vendor:
NetDecision Dashboard Server
by:
Prabhu S Angadi
5,5
CVSS
MEDIUM
Information Disclosure
200
CWE
Product Name: NetDecision Dashboard Server
Affected Version From: Netmechanica NetDecision 4.5.1
Affected Version To: Netmechanica NetDecision 4.5.1
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3 & Win XP2
2011
Netmechanica NetDecision Dashboard Server Information Disclosure Vulnerability
The vulnerability is caused due to improper validation of malicious HTTP request to Dashboard server appended with '?' character, which discloses the Dashboard server's web script physical path.
Mitigation:
Upgrade to the latest version of Netmechanica NetDecision 4.5.2