CVE-2017-9249
28.05.2017, 20:29
Cross-site scripting (XSS) vulnerability in Allen Disk 1.6 allows remote authenticated users to inject arbitrary web script or HTML persistently by uploading a crafted HTML file. The attack vector is the content of this file, and the filename must be specified in the PATH_INFO to readfile.php.
Vendor | Product | Version |
---|---|---|
allen_disk_project | allen_disk | 1.6 |
𝑥
= Vulnerable software versions