CVE-2008-1883
The server in Blackboard Academic Suite 7.x stores MD5 password hashes that are provided directly by clients, which makes it easier for remote attackers to access accounts via a modified client that skips the javascript/md5.js hash calculation, and…
Does this matter?
Lower severity and a low EPSS score (1.26%). Track it; it rarely justifies an emergency change on its own.
Description
The server in Blackboard Academic Suite 7.x stores MD5 password hashes that are provided directly by clients, which makes it easier for remote attackers to access accounts via a modified client that skips the javascript/md5.js hash calculation, and instead sends an arbitrary MD5 string.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.26% probability · 68th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- blackboard/blackboard academic suite
- Source
- cve@mitre.org
References
- http://secskill.wordpress.com/2008/03/27/hacking-blackboard-academic-suite-2/Exploit
- http://securityreason.com/securityalert/3810
- http://www.scribd.com/doc/2363025/Hacking-Blackboard-Academic-SuiteExploit
- http://www.securityfocus.com/archive/1/490096/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41935
- http://secskill.wordpress.com/2008/03/27/hacking-blackboard-academic-suite-2/Exploit
- http://securityreason.com/securityalert/3810
- http://www.scribd.com/doc/2363025/Hacking-Blackboard-Academic-SuiteExploit
- http://www.securityfocus.com/archive/1/490096/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41935
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.