Rigter Portal System (RPS) 1.0, 2.0, and 3.0 allows remote attackers to bypass authentication and upload arbitrary files via direct requests to (1) adm/photos/images.php and (2) adm/down/files.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Rigter_portal_system | Rigter_portal_system | 1.0 (including) | 1.0 (including) |
Rigter_portal_system | Rigter_portal_system | 2.0 (including) | 2.0 (including) |
Rigter_portal_system | Rigter_portal_system | 3.0 (including) | 3.0 (including) |