Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.105293
Category:Web application abuses
Title:Sendio ESP Multiple Information Disclosure Vulnerabilities
Summary:Sendio is prone to multiple information disclosure vulnerabilities
Description:Summary:
Sendio is prone to multiple information disclosure vulnerabilities

Vulnerability Insight:
Sendio before 7.2.4 includes the session identifier in URLs in emails, which allows remote attackers to obtain sensitive information and hijack
sessions by reading the jsessionid parameter in the Referrer HTTP header.

Affected Software/OS:
Sendio before 7.2.4

Solution:
Updates are available

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2014-0999
Bugtraq: 20150522 [CORE-2015-0010] - Sendio ESP Information Disclosure Vulnerability (Google Search)
http://www.securityfocus.com/archive/1/535592/100/0/threaded
http://www.exploit-db.com/exploits/37114
http://seclists.org/fulldisclosure/2015/May/95
http://packetstormsecurity.com/files/132022/Sendio-ESP-Information-Disclosure.html
Common Vulnerability Exposure (CVE) ID: CVE-2014-8391
https://www.exploit-db.com/exploits/37114/
CopyrightCopyright (C) 2015 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.