Vulnerabilities
6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-9307 | SSRF vulnerability in remotedownload.php in Allen Disk 1.6 allows remote authenticated users to conduct port scans and access intranet servers via a crafted fil SSRF vulnerability in remotedownload.php in Allen Disk 1.6 allows remote authenticated users to conduct port scans and access intranet servers via a crafted file parameter. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2017-9249 | Cross-site scripting (XSS) vulnerability in Allen Disk 1.6 allows remote authenticated users to inject arbitrary web script or HTML persistently by uploading a Cross-site scripting (XSS) vulnerability in Allen Disk 1.6 allows remote authenticated users to inject arbitrary web script or HTML persistently by uploading a crafted HTML file. The attack vector is the content of this file, and the filename must be specified in the PATH_INFO to readfile.php. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2017-9091 +1 in the same advisory: …9090 | /admin/loginc.php in Allen Disk 1.6 doesn't check if isset($_SESSION['captcha']['code']) == 1, which leads to CAPTCHA bypass by emptying $_POST['captcha']. /admin/loginc.php in Allen Disk 1.6 doesn't check if isset($_SESSION['captcha']['code']) == 1, which leads to CAPTCHA bypass by emptying $_POST['captcha']. NVD description · AI analysis pending | 7.5 | 1% |
| — | ||
| CVE-2017-8848 +1 in the same advisory: …8832 | Allen Disk 1.6 has CSRF in setpass.php with an impact of changing a password. Allen Disk 1.6 has CSRF in setpass.php with an impact of changing a password. NVD description · AI analysis pending | 6.5 group max | <1% |
| — |