Back

CVE-2005-3201

SQL injection vulnerability in news.php for Utopia News Pro (UNP) 1.1.3, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to execute arbitrary SQL via the newsid parameter.

Published: Oct 14, 2005 Modified: Jun 16, 2026

CVSS Metrics

GitHub Security Advisory GHSA-mh98-9c79-r68x

SQL injection vulnerability in news.php for Utopia News Pro (UNP) 1.1.3, when magic_quotes_gpc is...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.75%

Top 24% most likely to be exploited

Threat Score 30.5 / 100

Data Sources

NVD EPSS GitHub