SQL injection vulnerability in fullnews.php in PHP Real Estate Classifieds allows remote attackers to execute arbitrary SQL commands via the id parameter.
https://www.exploit-db.com/exploits/4737
http://secunia.com/advisories/28119
http://phprealestatescript.com/PHPREC-121707-646PM-PATCH.zip