I was astonished to see, that Virtuemart is not listed under joomla.org > extensions > ecommerce > shopping cart. It was before but obviously joomla.org did remove it!
It will be back with the 2.0.4 release.
The 2.0.4beta has shown up. Does it mean that, in that version, the sqli vulnerability does not exist anymore ? did it still exist in the 2.0.3 version ?
The vulnerability is quite akademical. When you have a correct htaccess of sobi or akeeba tools, nothing can happen. Imho theoretical people can vandalize a bit. Anyway all is fixed in the 2.0.4beta and in the 2.0.4, which is now in our last test phase.