VulnerabilityModified
CVE-2006-7085
Rigter Portal System (RPS) 1.0, 2.0, and 3.0 allows remote attackers to add arbitrary content and conduct XSS attacks via a direct request to add_art.php.
MEDIUM 4.3EPSS 0.97%
Does this matter?
Lower severity and a low EPSS score (0.97%). Track it; it rarely justifies an emergency change on its own.
Description
Rigter Portal System (RPS) 1.0, 2.0, and 3.0 allows remote attackers to add arbitrary content and conduct XSS attacks via a direct request to add_art.php. NOTE: this issue was originally reported as SQL injection, but this is not likely.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 0.97% probability · 60th percentile
- CISA KEV
- Not listed
- Affected
- rigter portal system/rigter portal system
- Source
- cve@mitre.org
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/048006.htmlExploit, Vendor Advisory
- http://securityreason.com/securityalert/2322
- http://www.osvdb.org/28640Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39972
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/048006.htmlExploit, Vendor Advisory
- http://securityreason.com/securityalert/2322
- http://www.osvdb.org/28640Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39972
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.