[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Powerschool 404 Admin Exposure
- To: bugtraq@xxxxxxxxxxxxxxxxx
- Subject: Powerschool 404 Admin Exposure
- From: gheetotank@xxxxxxxxxxx
- Date: 19 Feb 2007 05:06:38 -0000
Powerschool 4.3.6 and possibly other versions expose the admin interface when
requesting any file with .js
This allows one to see some directory and file names inside the admin folder.
POC:
http://[powerschoolip]/admin/.js
Product's website does not provide email contact?