Vulnerabilities > CVE-2017-9307 - Server-Side Request Forgery (SSRF) vulnerability in Allen Disk Project Allen Disk 1.6

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
allen-disk-project
CWE-918

Summary

SSRF vulnerability in remotedownload.php in Allen Disk 1.6 allows remote authenticated users to conduct port scans and access intranet servers via a crafted file parameter.

Vulnerable Configurations

Part Description Count
Application
Allen_Disk_Project
1

Common Weakness Enumeration (CWE)