SQL injection vulnerability in news.php for Utopia News Pro (UNP) 1.1.3, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to execute arbitrary SQL via the newsid parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Utopia_news_pro | Utopia_software | 1.1.1b (including) | 1.1.1b (including) |
Utopia_news_pro | Utopia_software | 1.1.2 (including) | 1.1.2 (including) |
Utopia_news_pro | Utopia_software | 1.1.3 (including) | 1.1.3 (including) |