Website Auction Marketplace 2.0.5 has SQL Injection via the search.php cat_id parameter.
- https://packetstormsecurity.com/files/145248/Website-Auction-Marketplace-2.0.5-SQL-Injection.html
- https://www.exploit-db.com/exploits/43238/
No PoCs found on GitHub currently.