CVE-2017-8832by Jeremyin Security Bulletinson Posted on May 8, 2017 Allen Disk 1.6 has XSS in the id parameter to downfile.php.