CVE-2017-9091
19.05.2017, 18:29
/admin/loginc.php in Allen Disk 1.6 doesn't check if isset($_SESSION['captcha']['code']) == 1, which leads to CAPTCHA bypass by emptying $_POST['captcha'].Enginsight
Vendor | Product | Version |
---|---|---|
allen_disk_project | allen_disk | 1.6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration