CVE-2014-8391

Sendio < 7.2.3 - Authenticated Session Information Exposure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-8391. PoCs published by Core Security.

AI-analyzed exploit summary The exploit demonstrates an information disclosure vulnerability in Sendio ESP, where session identifiers are exposed in URLs and sensitive data can be leaked due to improper session handling. The provided Python script automates the detection of response mixup issues by comparing content lengths.

Description

The Web interface in Sendio before 7.2.4 does not properly handle sessions, which allows remote authenticated users to obtain sensitive information from other users' sessions via a large number of requests.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Core Security · textwebappsjsp
https://www.exploit-db.com/exploits/37114

The exploit demonstrates an information disclosure vulnerability in Sendio ESP, where session identifiers are exposed in URLs and sensitive data can be leaked due to improper session handling. The provided Python script automates the detection of response mixup issues by comparing content lengths.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Sendio ESP 6 (14.1120.0)
Auth required
Prerequisites: Valid session identifier (jsessionid) · Access to the target Sendio ESP web interface
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Exploit mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2015/May/95
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/535592/100/0/threaded
Exploit exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/37114/
Vendor Advisory x_refsource_confirm
http://www.sendio.com/software-release-history/

Scores

EPSS 0.0546
EPSS Percentile 91.7%

Details

CWE
CWE-200
Status published
Products (1)
sendio/sendio < 7.2.3
Published Jun 02, 2015
Tracked Since Feb 18, 2026