Allen Disk Project

Allen Disk

6 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Published 31.05.2017 04:29:00
  • Last modified 20.04.2025 01:37:25

SSRF vulnerability in remotedownload.php in Allen Disk 1.6 allows remote authenticated users to conduct port scans and access intranet servers via a crafted file parameter.

Exploit
  • EPSS 0.15%
  • Published 28.05.2017 20:29:00
  • Last modified 20.04.2025 01:37:25

Cross-site scripting (XSS) vulnerability in Allen Disk 1.6 allows remote authenticated users to inject arbitrary web script or HTML persistently by uploading a crafted HTML file. The attack vector is the content of this file, and the filename must be...

  • EPSS 0.2%
  • Published 19.05.2017 18:29:00
  • Last modified 20.04.2025 01:37:25

reg.php in Allen Disk 1.6 doesn't check if isset($_SESSION['captcha']['code'])==1, which makes it possible to bypass the CAPTCHA via an empty $_POST['captcha'].

  • EPSS 0.2%
  • Published 19.05.2017 18:29:00
  • Last modified 20.04.2025 01:37:25

/admin/loginc.php in Allen Disk 1.6 doesn't check if isset($_SESSION['captcha']['code']) == 1, which leads to CAPTCHA bypass by emptying $_POST['captcha'].

  • EPSS 0.1%
  • Published 08.05.2017 17:29:00
  • Last modified 20.04.2025 01:37:25

Allen Disk 1.6 has CSRF in setpass.php with an impact of changing a password.

  • EPSS 0.31%
  • Published 08.05.2017 06:29:00
  • Last modified 20.04.2025 01:37:25

Allen Disk 1.6 has XSS in the id parameter to downfile.php.