CVE-2010-0693
SQL injection vulnerability in products.php in CommodityRentals Trade Manager Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.
Date published : 2010-02-23
http://www.exploit-db.com/exploits/11412
http://packetstormsecurity.org/1002-exploits/trademanager-sql.txt