7.5
CVE-2005-4223
- EPSS 1.8%
- Veröffentlicht 14.12.2005 11:03:00
- Zuletzt bearbeitet 16.06.2026 22:18:23
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Multiple "potential" SQL injection vulnerabilities in Utopia News Pro (UNP) 1.1.4 might allow remote attackers to execute arbitrary SQL commands via (1) the newsid parameter in editnews.php, (2) the catid and question parameters in faq.php, (3) the poster parameter in postnews.php, (4) the tempid parameter in templates.php, and (5) the userid and groupid parameters in users.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Utopia Software ≫ Utopia News Pro Version1.1.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.8% | 0.757 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://glide.stanford.edu/yichen/research/sec.pdf
http://www.securityfocus.com/archive/1/419280/100/0/threaded
http://secunia.com/advisories/17988/
http://www.osvdb.org/21645
http://www.osvdb.org/21646
http://www.osvdb.org/21647
http://www.osvdb.org/21648
http://www.osvdb.org/21649
http://www.securityfocus.com/archive/1/419487/100/0/threaded
http://www.vupen.com/english/advisories/2005/2859
https://exchange.xforce.ibmcloud.com/vulnerabilities/23564