Blackboard Learning System search.pl SQL Injection Variant Vulnerability
BID:6687
Info
Blackboard Learning System search.pl SQL Injection Variant Vulnerability
| Bugtraq ID: | 6687 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 25 2003 12:00AM |
| Updated: | Jan 25 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to "Cory Michal" <[email protected]>. |
| Vulnerable: |
Blackboard Blackboard 5.5.1 Blackboard Blackboard 5.5 Blackboard Blackboard 5.0.2 Blackboard Blackboard 5.0 |
| Not Vulnerable: | |
Discussion
Blackboard Learning System search.pl SQL Injection Variant Vulnerability
Blackboard Learning System, in some cases, does not sufficiently sanitize user-supplied input which is used when constructing SQL queries. As a result, attackers may supply malicious parameters to manipulate the structure and logic of SQL queries.
This vulnerability was reported to exist in the search.pl script file. A remote attacker can exploit this vulnerability to discover the passwords of other users.
This vulnerability is a variant of the vulnerability described in BID 6655.
Blackboard Learning System, in some cases, does not sufficiently sanitize user-supplied input which is used when constructing SQL queries. As a result, attackers may supply malicious parameters to manipulate the structure and logic of SQL queries.
This vulnerability was reported to exist in the search.pl script file. A remote attacker can exploit this vulnerability to discover the passwords of other users.
This vulnerability is a variant of the vulnerability described in BID 6655.
Exploit / POC
Blackboard Learning System search.pl SQL Injection Variant Vulnerability
The following exploits were provided:
The following exploits were provided:
Solution / Fix
Blackboard Learning System search.pl SQL Injection Variant Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Blackboard Learning System search.pl SQL Injection Variant Vulnerability
References:
References:
- Blackboard Homepage (Blackboard)
- Blackboard 5.x & patched 5.x systems Password Retrieval ("Cory Michal"
)