CVE-2009-3497
SQL injection vulnerability in view_listing.php in Vastal I-Tech Agent Zone (aka The Real Estate Script) allows remote attackers to execute arbitrary SQL commands via the id parameter.
Date published : 2009-09-30
http://www.packetstormsecurity.org/0909-exploits/realestaterealtors-sql.txt