CVE-2014-0999
Estado: ModificadaMedia (5)—💥 Exploit
Sendio before 7.2.4 includes the session identifier in URLs in emails, which allows remote attackers to obtain sensitive information and hijack sessions by reading the jsessionid parameter in the Referrer HTTP header.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N
- Puntuación base: 5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 6.60%
- Percentil entre todas las CVEs puntuadas: 94
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
💥 Exploits públicos
Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.
- Publicado en Exploit-DB · Sendio ESP - Information Disclosure (26/5/2015)
Tecnologías afectadas (1)
CWE
- CWE-200
Referencias
- http://packetstormsecurity.com/files/132022/Sendio-ESP-Information-Disclosure.html
- http://seclists.org/fulldisclosure/2015/May/95
- http://www.exploit-db.com/exploits/37114
- http://www.securityfocus.com/archive/1/535592/100/0/threaded
- http://www.sendio.com/software-release-history/
- http://packetstormsecurity.com/files/132022/Sendio-ESP-Information-Disclosure.html
- http://seclists.org/fulldisclosure/2015/May/95
- http://www.exploit-db.com/exploits/37114
- http://www.securityfocus.com/archive/1/535592/100/0/threaded
- http://www.sendio.com/software-release-history/
JSON original (NVD)
Mostrar
{
"id": "CVE-2014-0999",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2015-06-02T14:59:00.067",
"references": [
{
"url": "http://packetstormsecurity.com/files/132022/Sendio-ESP-Information-Disclosure.html",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://seclists.org/fulldisclosure/2015/May/95",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.exploit-db.com/exploits/37114",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/535592/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.sendio.com/software-release-history/",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://packetstormsecurity.com/files/132022/Sendio-ESP-Information-Disclosure.html",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://seclists.org/fulldisclosure/2015/May/95",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.exploit-db.com/exploits/37114",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/535592/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.sendio.com/software-release-history/",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Sendio before 7.2.4 includes the session identifier in URLs in emails, which allows remote attackers to obtain sensitive information and hijack sessions by reading the jsessionid parameter in the Referrer HTTP header."
},
{
"lang": "es",
"value": "Sendio anterior a 7.2.4 incluye el identificador de sesiones en las URLs en emails, lo que permite a atacantes remotos obtener información sensible y secuestrar sesiones mediante la lectura del parámetro jsessionid en la cabecera Referrer HTTP."
}
],
"lastModified": "2026-06-17T00:03:59.550",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sendio:sendio:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "094086AE-DDCB-49FC-84C8-7A94CDC08CB9",
"versionEndIncluding": "7.2.3"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}