{"api_version":"1","generated_at":"2026-07-23T06:20:38+00:00","cve":"CVE-2005-4223","urls":{"html":"https://cve.report/CVE-2005-4223","api":"https://cve.report/api/cve/CVE-2005-4223.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-4223","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-4223"},"summary":{"title":"CVE-2005-4223","description":"Multiple \"potential\" SQL injection vulnerabilities in Utopia News Pro (UNP) 1.1.4 might allow remote attackers to execute arbitrary SQL commands via (1) the newsid parameter in editnews.php, (2) the catid and question parameters in faq.php, (3) the poster parameter in postnews.php, (4) the tempid parameter in templates.php, and (5) the userid and groupid parameters in users.php.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-12-14 11:03:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.osvdb.org/21649","name":"http://www.osvdb.org/21649","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/archive/1/419487/100/0/threaded","name":"http://www.securityfocus.com/archive/1/419487/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/419280/100/0/threaded","name":"http://www.securityfocus.com/archive/1/419280/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/17988/","name":"http://secunia.com/advisories/17988/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Secunia - Advisories - Utopia News Pro SQL Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23564","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23564","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/21646","name":"http://www.osvdb.org/21646","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.osvdb.org/21647","name":"http://www.osvdb.org/21647","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.osvdb.org/21645","name":"http://www.osvdb.org/21645","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://glide.stanford.edu/yichen/research/sec.pdf","name":"http://glide.stanford.edu/yichen/research/sec.pdf","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"application/pdf","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2005/2859","name":"http://www.vupen.com/english/advisories/2005/2859","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/21648","name":"http://www.osvdb.org/21648","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-4223","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-4223","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"4223","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"utopia_software","cpe5":"utopia_news_pro","cpe6":"1.1.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T23:38:51.526Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20051211 [PHP-CHECKER] 99 potential SQL injection vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/419280/100/0/threaded"},{"name":"21649","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/21649"},{"name":"ADV-2005-2859","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2005/2859"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://glide.stanford.edu/yichen/research/sec.pdf"},{"name":"17988","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/17988/"},{"name":"20051212 [PHP-CHECKER] 99 potential SQL injection vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/419487/100/0/threaded"},{"name":"21647","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/21647"},{"name":"21648","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/21648"},{"name":"21645","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/21645"},{"name":"21646","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/21646"},{"name":"utopianewspro-editnews-sql-injection(23564)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23564"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-12-11T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple \"potential\" SQL injection vulnerabilities in Utopia News Pro (UNP) 1.1.4 might allow remote attackers to execute arbitrary SQL commands via (1) the newsid parameter in editnews.php, (2) the catid and question parameters in faq.php, (3) the poster parameter in postnews.php, (4) the tempid parameter in templates.php, and (5) the userid and groupid parameters in users.php."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-19T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20051211 [PHP-CHECKER] 99 potential SQL injection vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/419280/100/0/threaded"},{"name":"21649","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/21649"},{"name":"ADV-2005-2859","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2005/2859"},{"tags":["x_refsource_MISC"],"url":"http://glide.stanford.edu/yichen/research/sec.pdf"},{"name":"17988","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/17988/"},{"name":"20051212 [PHP-CHECKER] 99 potential SQL injection vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/419487/100/0/threaded"},{"name":"21647","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/21647"},{"name":"21648","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/21648"},{"name":"21645","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/21645"},{"name":"21646","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/21646"},{"name":"utopianewspro-editnews-sql-injection(23564)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23564"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-4223","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple \"potential\" SQL injection vulnerabilities in Utopia News Pro (UNP) 1.1.4 might allow remote attackers to execute arbitrary SQL commands via (1) the newsid parameter in editnews.php, (2) the catid and question parameters in faq.php, (3) the poster parameter in postnews.php, (4) the tempid parameter in templates.php, and (5) the userid and groupid parameters in users.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20051211 [PHP-CHECKER] 99 potential SQL injection vulnerabilities","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/419280/100/0/threaded"},{"name":"21649","refsource":"OSVDB","url":"http://www.osvdb.org/21649"},{"name":"ADV-2005-2859","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2005/2859"},{"name":"http://glide.stanford.edu/yichen/research/sec.pdf","refsource":"MISC","url":"http://glide.stanford.edu/yichen/research/sec.pdf"},{"name":"17988","refsource":"SECUNIA","url":"http://secunia.com/advisories/17988/"},{"name":"20051212 [PHP-CHECKER] 99 potential SQL injection vulnerabilities","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/419487/100/0/threaded"},{"name":"21647","refsource":"OSVDB","url":"http://www.osvdb.org/21647"},{"name":"21648","refsource":"OSVDB","url":"http://www.osvdb.org/21648"},{"name":"21645","refsource":"OSVDB","url":"http://www.osvdb.org/21645"},{"name":"21646","refsource":"OSVDB","url":"http://www.osvdb.org/21646"},{"name":"utopianewspro-editnews-sql-injection(23564)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23564"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-4223","datePublished":"2005-12-14T11:00:00.000Z","dateReserved":"2005-12-14T00:00:00.000Z","dateUpdated":"2024-08-07T23:38:51.526Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-12-14 11:03:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:utopia_software:utopia_news_pro:1.1.4:*:*:*:*:*:*:*","matchCriteriaId":"7A35C687-FC90-432B-A4A5-B47773D93DFD"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"4223","Ordinal":"1","Title":"CVE-2005-4223","CVE":"CVE-2005-4223","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"4223","Ordinal":"1","NoteData":"Multiple \"potential\" SQL injection vulnerabilities in Utopia News Pro (UNP) 1.1.4 might allow remote attackers to execute arbitrary SQL commands via (1) the newsid parameter in editnews.php, (2) the catid and question parameters in faq.php, (3) the poster parameter in postnews.php, (4) the tempid parameter in templates.php, and (5) the userid and groupid parameters in users.php.","Type":"Description","Title":"CVE-2005-4223"},{"CveYear":"2005","CveId":"4223","Ordinal":"2","NoteData":"2005-12-14","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"4223","Ordinal":"3","NoteData":"2018-10-19","Type":"Other","Title":"Modified"}]}}}