Vulnerabilities > CVE-2005-4337 - Security Bypass vulnerability in Blackboard Academic Suite 6.2.3.23/6.3.1.424

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
blackboard

Summary

The login page in Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to bypass authentication and gain privileges as other users via a modified user_id parameter and a "/" in the encoded_pw parameter.

Vulnerable Configurations

Part Description Count
Application
Blackboard
3