
CVE-2022-1844 – WP Sentry <= 1.0 - Arbitrary Settings Update to Stored XSS via CSRF
https://notcve.org/view.php?id=CVE-2022-1844
31 May 2022 — The WP Sentry WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping as well El plugin WP Sentry de WordPress versiones hasta 1.0, no presenta comprobación de CSRF cuando es actualizada su configuración, lo que podría permitir a atacantes hacer que un administrador conectado los cambie por medio de un ataq... • https://wpscan.com/vulnerability/f0b0baac-7f44-44e1-af73-5a72b967858d • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2008-1321 – asg-sentry 7.0.0 - Multiple Vulnerabilities
https://notcve.org/view.php?id=CVE-2008-1321
13 Mar 2008 — The FxIAList service in ASG-Sentry Network Manager 7.0.0 and earlier does require authentication, which allows remote attackers to cause a denial of service (service termination) via the exit command to TCP port 6162, or have other impacts via other commands. El servicio FxIAList de ASG-Sentry Network Manager versión 7.0.0 y anteriores implementa mecanismo de autenticación que permite a atacantes remotos provocar una denegación de servicio (finalización del servicio) mediante la utilización del comando exit... • https://www.exploit-db.com/exploits/5229 • CWE-287: Improper Authentication •

CVE-2008-1322 – asg-sentry 7.0.0 - Multiple Vulnerabilities
https://notcve.org/view.php?id=CVE-2008-1322
13 Mar 2008 — The File Check Utility (fcheck.exe) in ASG-Sentry Network Manager 7.0.0 and earlier allows remote attackers to cause a denial of service (CPU consumption) or overwrite arbitrary files via a query string that specifies the -b option, probably due to an argument injection vulnerability. La utilidad de evaluación de ficheros (fcheck.exe) en ASG-Sentry Network Manager versión 7.0.0 y anteriores permite a atacantes remotos provocar una denegación de servicio (consumo de CPU) o sobreescribir ficheros de su elecci... • https://www.exploit-db.com/exploits/5229 •