CVE-2007-1044 Information

Description

Pearson Education PowerSchool 4.3.6 allows remote attackers to list the contents of the admin folder via a URI composed of the admin/ directory name and an arbitrary filename ending in .js.\ NOTE: it was later reported that this issue had been addressed by 5.1.2.

Reference

http://osvdb.org/33741 http://securityreason.com/securityalert/2276 http://www.securityfocus.com/archive/1/460533/100/0/threaded http://www.securityfocus.com/archive/1/484569/100/200/threaded http://www.securityfocus.com/bid/22611 https://exchange.xforce.ibmcloud.com/vulnerabilities/32569

Share on: