SQL injection vulnerability in index.php in GeodesicSolutions (1) GeoAuctions Premier 2.0.3 and (2) GeoClassifieds Basic 2.0.3 allows remote attackers to execute arbitrary SQL commands via the b parameter. Successful exploitation requires that the 'accumulative feedback' feature is turned on.
Publication date: Tue, 25 Jul 2006 18:22:00 +0000