SQL injection vulnerability in the classified page (classified.php) in BusinessSpace 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.Referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/48606http://secunia.com/advisories/33875https://www.exploit-db.com/exploits/8011http://www.securityfocus.com/bid/33692http://www.securityfocus.com/archive/1/500787/100/0/threaded