Vulnerabilities > Sendio

DATE CVE VULNERABILITY TITLE RISK
2017-07-27 CVE-2016-10399 File and Directory Information Exposure vulnerability in Sendio 7.2.3
Sendio versions before 8.2.1 were affected by a Local File Inclusion vulnerability that allowed an unauthenticated, remote attacker to read potentially sensitive system files via a specially crafted URL.
network
low complexity
sendio CWE-538
5.0
2015-06-02 CVE-2014-8391 Information Exposure vulnerability in Sendio 7.2.3
The Web interface in Sendio before 7.2.4 does not properly handle sessions, which allows remote authenticated users to obtain sensitive information from other users' sessions via a large number of requests.
network
low complexity
sendio CWE-200
4.0
2015-06-02 CVE-2014-0999 Information Exposure vulnerability in Sendio 7.2.3
Sendio before 7.2.4 includes the session identifier in URLs in emails, which allows remote attackers to obtain sensitive information and hijack sessions by reading the jsessionid parameter in the Referrer HTTP header.
network
low complexity
sendio CWE-200
5.0