Heap
18-01-08, 17:46
admin/config.php in Evilsentinel 1.0.9 and earlier allows remote attackers to bypass the CAPTCHA test by omitting the es_security_captcha parameter and not invoking captcha.php.
More... (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0351)
More... (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0351)