PT-2005-5028 · Blackboard · Blackboard Learning/Community Portal System

Publicado

2005-12-17

·

Atualizado

2008-09-05

·

CVE-2005-4341

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Blackboard Learning and Community Portal System versions prior to 6.3.1.424
Description The issue allows remote attackers to list all available categories by providing a blank category id parameter to the "category.pl" endpoint. It is unclear whether the exposed information is sensitive.
Recommendations For versions prior to 6.3.1.424, as a temporary workaround, consider restricting access to the "category.pl" endpoint until a fix is available. Avoid using a blank category id parameter in the affected endpoint to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-4341

Produtos afetados

Blackboard Learning/Community Portal System