CVE-2005-4223
Multiple "potential" SQL injection vulnerabilities in Utopia News Pro (UNP) 1.1.4 might allow remote attackers to execute arbitrary SQL commands via (1) the newsid parameter in editnews.php, (2) the catid and question parameters in faq.php, (3) the…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.80%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple "potential" SQL injection vulnerabilities in Utopia News Pro (UNP) 1.1.4 might allow remote attackers to execute arbitrary SQL commands via (1) the newsid parameter in editnews.php, (2) the catid and question parameters in faq.php, (3) the poster parameter in postnews.php, (4) the tempid parameter in templates.php, and (5) the userid and groupid parameters in users.php.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.80% probability · 77th percentile
- CISA KEV
- Not listed
- Affected
- utopia software/utopia news pro
- Source
- cve@mitre.org
References
- http://glide.stanford.edu/yichen/research/sec.pdf
- http://secunia.com/advisories/17988/Patch, Vendor Advisory
- http://www.osvdb.org/21645Patch
- http://www.osvdb.org/21646Patch
- http://www.osvdb.org/21647Patch
- http://www.osvdb.org/21648Patch
- http://www.osvdb.org/21649Patch
- http://www.securityfocus.com/archive/1/419280/100/0/threaded
- http://www.securityfocus.com/archive/1/419487/100/0/threaded
- http://www.vupen.com/english/advisories/2005/2859
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23564
- http://glide.stanford.edu/yichen/research/sec.pdf
- http://secunia.com/advisories/17988/Patch, Vendor Advisory
- http://www.osvdb.org/21645Patch
- http://www.osvdb.org/21646Patch
- http://www.osvdb.org/21647Patch
- http://www.osvdb.org/21648Patch
- http://www.osvdb.org/21649Patch
- http://www.securityfocus.com/archive/1/419280/100/0/threaded
- http://www.securityfocus.com/archive/1/419487/100/0/threaded
- http://www.vupen.com/english/advisories/2005/2859
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23564
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.