The Traffic Grapher Server for NetMechanica NetDecision prior to 4.6.1 allows remote malicious users to obtain the source code of NtDecision script files with a .nd extension via an invalid version number in an HTTP request, as demonstrated using default.nd. NOTE: some of these details are obtained from third party information.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
netmechanica netdecision |