SQL injection vulnerability in viewmsg.asp in LocazoList Classifieds 1.05e allows remote attackers to execute arbitrary SQL commands via the msgid parameter.Referenceshttp://www.vupen.com/english/advisories/2006/2136http://securitytracker.com/id?1016222https://exchange.xforce.ibmcloud.com/vulnerabilities/26900http://www.securityfocus.com/archive/1/435986/100/0/threadedhttp://www.securityfocus.com/bid/18254http://www.securityfocus.com/archive/1/435867/100/0/threadedhttp://secunia.com/advisories/20462http://securityreason.com/securityalert/1048