Rigter · Rigter Portal System · CVE-2007-1293
**Name of the Vulnerable Software and Affected Versions**
Rigter Portal System (RPS) version 6.2
**Description**
The issue allows remote attackers to execute arbitrary SQL commands, possibly related to ver descarga.php, when the magic quotes gpc setting is disabled. This can be achieved via the `categoria` parameter to the "index.php" endpoint.
**Recommendations**
For RPS version 6.2, consider disabling the use of the `categoria` parameter in the "index.php" endpoint until a fix is available, or enable the magic quotes gpc setting to prevent SQL injection attacks.