Powerschool 404 Admin Exposure

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Powerschool 4.3.6 and possibly other versions expose the admin interface when requesting any file with .js

This allows one to see some directory and file names inside the admin folder.

POC:

http://[powerschoolip]/admin/.js

Product's website does not provide email contact? 

[Index of Archives]     [Linux Security]     [Netfilter]     [PHP]     [Yosemite News]     [Linux Kernel]

  Powered by Linux