MEDIUM · 5.0

CVE-2012-1466

The Traffic Grapher Server for NetMechanica NetDecision before 4.6.1 allows remote attackers to obtain the source code of NtDecision script files with a .nd extension via an invalid version number in ...

Vulnerability Description

The Traffic Grapher Server for NetMechanica NetDecision before 4.6.1 allows remote attackers to obtain the source code of NtDecision script files with a .nd extension via an invalid version number in an HTTP request, as demonstrated using default.nd. NOTE: some of these details are obtained from third party information.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
NetmechanicaNetdecision<= 4.5.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-1466?

CVE-2012-1466 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The Traffic Grapher Server for NetMechanica NetDecision before 4.6.1 allows remote attackers to obtain the source code of NtDecision script files with a .nd extension via an invalid version number in ...

How severe is CVE-2012-1466?

CVE-2012-1466 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-1466?

Check the references section above for vendor advisories and patch information. Affected products include: Netmechanica Netdecision.