René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

108 lines
2.9 KiB
JSON

{
"id": "CVE-2014-0999",
"sourceIdentifier": "cve@mitre.org",
"published": "2015-06-02T14:59:00.067",
"lastModified": "2018-10-09T19:42:19.577",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Sendio before 7.2.4 includes the session identifier in URLs in emails, which allows remote attackers to obtain sensitive information and hijack sessions by reading the jsessionid parameter in the Referrer HTTP header."
},
{
"lang": "es",
"value": "Sendio anterior a 7.2.4 incluye el identificador de sesiones en las URLs en emails, lo que permite a atacantes remotos obtener informaci\u00f3n sensible y secuestrar sesiones mediante la lectura del par\u00e1metro jsessionid en la cabecera Referrer HTTP."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 5.0
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sendio:sendio:*:*:*:*:*:*:*:*",
"versionEndIncluding": "7.2.3",
"matchCriteriaId": "094086AE-DDCB-49FC-84C8-7A94CDC08CB9"
}
]
}
]
}
],
"references": [
{
"url": "http://packetstormsecurity.com/files/132022/Sendio-ESP-Information-Disclosure.html",
"source": "cve@mitre.org",
"tags": [
"Exploit"
]
},
{
"url": "http://seclists.org/fulldisclosure/2015/May/95",
"source": "cve@mitre.org",
"tags": [
"Exploit"
]
},
{
"url": "http://www.exploit-db.com/exploits/37114",
"source": "cve@mitre.org",
"tags": [
"Exploit"
]
},
{
"url": "http://www.securityfocus.com/archive/1/535592/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.sendio.com/software-release-history/",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
}
]
}