PT-2005-5025 · Blackboard · Blackboard Learning/Community Portal System

Published

2005-12-17

·

Updated

2008-09-05

·

CVE-2005-4337

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Blackboard Learning and Community Portal System versions prior to 6
Description The issue allows remote attackers to bypass authentication and gain privileges as other users. This is achieved via a modified user id parameter and a "/" in the encoded pw parameter in the login page.
Recommendations For versions prior to 6, consider restricting access to the login page until a fix is available. As a temporary workaround, avoid using the user id parameter in the affected login endpoint until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-4337

Affected Products

Blackboard Learning/Community Portal System