SQL injection vulnerability in index.php in the jlmZone Classifieds module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter in an Adsview action.Referenceshttp://securityreason.com/securityalert/3681https://www.exploit-db.com/exploits/5158http://www.securityfocus.com/bid/27895http://www.securityfocus.com/archive/1/488357/100/0/threaded