Powerschool 404 Admin Exposure

看板Bugtraq作者時間19年前 (2007/02/20 01:46), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/2 (看更多)
Powerschool 4.3.6 and possibly other versions expose the admin interface when requesting any file with .js This allows one to see some directory and file names inside the admin folder. POC: http://[powerschoolip]/admin/.js Product's website does not provide email contact?
文章代碼(AID): #15sU9S00 (Bugtraq)
文章代碼(AID): #15sU9S00 (Bugtraq)