CVE-2017-17638
Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter.
Date published : 2017-12-13
https://www.exploit-db.com/exploits/43309/
https://packetstormsecurity.com/files/145350/Groupon-Clone-Script-3.01-SQL-Injection.html