← Back

Evilsentinel

evilsentinel

Vendor: Evilsentinel • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Evilsentinel
1Evilsentinel
Apr 23, 2026
Jan 18, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
admin/config.php in Evilsentinel 1.0.9 and earlier allows remote attackers to bypass the CAPTCHA test by omitting the es_security_captcha parameter and not invoking captcha.php.
1Evilsentinel
1Evilsentinel
Apr 23, 2026
Jan 18, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
admin/index.php in Evilsentinel 1.0.9 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to gain administrative privileges and make arbitrary configuration changes.