CVE-2006-0511 Information

Description

LICENSE README.md cvefilelist cvelist nvdcve nvdpages.sh scripts test-CVE-2017-1882.markdown test-CVE-2017-18822.markdown tmpvendorlinks DISPUTED LICENSE README.md cvefilelist cvelist nvdcve nvdpages.sh scripts test-CVE-2017-1882.markdown test-CVE-2017-18822.markdown tmpvendorlinks Blackboard Academic Suite 6.0 and earlier does not properly clear session information when de-authenticating a user who is idle which allows subsequent users to log in as the previous user and gain privileges. NOTE: the vendor has disputed this issue saying that \This is a customer specific issue related to their Kerberos authentication single sign-on application and not a vulnerability in the Blackboard product.\

Reference

http://www.osvdb.org/28023 http://www.securityfocus.com/archive/1/423654/100/0/threaded http://www.securityfocus.com/archive/1/423686/100/0/threaded http://www.securityfocus.com/archive/1/423778/100/0/threaded http://www.securityfocus.com/bid/16438

Share on: