CVE-2002-1007
Blackboard 5 - Cross-Site Scripting via Multiple Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2002-1007. PoCs published by Berend-Jan Wever.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Blackboard's login.pl script due to insufficient sanitization of HTML tags in CGI parameters. The PoC provides a malicious URL that, when visited, executes arbitrary JavaScript in the victim's browser.
Description
Cross-site scripting vulnerabilities in Blackboard 5 allow remote attackers to execute arbitrary web script via (1) the course_id parameter in a link to login.pl, (2) the CTID parameter in ProcessInfo.cgi, or (3) the Message parameter in index.cgi.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Blackboard's login.pl script due to insufficient sanitization of HTML tags in CGI parameters. The PoC provides a malicious URL that, when visited, executes arbitrary JavaScript in the victim's browser.