SQL injection vulnerability in product_desc.php in Softbiz Auctions Script allows remote attackers to execute arbitrary SQL commands via the id parameter.Referenceshttp://www.securityfocus.com/bid/26399https://www.exploit-db.com/exploits/4617https://exchange.xforce.ibmcloud.com/vulnerabilities/38399