Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:16114
HistoryFeb 19, 2007 - 12:00 a.m.

Powerschool 404 Admin Exposure

2007-02-1900:00:00
vulners.com
37

Powerschool 4.3.6 and possibly other versions expose the admin interface when requesting any file with .js

This allows one to see some directory and file names inside the admin folder.

POC:

http://[powerschoolip]/admin/.js

Product's website does not provide email contact?