CVE-2006-4308

Blackboard - XSS

Title source: rule

Description

Multiple cross-site scripting (XSS) vulnerabilities in Blackboard Learning System 6, Blackboard Learning and Community Portal Suite 6.2.3.23, and Blackboard Vista 4 allow remote attackers to inject arbitrary Javascript, VBScript, or HTML via (1) data, (2) vbscript, and (3) malformed javascript URIs in various HTML tags when posting to the Discussion Board.

Exploits (1)

exploitdb WORKING POC VERIFIED
by proton · textwebappsphp
https://www.exploit-db.com/exploits/28324

Scores

EPSS 0.0096
EPSS Percentile 76.3%

Classification

CWE
CWE-79
Status draft

Affected Products (4)

blackboard/blackboard
blackboard/blackboard_learning_and_community_portal_suite
blackboard/blackboard_learning_and_community_portal_suite
blackboard/vista

Timeline

Published Aug 23, 2006
Tracked Since Feb 18, 2026