SQL injection vulnerability in news.php for Utopia News Pro (UNP) 1.1.3, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to execute arbitrary SQL via the newsid parameter.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Utopia_news_pro | Utopia_software | 1.1.1b (including) | 1.1.1b (including) |
| Utopia_news_pro | Utopia_software | 1.1.2 (including) | 1.1.2 (including) |
| Utopia_news_pro | Utopia_software | 1.1.3 (including) | 1.1.3 (including) |