5
CVSSv2

CVE-2007-1044

Published: 21/02/2007 Updated: 16/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Pearson Education PowerSchool 4.3.6 allows remote malicious users to list the contents of the admin folder via a URI composed of the admin/ directory name and an arbitrary filename ending in ".js." NOTE: it was later reported that this issue had been addressed by 5.1.2.

Vulnerable Product Search on Vulmon Subscribe to Product

pearson education powerschool 4.3.6

Exploits

source: wwwsecurityfocuscom/bid/22611/info Powerschool is prone to an information-disclosure vulnerability because the application discloses information about administrative session variables An attacker can exploit these issue to obtain sensitive information that may aid in other attacks This issue affects Powerschool 436; other ve ...