Show filters
251 Total Results
Displaying 221-230 of 251
Sort by:
Attacker Value
Unknown
CVE-2007-1039
Disclosure Date: February 21, 2007 (last updated October 04, 2023)
Unspecified vulnerability in Peanut Knowledge Base (PeanutKB) 0.0.3 and earlier has unknown impact and attack vectors.
0
Attacker Value
Unknown
CVE-2006-5775
Disclosure Date: November 06, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in profile.php in FunkBoard 0.71 before 4 November 2006 at 18:16 GMT allows remote attackers to inject arbitrary web script or HTML, possibly via the name parameter.
0
Attacker Value
Unknown
CVE-2006-4308
Disclosure Date: August 23, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Blackboard Learning System 6, Blackboard Learning and Community Portal Suite 6.2.3.23, and Blackboard Vista 4 allow remote attackers to inject arbitrary Javascript, VBScript, or HTML via (1) data, (2) vbscript, and (3) malformed javascript URIs in various HTML tags when posting to the Discussion Board.
0
Attacker Value
Unknown
CVE-2006-3914
Disclosure Date: July 28, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Blackboard Academic Suite 6.2.3.23 allows remote authenticated users to inject arbitrary HTML or web script by bypassing client-side validation through disabling JavaScript when submitting an essay response, which has no server-side validation before being viewed via "View Attempt Details" in the Gradebook.
0
Attacker Value
Unknown
CVE-2006-3040
Disclosure Date: June 15, 2006 (last updated November 08, 2023)
PHP remote file inclusion vulnerability in talkbox.php in Amr Talkbox allows remote attackers to execute arbitrary PHP code via a URL in the direct parameter. NOTE: this issue has been disputed by CVE, since the $direct variable is set to a static value just before the include statement
0
Attacker Value
Unknown
CVE-2006-2896
Disclosure Date: June 07, 2006 (last updated October 04, 2023)
profile.php in FunkBoard CF0.71 allows remote attackers to change arbitrary passwords via a modified uid hidden form field in an Edit Profile action.
0
Attacker Value
Unknown
CVE-2006-2897
Disclosure Date: June 07, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in FunkBoard 0.71 allows remote attackers to inject arbitrary HTML or web script via unspecified vectors.
0
Attacker Value
Unknown
CVE-2006-0511
Disclosure Date: February 01, 2006 (last updated February 22, 2025)
Blackboard Academic Suite 6.0 and earlier does not properly clear session information when de-authenticating a user who is idle, which allows subsequent users to log in as the previous user and gain privileges. NOTE: the vendor has disputed this issue, saying that "This is a customer specific issue related to their Kerberos authentication single sign-on application and not a vulnerability in the Blackboard product.
0
Attacker Value
Unknown
CVE-2005-4341
Disclosure Date: December 19, 2005 (last updated February 22, 2025)
Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to list all available categories via a blank category_id parameter to category.pl. NOTE: it is not clear whether this information is sensitive or not, so this might not be an exposure.
0
Attacker Value
Unknown
CVE-2005-4337
Disclosure Date: December 19, 2005 (last updated February 22, 2025)
The login page in Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to bypass authentication and gain privileges as other users via a modified user_id parameter and a "/" in the encoded_pw parameter.
0