sendio kayıtları
sendio üreticisine ait 3 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-538 Insertion of Sensitive Information into Externally-Accessible File or Directory1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
3 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
30İzleyin | CVE-2016-10399İstismar yok | Sendio versions before 8.2.1 were affected by a Local File Inclusion vulnerability that allowed an unauthenticated, remote attacker to read sendio · sendio · CWE-538 | Yüksek7,5 | — | %1,4 | 27 Tem 2017 |
22İzleyin | CVE-2014-0999Kavram kanıtı | Sendio before 7.2.4 includes the session identifier in URLs in emails, which allows remote attackers to obtain sensitive information and hijsendio · sendio · CWE-200 | Orta5,0 | — | %6,6 | 2 Haz 2015 |
18İzleyin | CVE-2014-8391Kavram kanıtı | The Web interface in Sendio before 7.2.4 does not properly handle sessions, which allows remote authenticated users to obtain sensitive infosendio · sendio · CWE-200 | Orta4,0 | — | %5,4 | 2 Haz 2015 |
- CVE-2016-1039930İzleyin
Sendio versions before 8.2.1 were affected by a Local File Inclusion vulnerability that allowed an unauthenticated, remote attacker to read
YüksekCVSS 7,5İstismar yokEPSS %1sendio · sendio27 Tem 2017
- CVE-2014-099922İzleyin
Sendio before 7.2.4 includes the session identifier in URLs in emails, which allows remote attackers to obtain sensitive information and hij
OrtaCVSS 5,0Kavram kanıtıEPSS %7sendio · sendio2 Haz 2015
- CVE-2014-839118İzleyin
The Web interface in Sendio before 7.2.4 does not properly handle sessions, which allows remote authenticated users to obtain sensitive info
OrtaCVSS 4,0Kavram kanıtıEPSS %5sendio · sendio2 Haz 2015