MyClassifieds SQL Versions below 2.13 are vulnerable to a SQL injection attack. The problem is due to improper sanitization of user input for the email variable. A remote attacker could insert arbitrary SQL code in the email variable. The passwords of the users can be written into a file and made world readable.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/32124/sa-2003-04-myclassified.pdf
Source: https://packetstormsecurity.com/files/32124/sa-2003-04-myclassified.pdf.html

