vendor:
NetDecision Traffic Grapher Server
by:
Prabhu S Angadi
7,5
CVSS
HIGH
Information Disclosure
200
CWE
Product Name: NetDecision Traffic Grapher Server
Affected Version From: NetDecision 4.5.1 (full package) Traffic Grapher Server version 4.5.1
Affected Version To: Older versions might be affected.
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3 & Win XP2
2011
Netmechanica NetDecision Traffic Grapher Server Information Disclosure Vulnerability
The vulnerability is caused due to improper validation of malicious HTTP GET request to Traffic Grapher Server 'default.nd' with invalid HTTP version number followed by multiple 'CRLF', which discloses the source code of 'default.nd'
Mitigation:
Upgrade to the latest version of Netmechanica NetDecision Traffic Grapher Server.