CVE-2008-1795

Blackboard Academic Suite <8.0 - XSS

Title source: llm
STIX 2.1

Description

Multiple cross-site scripting (XSS) vulnerabilities in Blackboard Academic Suite 7.x and earlier, and possibly some 8.0 versions, allow remote attackers to inject arbitrary web script or HTML via (1) the searchText parameter in a Course action to webapps/blackboard/execute/viewCatalog or (2) the data__announcements___pk1_pk2__subject parameter in an ADD action to bin/common/announcement.pl.

Exploits (2)

exploitdb WRITEUP VERIFIED
by Knight4vn · textwebappscgi
https://www.exploit-db.com/exploits/31537
exploitdb WORKING POC VERIFIED
by Knight4vn · textwebappscgi
https://www.exploit-db.com/exploits/31538

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1019710
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3810
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29543
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/490096/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/28455
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/41478

Scores

EPSS 0.1091
EPSS Percentile 93.5%

Details

CWE
CWE-79
Status published
Products (1)
blackboard/academic_suite < 7
Published Apr 15, 2008
Tracked Since Feb 18, 2026