Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.802704
Category:Web Servers
Title:Netmechanica NetDecision Traffic Grapher Server Information Disclosure Vulnerability
Summary:NetDecision Traffic Grapher Server is prone to an information disclosure vulnerability.
Description:Summary:
NetDecision Traffic Grapher Server is prone to an information disclosure vulnerability.

Vulnerability Insight:
The flaw is due to an improper validation of malicious HTTP GET
request to 'default.nd' with invalid HTTP version number followed by multiple
'CRLF', which discloses the source code of 'default.nd'.

Vulnerability Impact:
Successful exploitation will allow attackers to gain sensitive information.

Affected Software/OS:
NetDecision Traffic Grapher Server version 4.5.1

Solution:
Upgrade to Traffic Grapher Server 4.6.1 or later.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2012-1466
BugTraq ID: 52196
http://www.securityfocus.com/bid/52196
http://www.exploit-db.com/exploits/18542
http://secpod.org/advisories/SecPod_Netmechanica_NetDecision_Traffic_Grapher_Server_SourceCode_Disc_Vuln.txt
http://secpod.org/blog/?p=481
http://osvdb.org/79652
http://secunia.com/advisories/48168
XForce ISS Database: netdecision-traffic-nd-source-disclosure(73531)
https://exchange.xforce.ibmcloud.com/vulnerabilities/73531
CopyrightCopyright (C) 2012 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.