Lucene search

K
exploitdbGheetotankEDB-ID:29615
HistoryFeb 19, 2007 - 12:00 a.m.

Powerschool 4.3.6/5.1.2 - JavaScript File Request Information Disclosure

2007-02-1900:00:00
gheetotank
www.exploit-db.com
16

AI Score

7.4

Confidence

Low

source: https://www.securityfocus.com/bid/22611/info

Powerschool is prone to an information-disclosure vulnerability because the application discloses information about administrative session variables.

An attacker can exploit these issue to obtain sensitive information that may aid in other attacks.

This issue affects Powerschool 4.3.6; other versions may also be affected.

UPDATE: Powerschool 5.1.2 is also reportedly affected by this issue, in a limited fashion.

http://www.example.com/admin/.js

AI Score

7.4

Confidence

Low

Related for EDB-ID:29615