SQL injection vulnerability in view_listing.php in Vastal I-Tech Agent Zone (aka The Real Estate Script) allows remote attackers to execute arbitrary SQL commands via the id parameter.Referenceshttp://secunia.com/advisories/36812http://www.packetstormsecurity.org/0909-exploits/realestaterealtors-sql.txt