The login page in Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to bypass authentication and gain privileges as other users via a modified user_id parameter and a "/" in the encoded_pw parameter.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2005-12-17T21:00:00Z

Updated: 2024-09-16T19:30:21.863Z

Reserved: 2005-12-17T00:00:00Z

Link: CVE-2005-4337

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2005-12-19T03:47:00.000

Modified: 2008-09-05T20:56:38.177

Link: CVE-2005-4337

cve-icon Redhat

No data.