Show filters
27 Total Results
Displaying 21-27 of 27
Sort by:
Attacker Value
Unknown
CVE-2005-4338
Disclosure Date: December 19, 2005 (last updated February 22, 2025)
announcement.pl in Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to gain administrator privileges by setting the context parameter to "admin".
0
Attacker Value
Unknown
CVE-2005-4206
Disclosure Date: December 13, 2005 (last updated February 22, 2025)
Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to redirect users to other URLs and conduct phishing attacks via a modified url parameter to frameset.jsp, which loads the URL into a frame and causes it to appear to be part of a valid page.
0
Attacker Value
Unknown
CVE-2004-1582
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
PHP remote file inclusion vulnerability in BlackBoard 1.5.1 allows remote attackers to execute arbitrary PHP code by modifying the libpath parameter (incorrectly called "libpach") to reference a URL on a remote web server that contains _more.php, as demonstrated using checkdb.inc.php.
0
Attacker Value
Unknown
CVE-2004-1581
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
BlackBoard 1.5.1 allows remote attackers to gain sensitive information via a direct request to (1) checkdb.inc.php, (2) admin.inc.php or (3) cp.inc.php, which reveals the path in a PHP error message.
0
Attacker Value
Unknown
CVE-2002-1007
Disclosure Date: October 04, 2002 (last updated February 22, 2025)
Cross-site scripting vulnerabilities in Blackboard 5 allow remote attackers to execute arbitrary web script via (1) the course_id parameter in a link to login.pl, (2) the CTID parameter in ProcessInfo.cgi, or (3) the Message parameter in index.cgi.
0
Attacker Value
Unknown
CVE-2000-0627
Disclosure Date: July 18, 2000 (last updated February 22, 2025)
BlackBoard CourseInfo 4.0 does not properly authenticate users, which allows local users to modify CourseInfo database information and gain privileges by directly calling the supporting CGI programs such as user_update_passwd.pl and user_update_admin.pl.
0
Attacker Value
Unknown
CVE-2000-0605
Disclosure Date: July 10, 2000 (last updated February 22, 2025)
Blackboard CourseInfo 4.0 stores the local and SQL administrator user names and passwords in cleartext in a registry key whose access control allows users to access the passwords.
0