An issue was discovered in rageframe2 2.6.37. There is a XSS vulnerability in the user agent related parameters of the info.php page.
https://github.com/jianyan74/rageframe2/issues/106?by=xboy%28Topsec%29
https://github.com/jianyan74/rageframe2/issues/106