SQL injection vulnerability in search.php in phpDirectorySource 1.x allows remote attackers to execute arbitrary SQL commands via the st parameter.Referenceshttp://www.exploit-db.com/exploits/9226http://packetstormsecurity.org/0907-exploits/wbd-sqlxss.txthttp://www.securityfocus.com/bid/35760http://secunia.com/advisories/35941