CVE-2005-3200
Utopia News Pro 1.1.3-1.1.4 - Cross-Site Scripting via sitetitle, version, and query_count Parameters
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2005-3200. PoCs published by rgod.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Utopia News Pro by injecting arbitrary JavaScript code via the 'sitetitle' parameter in header.php. The PoC uses a simple alert to display the user's cookies, proving the vulnerability.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Utopia News Pro (UNP) 1.1.3 and 1.1.4 allow remote attackers to inject arbitrary web script or HTML via (1) the sitetitle parameter in header.php and (2) the version and (3) query_count parameters in footer.php.
Exploits (2)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Utopia News Pro by injecting arbitrary JavaScript code via the 'sitetitle' parameter in header.php. The PoC uses a simple alert to display the user's cookies, proving the vulnerability.
This exploit demonstrates multiple XSS vulnerabilities in Utopia News Pro by injecting arbitrary JavaScript code via the 'version' and 'query_count' parameters in footer.php. The PoC uses simple script tags to trigger an alert with the user's cookies, proving the lack of input sanitization.