{"api_version":"1","generated_at":"2026-07-23T05:38:44+00:00","cve":"CVE-2005-3200","urls":{"html":"https://cve.report/CVE-2005-3200","api":"https://cve.report/api/cve/CVE-2005-3200.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-3200","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-3200"},"summary":{"title":"CVE-2005-3200","description":"Multiple cross-site scripting (XSS) vulnerabilities in Utopia News Pro (UNP) 1.1.3 and 1.1.4 allow remote attackers to inject arbitrary web script or HTML via (1) the sitetitle parameter in header.php and (2) the version and (3) query_count parameters in footer.php.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-10-14 10:02:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://rgod.altervista.org/utopia113.html","name":"http://rgod.altervista.org/utopia113.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/plain","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.osvdb.org/19940","name":"http://www.osvdb.org/19940","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22554","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22554","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1015016","name":"http://securitytracker.com/id?1015016","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Utopia News Pro Input Validation Holes Permit SQL Injection and Cross-Site Scripting Attacks","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.utopiasoftware.net/","name":"http://www.utopiasoftware.net/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Utopia Software - Main","mime":"text/html","httpstatus":"403","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/15027","name":"http://www.securityfocus.com/bid/15027","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Utopia News Pro Multiple Cross-Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/17115/","name":"http://secunia.com/advisories/17115/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Secunia - Advisories - Utopia News Pro Cross-Site Scripting and SQL Injection","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=112872691119874&w=2","name":"http://marc.info/?l=bugtraq&m=112872691119874&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'Utopia News Pro 1.1.3 SQL Injection / cross site scripting' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/19941","name":"http://www.osvdb.org/19941","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-3200","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-3200","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"3200","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"utopia_software","cpe5":"utopia_news_pro","cpe6":"1.1.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"3200","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"utopia_software","cpe5":"utopia_news_pro","cpe6":"1.1.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T23:01:59.282Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"utopianewspro-header-footer-xss(22554)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22554"},{"name":"17115","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/17115/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://rgod.altervista.org/utopia113.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.utopiasoftware.net/"},{"name":"20051007 Utopia News Pro 1.1.3 SQL Injection / cross site scripting","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=112872691119874&w=2"},{"name":"19941","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/19941"},{"name":"15027","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/15027"},{"name":"1015016","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1015016"},{"name":"19940","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/19940"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-10-06T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in Utopia News Pro (UNP) 1.1.3 and 1.1.4 allow remote attackers to inject arbitrary web script or HTML via (1) the sitetitle parameter in header.php and (2) the version and (3) query_count parameters in footer.php."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"utopianewspro-header-footer-xss(22554)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22554"},{"name":"17115","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/17115/"},{"tags":["x_refsource_MISC"],"url":"http://rgod.altervista.org/utopia113.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.utopiasoftware.net/"},{"name":"20051007 Utopia News Pro 1.1.3 SQL Injection / cross site scripting","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=112872691119874&w=2"},{"name":"19941","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/19941"},{"name":"15027","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/15027"},{"name":"1015016","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1015016"},{"name":"19940","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/19940"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-3200","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in Utopia News Pro (UNP) 1.1.3 and 1.1.4 allow remote attackers to inject arbitrary web script or HTML via (1) the sitetitle parameter in header.php and (2) the version and (3) query_count parameters in footer.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"utopianewspro-header-footer-xss(22554)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22554"},{"name":"17115","refsource":"SECUNIA","url":"http://secunia.com/advisories/17115/"},{"name":"http://rgod.altervista.org/utopia113.html","refsource":"MISC","url":"http://rgod.altervista.org/utopia113.html"},{"name":"http://www.utopiasoftware.net/","refsource":"CONFIRM","url":"http://www.utopiasoftware.net/"},{"name":"20051007 Utopia News Pro 1.1.3 SQL Injection / cross site scripting","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=112872691119874&w=2"},{"name":"19941","refsource":"OSVDB","url":"http://www.osvdb.org/19941"},{"name":"15027","refsource":"BID","url":"http://www.securityfocus.com/bid/15027"},{"name":"1015016","refsource":"SECTRACK","url":"http://securitytracker.com/id?1015016"},{"name":"19940","refsource":"OSVDB","url":"http://www.osvdb.org/19940"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-3200","datePublished":"2005-10-14T04:00:00.000Z","dateReserved":"2005-10-14T00:00:00.000Z","dateUpdated":"2024-08-07T23:01:59.282Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-10-14 10:02:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:utopia_software:utopia_news_pro:1.1.3:*:*:*:*:*:*:*","matchCriteriaId":"4A39A7F8-EBCC-4E06-B663-6BA87D1709DB"},{"vulnerable":true,"criteria":"cpe:2.3:a:utopia_software:utopia_news_pro:1.1.4:*:*:*:*:*:*:*","matchCriteriaId":"7A35C687-FC90-432B-A4A5-B47773D93DFD"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"3200","Ordinal":"1","Title":"CVE-2005-3200","CVE":"CVE-2005-3200","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"3200","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in Utopia News Pro (UNP) 1.1.3 and 1.1.4 allow remote attackers to inject arbitrary web script or HTML via (1) the sitetitle parameter in header.php and (2) the version and (3) query_count parameters in footer.php.","Type":"Description","Title":"CVE-2005-3200"},{"CveYear":"2005","CveId":"3200","Ordinal":"2","NoteData":"2005-10-14","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"3200","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}