« Back to list

Allen Disk Project

Allen Disk Project Allen Disk: vulnerabilities and CVEs

Allen Disk Project Allen Disk has 6 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs6
Last 12 months0
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2017-9307Medium (6.5)0.89%—May 31, 2017
SSRF vulnerability in remotedownload.php in Allen Disk 1.6 allows remote authenticated users to conduct port scans and access intranet servers via a crafted file parameter.
CVE-2017-9249Medium (5.4)0.68%—May 28, 2017
Cross-site scripting (XSS) vulnerability in Allen Disk 1.6 allows remote authenticated users to inject arbitrary web script or HTML persistently by uploading a crafted HTML file. The attack vector is the content of this…
CVE-2017-9091High (7.5)1.3%—May 19, 2017
/admin/loginc.php in Allen Disk 1.6 doesn't check if isset($_SESSION['captcha']['code']) == 1, which leads to CAPTCHA bypass by emptying $_POST['captcha'].
CVE-2017-9090High (7.5)1.3%—May 19, 2017
reg.php in Allen Disk 1.6 doesn't check if isset($_SESSION['captcha']['code'])==1, which makes it possible to bypass the CAPTCHA via an empty $_POST['captcha'].
CVE-2017-8848Medium (6.5)0.49%—May 8, 2017
Allen Disk 1.6 has CSRF in setpass.php with an impact of changing a password.
CVE-2017-8832Medium (6.1)0.63%—May 8, 2017
Allen Disk 1.6 has XSS in the id parameter to downfile.php.