ZeroHour

Vulnerabilities

6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-9307
SSRF vulnerability in remotedownload.php in Allen Disk 1.6 allows remote authenticated users to conduct port scans and access intranet servers via a crafted fil

SSRF vulnerability in remotedownload.php in Allen Disk 1.6 allows remote authenticated users to conduct port scans and access intranet servers via a crafted file parameter.

NVD description · AI analysis pending
6.5<1%
  • allen disk project allen disk
CVE-2017-9249
Cross-site scripting (XSS) vulnerability in Allen Disk 1.6 allows remote authenticated users to inject arbitrary web script or HTML persistently by uploading a

Cross-site scripting (XSS) vulnerability in Allen Disk 1.6 allows remote authenticated users to inject arbitrary web script or HTML persistently by uploading a crafted HTML file. The attack vector is the content of this file, and the filename must be specified in the PATH_INFO to readfile.php.

NVD description · AI analysis pending
5.4<1% PoC
  • allen disk project allen disk
CVE-2017-9091
+1 in the same advisory: …9090
/admin/loginc.php in Allen Disk 1.6 doesn't check if isset($_SESSION['captcha']['code']) == 1, which leads to CAPTCHA bypass by emptying $_POST['captcha'].

/admin/loginc.php in Allen Disk 1.6 doesn't check if isset($_SESSION['captcha']['code']) == 1, which leads to CAPTCHA bypass by emptying $_POST['captcha'].

NVD description · AI analysis pending
7.51%
  • allen disk project allen disk
CVE-2017-8848
+1 in the same advisory: …8832
Allen Disk 1.6 has CSRF in setpass.php with an impact of changing a password.

Allen Disk 1.6 has CSRF in setpass.php with an impact of changing a password.

NVD description · AI analysis pending
6.5
group max
<1%
  • allen disk project allen disk