CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:N/C:N/I:P/A:N
AI Score
Confidence
High
EPSS
Percentile
83.3%
Multiple cross-site scripting (XSS) vulnerabilities in Blackboard Learning System 6, Blackboard Learning and Community Portal Suite 6.2.3.23, and Blackboard Vista 4 allow remote attackers to inject arbitrary Javascript, VBScript, or HTML via (1) data, (2) vbscript, and (3) malformed javascript URIs in various HTML tags when posting to the Discussion Board.
Vendor | Product | Version | CPE |
---|---|---|---|
blackboard | blackboard | 6.0 | cpe:2.3:a:blackboard:blackboard:6.0:*:*:*:*:*:*:* |
blackboard | blackboard_learning_and_community_portal_suite | 6.0 | cpe:2.3:a:blackboard:blackboard_learning_and_community_portal_suite:6.0:*:*:*:*:*:*:* |
blackboard | blackboard_learning_and_community_portal_suite | 6.2.3.23 | cpe:2.3:a:blackboard:blackboard_learning_and_community_portal_suite:6.2.3.23:*:*:*:*:*:*:* |
blackboard | vista | 4 | cpe:2.3:a:blackboard:vista:4:*:*:*:*:*:*:* |
secunia.com/advisories/21577
securitytracker.com/id?1016735
www.securityfocus.com/archive/1/444062/100/0/threaded
www.securityfocus.com/archive/1/444116/100/0/threaded
www.securityfocus.com/archive/1/444885/100/0/threaded
www.securityfocus.com/bid/19308
www.vupen.com/english/advisories/2006/3366
exchange.xforce.ibmcloud.com/vulnerabilities/28537