Rigter Portal System (RPS) 1.0, 2.0, and 3.0 allows remote attackers to add arbitrary content and conduct XSS attacks via a direct request to add_art.php. NOTE: this issue was originally reported as SQL injection, but this is not likely.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Rigter_portal_system | Rigter_portal_system | 1.0 (including) | 1.0 (including) |
Rigter_portal_system | Rigter_portal_system | 2.0 (including) | 2.0 (including) |
Rigter_portal_system | Rigter_portal_system | 3.0 (including) | 3.0 (including) |