPSS 1.21%
- Veröffentlicht 19.12.2005 03:47:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
announcement.pl in Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to gain administrator privileges by setting the context parameter to "admin".
CVE-2005-4339
- EPSS 0.3%
- Veröffentlicht 19.12.2005 03:47:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Cross-site scripting (XSS) vulnerability in Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to inject arbitrary web script or HTML via the context parameter to...
- EPSS 0.35%
- Veröffentlicht 19.12.2005 03:47:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to list all available categories via a blank category_id parameter to category.pl. NOTE: it is not clear wheth...
CVE-2005-4206
- EPSS 5.94%
- Veröffentlicht 13.12.2005 11:03:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to redirect users to other URLs and conduct phishing attacks via a modified url parameter to frameset.jsp, whic...