Lucene search

K
cveMitreCVE-2005-4206
HistoryDec 13, 2005 - 11:03 a.m.

CVE-2005-4206

2005-12-1311:03:00
CWE-601
mitre
web.nvd.nist.gov
26
blackboard learning
community portal
academic suite
phishing
remote attack
url redirection
cve-2005-4206

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

6.9

Confidence

Low

EPSS

0.026

Percentile

90.3%

Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to redirect users to other URLs and conduct phishing attacks via a modified url parameter to frameset.jsp, which loads the URL into a frame and causes it to appear to be part of a valid page.

Affected configurations

Nvd
Node
blackboardacademic_suiteRange6.0.0.0
OR
blackboardacademic_suiteMatch6.2.3.23
OR
blackboardacademic_suiteMatch6.3.1.424
VendorProductVersionCPE
blackboardacademic_suite*cpe:2.3:a:blackboard:academic_suite:*:*:*:*:*:*:*:*
blackboardacademic_suite6.2.3.23cpe:2.3:a:blackboard:academic_suite:6.2.3.23:*:*:*:*:*:*:*
blackboardacademic_suite6.3.1.424cpe:2.3:a:blackboard:academic_suite:6.3.1.424:*:*:*:*:*:*:*

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

6.9

Confidence

Low

EPSS

0.026

Percentile

90.3%

Related for CVE-2005-4206