Blackboard Products Multiple HTML Injection Vulnerabilities
BID:19308
CVE-2006-4308 |Info
Blackboard Products Multiple HTML Injection Vulnerabilities
| Bugtraq ID: | 19308 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-4308 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 24 2006 12:00AM |
| Updated: | Jun 14 2007 11:19PM |
| Credit: | PrOtOn & digi7al64 are credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Blackboard Blackboard Learning and Community Portal Suite 6.0 Blackboard Blackboard Learning and Community Portal Suite 6.2.3.23 Blackboard Blackboard Academic Suite Vista 4 Blackboard Blackboard 6.0 |
| Not Vulnerable: | |
Discussion
Blackboard Products Multiple HTML Injection Vulnerabilities
Blackboard products are prone to multiple HTML-injection vulnerabilities because the software fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would execute in the context of the affected website, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
Blackboard Learning System (Release 6) and Blackboard Learning and Community Portal Suite (Release 6 build 6.2.3.23) are vulnerable; other version may also be affected.
Reports indicate this issue has been addressed in versions 7.0 and 7.1, but Symantec has not confirmed this.
UPDATE (June 14, 2007): Reports indicate that Blackboard Academic Suite - Vista 4 is also vulnerable.
Blackboard products are prone to multiple HTML-injection vulnerabilities because the software fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would execute in the context of the affected website, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
Blackboard Learning System (Release 6) and Blackboard Learning and Community Portal Suite (Release 6 build 6.2.3.23) are vulnerable; other version may also be affected.
Reports indicate this issue has been addressed in versions 7.0 and 7.1, but Symantec has not confirmed this.
UPDATE (June 14, 2007): Reports indicate that Blackboard Academic Suite - Vista 4 is also vulnerable.
Exploit / POC
Blackboard Products Multiple HTML Injection Vulnerabilities
Attackers can use a browser to exploit this issue.
HTML-injection examples have been provided:
Attackers can use a browser to exploit this issue.
HTML-injection examples have been provided:
Solution / Fix
Blackboard Products Multiple HTML Injection Vulnerabilities
Solution:
Reports indicate that this issue may have been addressed in versions 7.0 and 7.1, but Symantec has not confirmed this.
Please contact the vendor for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Reports indicate that this issue may have been addressed in versions 7.0 and 7.1, but Symantec has not confirmed this.
Please contact the vendor for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
Blackboard Products Multiple HTML Injection Vulnerabilities
References:
References:
- Blackboard Academic Suite Web Site (Blackboard Academic Suite)
- BlackBoard Multiple Vulnerabilities (XSS) (Pr070n)