# Type | Modules affected | vulnerability title | version ini | version end | other version | vulnerability description | url reference (url1 uel2 ... url3)
Core||Multiple XSS/CSRF Vulnerability|1.5.9|1.5.9||A series of XSS and CSRF faults exist in the administrator application. Affected administrator components include com_admin, com_media, com_search. Both com_admin and com_search contain XSS vulnerabilities, and com_media contains 2 CSRF vulnerabilities.|
Core|joomla ja_purity com_users frontend|Multiple Cross Site Scripting and HTML Injection Vulnerabilities|1.5.0|1.5.10|Joomlart JS_Purity Template 1.2|Joomla! is prone to multiple cross-site scripting and HTML-injection vulnerabilities because the application fails to sufficiently sanitize user-supplied input. These issues affect the 'com_user' component, the 'JA_Purity' template, and the administrative panel in the 'Site client' subproject of the application. An attacker can exploit these issues to steal cookie-based authentication credentials and launch other attacks.|http://www.securityfocus.com/bid/35189/
Component||'com_user' Component Token Input Validation Vulnerability|1.5.0|1.5.5||The 'com_user' component for Joomla! is prone to an input-validation vulnerability because it fails to sufficiently sanitize user-supplied data.|http://www.securityfocus.com/bid/30667/
Component|com_countries|'com_countries' Component 'locat' Parameter SQL Injection Vulnerability|x.x.x|1.5.15||The 'com_countries' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.|http://www.securityfocus.com/bid/37561/
Component|com_rsgallery2|'com_rsgallery2' Component 'catid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla com_rsgallery2 2.0|The 'com_rsgallery2' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.|http://www.securityfocus.com/bid/38009/
Component|com_abbrev|'com_abbrev' Joomla! Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Joomla com_abbrev|The 'com_abbrev' component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input. An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/37560/
Component|com_weblinks|'com_weblinks' Component 'Itemid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla com_weblinks|The 'com_weblinks' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.|http://www.securityfocus.com/bid/42455/
Component|com_controller|JGrid Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|JGrid version 1.0|The JGrid component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input. An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/42486/
Component|com_controller|JGrid Component Unspecified SQL Injection Vulnerability|x.x.x|x.x.x|JGrid version 1.0|The JGrid component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.|http://www.securityfocus.com/bid/42552/
Component|com_jpodium|JPodium Component 'f_id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|JPodium|The JPodium component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.|http://www.securityfocus.com/bid/42405/
Component|com_slideshow|'com_slideshow' Component 'catid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|webmaster-tips.net com_slideshow 1.0|The 'com_slideshow' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.|http://www.securityfocus.com/bid/42427/
Component|com_yellowpages|Yellowpages Component SQL Injection Vulnerability|x.x.x|x.x.x|Joomla Yellowpages|The Yellowpages component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.|http://www.securityfocus.com/bid/42326/ http://www.exploit-db.com/exploits/14592/
Component|com_aardvertiser|Aardvertiser Component Insecure Directory Permissions Vulnerability|x.x.x|x.x.x|Aardvertiser < 2.1.1|The Aardvertiser component for Joomla! is prone to a security vulnerability because it sets insecure directory permissions.A local attacker can exploit this issue to obtain sensitive information, manipulate data, or gain escalated privileges.|http://www.securityfocus.com/bid/42239/
Component|com_jigsaw|'com_jigsaw' Component 'controller' Parameter Directory Traversal Vulnerability|x.x.x|x.x.x|com_jigsaw|The 'com_jigsaw' component for Joomla! is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.|http://www.securityfocus.com/bid/42144/
Component|controller.php|PBBooking Component 'controller.php' Multiple SQL Injection Vulnerabilities|x.x.x|x.x.x|PBBooking 1.0.4_3|The PBBooking component for Joomla! is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.|http://www.securityfocus.com/bid/42067/
Component|com_beamospetition|BeaMosPetition Component for Joomla! 'pet' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_beamospetition|The BeaMosPetition component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.|http://www.securityfocus.com/bid/42086/
Component|com_simpleshop|Galore Simple Shop Component for Joomla! 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Galore Simple Shop <= 3.5|The Galore Simple Shop component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.|http://www.securityfocus.com/bid/42073/
Component|com_photomapgallery|PhotoMap Gallery Component Multiple SQL Injection Vulnerabilities|x.x.x|x.x.x|PhotoMap Gallery 1.6.0 beta|The PhotoMap Gallery component for Joomla! is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.|http://www.securityfocus.com/bid/42030/
Component|com_ttvideo|'TTVideo' Component SQL Injection Vulnerability|x.x.x|x.x.x|TTVideo 1.0|The 'TTVideo' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.|http://www.securityfocus.com/bid/41977/ http://www.exploit-db.com/exploits/14481/
Component|com_appointinator|Component Appointinator Multiple SQL Injection Vulnerabilities|x.x.x|x.x.x|AjaXplorer <= 2.5.4|The Appointinator component for Joomla! is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.|http://www.securityfocus.com/bid/42007/ http://www.exploit-db.com/exploits/14488/
Component|com_freichat|FreiChat Component Unspecified HTML Injection Vulnerability|x.x.x|x.x.x|Avinash D'silva FreiChat <= 2.1.1|Joomla! FreiChat component is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content.Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.|http://www.securityfocus.com/bid/41961/
Component|com_oziogallery|Ozio Gallery Component 'Itemid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla Ozio Gallery|The Ozio Gallery component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.|http://www.securityfocus.com/bid/41942/
Component|com_youtube|Component 'com_youtube' SQL Injection Vulnerability|x.x.x|x.x.x|Joomla com_youtube 1.5|The 'com_youtube' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.|http://www.securityfocus.com/bid/41938/ http://www.exploit-db.com/exploits/14467/
Component|com_itarmory|ITArmory Component 'Itemid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|In Therapy ITArmory 0.1.4|The ITArmory component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.|http://www.securityfocus.com/bid/41944/
Component|com_joomdle|'Joomdle' Component 'course_id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomdle <= 0.24|The 'Joomdle' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.|http://www.securityfocus.com/bid/41939/ http://www.exploit-db.com/exploits/14466/
Component|com_golfcourseguide|GolfCourseGuide Component 'index.php' SQL Injection Vulnerability|x.x.x|x.x.x|Oh-Taek Im GolfCourseGuide 0.9.6.0 beta|The GolfCourseGuide 'com_golfcourseguide' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.|http://www.securityfocus.com/bid/41919/
Component|com_spa|'com_spa' Component 'pid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla com_spa|The 'com_spa' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.|http://www.securityfocus.com/bid/41828/
Core||Administration Pages Multiple HTML Injection Vulnerabilities|1.5.0|1.5.19||Joomla! is prone to multiple HTML-injection vulnerabilities because the application fails to sufficiently sanitize user-supplied data.Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.|http://www.securityfocus.com/bid/41822/
Component|com_spa|'com_spa' Component 'cid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla com_spa|The 'com_spa' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.|http://www.securityfocus.com/bid/41778/
Component|com_staticxt|staticXT Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|JoomlaXT! StaticXT|The staticXT component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.|http://www.securityfocus.com/bid/41765/
Component|?view=videos &view=videos&type=member&user_id=|JomTube Component 'user_id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|JomTube|The JomTube component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.|http://www.securityfocus.com/bid/41888/
Core||HTML Injection and SQL Injection Vulnerabilities|1.5.0|1.5.18||Joomla! is prone to multiple HTML-injection vulnerabilities and an SQL-injection vulnerability because the application fails to sufficiently sanitize user-supplied input.A successful exploit can allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/41743/
Component|com_redshop|redSHOP Component Search Form Multiple SQL Injection Vulnerabilities|x.x.x|x.x.x|redCOMPONENT redSHOP 1.0.23.1|The redSHOP component for Joomla! is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.A successful exploit requires that 'magic_quotes_gpc' is disabled.Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/41728/
Component|com_easyblog|EasyBlog HTML Injection Vulnerability|x.x.x|x.x.x|Stack Ideas EasyBlog|Joomla! EasyBlog is prone to an unspecified HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content.Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.|http://www.securityfocus.com/bid/41532/
Component|com_health|Health & Fitness Stats Component Multiple HTML Injection Vulnerabilities|x.x.x|x.x.x|Instantiate Web Solutions Health & Fitness Stats|Joomla! Health & Fitness Stats component is prone to multiple HTML-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.|http://www.securityfocus.com/bid/41530/
Component|com_qcontacts|QContacts Component Multiple Parameters SQL Injection Vulnerability|x.x.x|x.x.x|Latenight Coding QContacts 1.0.4|The QContacts component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/41570/
Component|com_rapidrecipe|Rapid-Recipe Component HTML Injection Vulnerability|x.x.x|x.x.x|Rapid-Source Rapid-Recipe|Joomla! Rapid-Recipe component is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content.Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.|http://www.securityfocus.com/bid/41531/
Component|com_redshop|redSHOP Component 'pid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|redSHOP version 1.0|redSHOP component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/41533/
Component|com_myhome|MyHome Component 'nidimm' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Unisoft MyHome|MyHome component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/41536/
Component|com_mysms|'com_mysms' Component Arbitrary File Upload Vulnerability|x.x.x|x.x.x|Joomla com_mysms|The 'com_mysms' component for Joomla! is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to adequately sanitize user-supplied input.An attacker can exploit this vulnerability to upload arbitrary code and run it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.|http://www.securityfocus.com/bid/41535/
Component|com_quickfaq|Component for Joomla! 'Itemid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla QuickFAQ 1.0.3|The QuickFAQ component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue can allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/41508/
Component|component/music/album.html|Music Manager Component 'album.html' Local File Include Vulnerability|x.x.x|x.x.x|Daniel James Scott Music Manager|The Music Manager component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/41485/
Component|com_artforms|ArtForms Component Multiple Vulnerabilities|x.x.x|x.x.x|Joomla ArtForms 2.1b7.2 RC2|The ArtForms component for Joomla! is prone to multiple SQL-injection vulnerabilities, a cross-site scripting vulnerability, and a directory-traversal vulnerability.Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, or disclose sensitive information.|http://www.securityfocus.com/bid/41457/
Component|games/gambling/add.html|PaymentsPlus Component 'add.html' SQL Injection Vulnerability|x.x.x|x.x.x|Joomla PaymentsPlus 2.1.5|PaymentsPlus component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/41458/
Component|com_neorecruit|NeoRecruit Component for Joomla! 'Itemid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|NeoJoomla NeoRecruit 1.4 - 1.4.1 - 2.0.5|NeoRecruit is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.|http://www.securityfocus.com/bid/41408/
Component|jobs/search_jobs.html|Jobs Pro Component for Joomla! 'search_jobs.html' SQL Injection Vulnerability|x.x.x|x.x.x|Instant Php Jobs Pro 1.3.2|The Jobs Pro component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/41403/
Component|com_autartimonial|AutarTimonial Component 'index.php' SQL Injection Vulnerability|x.x.x|x.x.x|Autartica AutarTimonial|The AutarTimonial component 'com_autartimonial' for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/41400/
Component|com_jpodium|JPodium Component for Joomla! 'CID' SQL Injection Vulnerability|x.x.x|x.x.x|JPodium 0.9.15|The JPodium component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/41409/
Component|com_sef|'com_sef' Component for Joomla! 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|com_self|The 'com_sef' component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/41360/
Component|com_jomsocial|SocialAds for JomSocial Component 'Manage Your Ads' HTML Injection Vulnerability|x.x.x|x.x.x|Techjoomla SocialAds For JomSocial 1.0|Joomla! SocialAds for JomSocial component is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content.Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.|http://www.securityfocus.com/bid/41354/
Component|com_eventcal|eventCal Component for Joomla! 'Itemid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Kay Messerschmidt eventCal 1.6.4|eventCal Component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/41369/
Component|com_agora|Agora Pantheon 'task' Parameter Local File Include Vulnerability|x.x.x|x.x.x|jVitals Agora Pantheon 2.5.5|The Agora Pantheon component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/41463/
Component|com_addressbook|Front-edit Address Book Component 'Itemid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|B-Elektro Front-edit Address Book|Front-edit Address Book component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/41353/
Component|com_canteen|Miniwork Studio Canteen Component for Joomla! SQL Injection and Local File Include Vulnerabilities|x.x.x|x.x.x|Miniwork Studio Canteen 1.0|The Miniwork Studio Canteen component for Joomla! is prone to an SQL-injection vulnerability and a local file-include vulnerability because it fails to sufficiently sanitize user-supplied data.Attackers can exploit the SQL-injection vulnerability to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.An attacker can exploit the local file-include vulnerability using directory-traversal strings to view and execute arbitrary local files within the context of the webserver process. Information harvested may aid in further attacks.|http://www.securityfocus.com/bid/41358/
Component|com_booklibrary|OrdaSoft BookLibrary Books from same author Component for Joomla! SQL Injection Vulnerability|x.x.x|x.x.x|OrdaSoft BookLibrary Books from same author <= 1.5|The BookLibrary Books from same author component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/41350/
Component|plugins/system/mediaobject/js/mediaobject-150.js|Front-End Article Manager System Component Arbitrary File Upload Vulnerability|x.x.x|x.x.x|B-Elektro Front-End Article Manager System|The Front-End Article Manager System component for Joomla! is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to adequately sanitize user-supplied input.An attacker can exploit this vulnerability to upload arbitrary code and run it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.|http://www.securityfocus.com/bid/41351/
Component|com_seyret|Seyret Video Component 'view' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Joomlaholic Seyret Video|The Seyret Video component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/41357/
Component|com_joomdoc|oomDOC Component Information Disclosure Vulnerability|x.x.x|x.x.x|JoomDOC 2.0.2|The JoomDOC component for Joomla! is prone to an information-disclosure vulnerability.Successful exploits may allow attackers to obtain potentially sensitive information that may aid in other attacks.|http://www.securityfocus.com/bid/41317/
Component|com_seyret|Seyret Video Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomlaholic Seyret Video|Seyret Video component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/41324/
Component|com_dateconverter|AD/BS Date Converter 'Itemid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Geeknet Joomla AD/BS Date Converter 0.1|Joomla AD/BS Date Converter component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/41292/
Component|com_myblog|'com_myblog' Component Local File Include Vulnerability|x.x.x|x.x.x|Joomla com_myblog|The 'com_myblog' component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/41277/
Component|com_remository|Remository Component Multiple Local File Include Vulnerabilities|x.x.x|x.x.x|Black Sheep Research Remository|The Remository component for Joomla! is prone to multiple local file-include vulnerabilities because it fails to properly sanitize user-supplied input.An attacker can exploit these vulnerabilities to obtain potentially sensitive information and to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/41308/
Component|com_ckforms|CKForms Component SQL Injection and Arbitrary File Upload Vulnerabilities|x.x.x|x.x.x|Cookex Agency CKForms 1.3.4|The CKForms component for Joomla! is prone to multiple SQL-injection vulnerabilities and an arbitrary-file-upload vulnerability because it fails to sanitize user-supplied data.Exploiting these issues could allow an attacker to compromise the application, execute arbitrary code, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/41258/
Component|component/joomanager/|Joomanager Joomla Component 'catid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joommanager|The Joomanager component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/41256/
Component|com_wmtpic|Webmaster-Tips.net Flash Gallery for Joomla 'com_wmtpic' SQL Injection Vulnerability|x.x.x|x.x.x|Flash Gallery 1.0|Webmaster-Tips.net Flash Gallery for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/41253/
Component|com_booklibrary|BookLibrary Component Multiple SQL Injection Vulnerabilities|x.x.x|x.x.x|OrdaSoft BookLibrary Basic 1.5.3|The BookLibrary component for Joomla! is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/41264/
Component|com_gamesbox|Gamesbox 'com_gamesbox' Component SQL Injection Vulnerability|x.x.x|x.x.x|JOOFORGE Gamesbox <= 1.0.2|The Gamesbox 'com_gamesbox' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/41257/
Component|components/je-media-player.html|JE Media Player Component 'view' Parameter Local File Include Vulnerability|x.x.x|x.x.x|JExtensions JE Media player|The JE Media player component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/41173/
Component|propertyfinder/component/jesectionfinder/|JE Section/Property Finder Component 'view' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Joomla JE Section/Property Finder|The JE Section/Property Finder component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/41163/
Component|component/jeeventcalendar/|JE Event Calendar Component 'view' Parameter Local File Include Vulnerability|x.x.x|x.x.x|JE Event Calendar|The JE Event Calendar component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/41168/
Component|com_sef|'com_sef' Component Remote File Include Vulnerability|x.x.x|x.x.x|com_self|The 'com_sef' component for Joomla! is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/41166/
Component|com_awd_song|'com_awd_song' Component HTML Injection Vulnerability|x.x.x|x.x.x|Joomla JE Awd Song|Joomla! 'com_awd_song' component is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content.Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.|http://www.securityfocus.com/bid/41165/
Component|component/jesubmit/|JE Story Submit Component 'view' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla JE Story Submit 1.4|The JE Story Submit component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/41171/
Component|component/jeeventcalendar/|JE Ajax Event Calendar Component 'view' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla JE Ajax Event Calendar 1.0.5|The JE Ajax Event Calendar component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database|http://www.securityfocus.com/bid/41058/
Component|com_ybggal|YBG Gallery Component 'catid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Yusuf Bottie Gaos YBG Gallery 1.0|YBG Gallery component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database|http://www.securityfocus.com/bid/41033/
Component|com_picasa2gallery|Picasa2Gallery Joomla! Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Picasa2Gallery 1.2.8|The Picasa2Gallery component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/41031/
Component|com_jfaq|'Jfaq' Component SQL Injection and HTML Injection Vulnerabilities|x.x.x|x.x.x|Joomla Jfaq 1.2|The Joomla! 'Jfaq' component is prone to multiple SQL-injection vulnerabilities and an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied input.An attacker may leverage the HTML-injection issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials, control how the site is viewed, and launch other attacks.The attacker may exploit the SQL-injection issues to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/41029/
Component|com_jomsocial|JomSocial Joomla! Component Multiple HTML Injection Vulnerabilities|x.x.x|x.x.x|JomSocial 1.6.288|JomSocial Joomla! component is prone to multiple HTML-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.|http://www.securityfocus.com/bid/41010/
Component|com_jobline|Jobline Component 'Itemid' Parameter Cross Site Scripting Vulnerability|x.x.x|x.x.x|Olle Johansson Jobline 1.1.3.1|The Jobline component for Joomla! is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied input.Exploiting this vulnerability could allow an attacker to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.|http://www.securityfocus.com/bid/40996/
Component|com_cmsrealty|Transparent Technologies CMS Realty Component for Joomla! Cross-Site Scripting Vulnerability|x.x.x|x.x.x|Transparent Technologies CMS Realty 2.0.2|The Transparent Technologies CMS Realty component for Joomla! is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.|http://www.securityfocus.com/bid/40989/
Component|com_eportfolio|Belitsoft E-portfolio Joomla! Component Arbitrary File Upload Vulnerability|x.x.x|x.x.x|Belitsoft E-portfolio <= 1.5|The Belitsoft E-portfolio component for Joomla! is prone to a vulnerability that lets attackers upload arbitrary files. The issue occurs because the application fails to adequately validate user-supplied input.An attacker can exploit this vulnerability to upload arbitrary code and execute it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.|http://www.securityfocus.com/bid/40994/
Component|com_community|JomSocial 'com_community' Joomla! Component Status Field HTML Injection Vulnerability|x.x.x|x.x.x|JomSocial|The JomSocial 'com_community' Joomla! component is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.|http://www.securityfocus.com/bid/40997
Component|com_jomestate|'com_jomestate' Component 'task' Parameter Remote File Include Vulnerability|x.x.x|x.x.x|com_jomestate|The 'com_jomestate' component for Joomla! is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/41017/
Component|com_listbingo|Listbingo Component Cross Site Scripting and SQL Injection Vulnerabilities|x.x.x|x.x.x|Gobingoo 1.3.1|The Listbingo component for Joomla! is prone to an SQL-injection vulnerability and multiple cross-site scripting vulnerabilities.Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/40986/
Component|components/com_oziogallery2/|Ozio Gallery Joomla! Component Open Email Relay Vulnerability and Directory Traversal Vulnerability|x.x.x|x.x.x|Ozio Gallery Ozio Gallery 2.4|The Ozio Gallery component for Joomla! is prone to an open-email-relay vulnerability and a directory traversal vulnerability.An attacker could exploit this issue to gain access to sensitive information and to send unsolicited spam email to an unrestricted number of email addresses from a forged email address.|http://www.securityfocus.com/bid/40966/
Component|com_galleryxml|Gallery XML Joomla! Component SQL Injection and Local File Include Vulnerabilities|x.x.x|x.x.x|XML/SWF Gallery XML <= 1.1|The Gallery XML Joomla! component is prone to an SQL-injection vulnerability and a local file-include vulnerability because it fails to sufficiently sanitize user-supplied data.An attacker can exploit these vulnerabilities to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database; by using directory-traversal strings to execute local script code in the context of the application, the attacker may be able to obtain sensitive information that may aid in further attacks.|http://www.securityfocus.com/bid/40964/
Component|com_rss|RSComments Joomla! Component Multiple HTML Injection Vulnerabilities|x.x.x|x.x.x|Joomla RSComments 1.0|The RSComments Joomla! component is prone to multiple HTML-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.|http://www.securityfocus.com/bid/40977/
Component|com_chronocontact|'com_chronocontact' Component 'itemid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_chronocontact|The 'com_chronocontact' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/40504/
Component|com_chronoconnectivity|'com_chronoconnectivity' Component 'itemid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_chronoconnectivity|The 'com_chronoconnectivity' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/40500/
Component|com_sar_news|'com_sar_news' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_sar_news|The 'com_sar_news' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/40501/
Component|com_djartgallery|DJ-ArtGallery Component for Joomla! Cross-Site Scripting and SQL-Injection Vulnerabilities|x.x.x|x.x.x|Blue Constant Media DJ Art Gallery 0.9.1|The DJ-ArtGallery component for Joomla! is prone to a cross-site scripting vulnerability and an SQL-injection vulnerability because the application fails to sufficiently sanitize user-supplied input.A successful exploit can allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/40580/
Component|com_searchlog|'com_searchlog' Component 'search' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla com_searchlog 3.1|The 'com_searchlog' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/
Component|com_easygb|'com_easygb' Component 'Itemid' Parameter Cross Site Scripting Vulnerability|x.x.x|x.x.x|Joomla-addons.org Easy Guestbook|The 'com_easygb' component for Joomla! is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied input.Exploiting this vulnerability could allow an attacker to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.|http://www.securityfocus.com/bid/40860/
Component|com_jstore|'com_jstore' Component 'task' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_jstore|The 'com_jstore' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/40720/
Component|cd-hotel/Property-Cpanel.html|JReservation Component Cross Site Scripting Vulnerability|x.x.x|x.x.x|JForJoomla JReservation|The JForJoomla JReservation component for Joomla! is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied input.Exploiting this vulnerability could allow an attacker to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.|http://www.securityfocus.com/bid/40690/
Component|com_jtickets|'com_jtickets' Component 'task' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_jtickets|The 'com_jtickets' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/40724/
Component|com_jsubscription|Multiple Joobi Components for Joomla! 'task' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joobi Ltd jSubscription -jNews  - jMarket - jCommunity|Multiple Joobi components for Joomla! are prone to an SQL-injection vulnerability because they fail to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/40739/
Component|com_videowhisper_2wvc|'com_videowhisper_2wvc' Component Cross Site Scripting Vulnerability|x.x.x|x.x.x|VideoWhisper 2 Way Video Chat|The VideoWhisper 2 Way Video Chat component for Joomla! is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied input.Exploiting this vulnerability could allow an attacker to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.|http://www.securityfocus.com/bid/40828/
Component|com_answers|C-Logic Answers Joomla! Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Computer-Logic C-Logic Answers|The C-Logic Answers component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/40967/
Component|com_g2bridge|'com_g2bridge' Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|com_g2bridge|The 'com_g2bridge' component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/40440/
Component|com_jepoll|'com_jepoll' Component 'pollid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_jepoll|The 'com_jepoll' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/40436/
Component|com_jsjobs|JS Jobs Component 'cid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla JS Jobs 1.0.5 8|The JS Jobs component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/40471/
Component|com_quran|'com_quran' Component 'surano' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_quran|The 'com_quran' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/40433/
Component|com_bfquiztrial|BF Quiz Component 'catid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla BF Quiz 1.3|The BF Quiz component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/40435/
Component|com_mycar|My Car component for Joomla! Cross-Site Scripting and SQL-Injection Vulnerabilities|x.x.x|x.x.x|Emanuele Cappelletti My Cars 1.0|The My Car component for Joomla! is prone to a cross-site scripting vulnerability and an SQL-injection vulnerability because the application fails to sufficiently sanitize user-supplied input.A successful exploit may allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/40430/
Component|com_reservations|Reservations Joomla! Component 'namser' Parameter Cross-Site Scripting Vulnerability|x.x.x|x.x.x|Joomla Reservations|The Reservations component for Joomla! is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.|http://www.securityfocus.com/bid/40429/
Core||Multiple Modules 'search' Parameter Cross-Site Scripting Vulnerabilities|1.5.0|1.5.17||Joomla! is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.|http://www.securityfocus.com/bid/40444/
Component|com_mediqna|Medi-QnA Joomla! Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Famous Websites Medi-QnA 1.1|The Medi-QnA component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/40412/
Component|com_horses|'com_horses' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_horses|The 'com_horses' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/40308/
Component|com_perchaimageattach com_perchagallery com_perchafieldsattach  com_perchadownloadsattach  com_perchacategoriestree|Multiple Percha Components for Joomla 'controller' Parameter Local File Include Vulnerabilities|x.x.x|x.x.x|Percha com_perchaimageattach 1.1 - com_perchagallery 1.6 Beta -  com_perchafieldsattach 1.0 -  com_perchadownloadsattach 1.1 - com_perchacategoriestree 0.6|Multiple Percha components for Joomla are prone to multiple local file-include vulnerabilities because they fail to properly sanitize user-supplied input.An attacker can exploit these vulnerabilities to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/40244/
Component|com_activehelper_livehelp|ActiveHelper LiveHelp Component Multiple Cross-Site Scripting Vulnerabilities|x.x.x|x.x.x|ActiveHelper LiveHelp 2.0.3|The Joomla! ActiveHelper LiveHelp ('com_activehelper_livehelp') component is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.|http://www.securityfocus.com/bid/40278/
Component|com_jcomments|JoomlaTune JComments Joomla! Component 'ComntrNam' Parameter Cross-Site Scripting Vulnerability|x.x.x|x.x.x|JoomlaTune JComments 2.1|The JComments component for Joomla! is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.|http://www.securityfocus.com/bid/40230/
Component|com_event|'com_event' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_event|The 'com_event' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/40214/
Component|com_event|'com_event' Joomla! Component SQL Injection and Local File Include Vulnerabilities|x.x.x|x.x.x|com_event|The 'com_event' Joomla! component is prone to an SQL-injection vulnerability and a local file-include vulnerability because it fails to sufficiently sanitize user-supplied data.An attacker can exploit these vulnerabilities to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database; by using directory-traversal strings to execute local script code in the context of the application, the attacker may be able to obtain sensitive information that may aid in further attacks.|http://www.securityfocus.com/bid/40200/
Component|com_simpledownload|SimpleDownload Joomla! Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Joel Rowley SimpleDownload 0.9.5|The SimpleDownload component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/40192/
Component|com_jequoteform|'com_jequoteform' Component 'view' Parameter Local File Include Vulnerability|x.x.x|x.x.x|com_jequoteform|The 'com_jequoteform' component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/40187/
Component|com_camp|'com_camp' Component 'cid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_camp|The 'com_camp' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/40184/
Component|com_simpledownload|SimpleDownload Joomla! Component 'fileid' Parameter Information Disclosure Vulnerability|x.x.x|x.x.x|Joel Rowley SimpleDownload 0.9.5|The SimpleDownload component for Joomla! is prone to an information-disclosure vulnerability because it fails to sufficiently validate user-supplied data.An attacker can exploit this issue to view local files in the context of the webserver process. This may allow the attacker to obtain sensitive information; other attacks are also possible.|http://www.securityfocus.com/bid/40198/
Component|com_mscomment|MS Comment Joomla! Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Joomla MS Comment Component 0.8.0b|The MS Comment component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/40185/
Component|com_jejob|JE Job Joomla! Component 'catid' and 'Itemid' Parameters SQL Injection Vulnerabilities|x.x.x|x.x.x|JExtensions JE Job|The JE Job component for Joomla! is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/40193/
Component|com_jejob|JE Job Joomla! Component 'view' Parameter Local File Include Vulnerability|x.x.x|x.x.x|JExtensions JE Job|The JE Job component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/40178/
Component|com_konsultasi|'com_konsultasi' Component 'sid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_konsultasi|The 'com_konsultasi' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/40160/
Component|com_aardvertiser|Advertising Component 'file' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Joomla Advertisement 2.0|The Advertising component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/40153/
Component|com_dioneformwizard|Dione Form Wizard Component for Joomla! 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|DioneSoft.Com Dione Form Wizard 1.0.2|The Dione Form Wizard component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/40166/
Component|com_sebercart|Seber Cart Component for Joomla! 'getPic.php' Directory Traversal Vulnerability|x.x.x|x.x.x|Seber Seber Cart 1.0.0.12 - 1.0.0.14 - 1.0.0.15|The Seber Cart component for Joomla! is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks.|http://www.securityfocus.com/bid/40161/
Component|com_php|Custom PHP Pages Component 'file' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Joomla Custom PHP Pages|The Custom PHP Pages component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/40099/
Component|mod_visitordata|Visitor Data Component for Joomla! 'X-Forwarded-For' Header Remote Command Execution Vulnerability|x.x.x|x.x.x|Camp26 Visitor Data 1.1|The Visitor Data Component for Joomla! is prone to a vulnerability that attackers can leverage to execute arbitrary commands. This issue occurs because the application fails to adequately sanitize user-supplied input.Successful attacks can compromise the affected application and possibly the underlying computer.Visitor Data 1.1 is vulnerable; other versions may also be affected.|http://www.securityfocus.com/bid/40075/
Component|com_articleman|'com_articleman' Component Arbitrary File Upload Vulnerability|x.x.x|x.x.x|com_articleman|The 'com_articleman' component for Joomla! is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to adequately sanitize user-supplied input.An attacker can exploit this vulnerability to upload arbitrary code and run it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.|http://www.securityfocus.com/bid/40026/
Component|com_djclassifieds|DJ-Classifieds Component Arbitrary File Upload Vulnerability|x.x.x|x.x.x|Joomla DJ-Classifieds < 0.9.2|The DJ-Classifieds ('com_djclassifieds') component for Joomla! is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to adequately sanitize user-supplied input.An attacker can exploit this vulnerability to upload arbitrary code and run it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.|http://www.securityfocus.com/bid/39858/
Component|com_grid|'com_grid' Component Multiple Cross-Site Scripting Vulnerabilities|x.x.x|x.x.x|com_grid|The Joomla! 'com_grid' component is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.|http://www.securityfocus.com/bid/39854/
Component|com_newsfeeds|Newsfeeds Component 'feedid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla Newsfeeds Component|The Newsfeeds ('com_newfeeds') component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.This issue affects unknown versions of the Joomla! Newsfeeds component. This BID will be updated when more details become available.NOTE: Reports indicate that this issue is not exploitable.|http://www.securityfocus.com/bid/39834/
Component|wap/wapmain.php|Wap4Joomla Joomla! Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|David Jardin Wap4Joomla Beta 3|The Wap4Joomla component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39774/
Component|com_jesectionfinder|JE Section/Property Finder Component Arbitrary File Upload Vulnerability|x.x.x|x.x.x|Joomla JE Section/Property Finder|The JE Section/Property Finder ('com_jesectionfinder') component for Joomla! is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to adequately sanitize user-supplied input.An attacker can exploit this vulnerability to upload arbitrary code and run it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.|http://www.securityfocus.com/bid/39754/
Component|com_abc|ABC Joomla Extension com_abc 'index.php' SQL Injection Vulnerability|x.x.x|x.x.x|Airiny ABC Joomla Extension com_abc 1.1.7|ABC Joomla Extension com_abc is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39741/
Component|com_ultimateportfolio|Ultimate Portfolio Joomla! Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Webkul Ultimate Portfolio 1.0|The Ultimate Portfolio component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39739/
Component|com_graphics|oomla Graphics Joomla! Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Dmitry Lysohor Joomla Graphics 1.0.6|The Joomla Graphics component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39743/
Component|com_smartsite|SmartSite Joomla! Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Recly Interactive SmartSite|The Recly Interactive SmartSite component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39740/
Component|com_noticeboard|NoticeBoard Joomla! Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Code-Garage NoticeBoard 1.3|The NoticeBoard component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39742/
Core||Session Fixation Vulnerability|1.5.0|1.5.15||Joomla! is prone to a session-fixation vulnerability.Attackers can exploit this issue to hijack a user's session and gain unauthorized access to the affected application.|http://www.securityfocus.com/bid/39708/
Component|com_caddy|SimpleCaddy Component for Joomla! Unspecified Security Vulnerability|x.x.x|x.x.x|Henk von Pickartz SimpleCaddy 1.72|The SimpleCaddy (com_caddy) component for Joomla! is prone to an unspecified remote security vulnerability.Remote attackers can exploit this issue to perform unauthorized manipulation of certain data.|http://www.securityfocus.com/bid/39634/
Component|com_portfolio|PortfolioDesign.org Portfolio for Joomla! 'phpThumb.php' Remote File Disclosure Vulnerability|x.x.x|x.x.x|PortfolioDesign.org Portfolio 2.0.2|The PortfolioDesign.org Portfolio component for Joomla! is prone to a remote file-disclosure vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to view local files in the context of the webserver process, which may aid in further attacks.|http://www.securityfocus.com/bid/39620/
Component|com_wmi|Webmoney Web Merchant Interface Component for Joomla! Local File Include Vulnerability|x.x.x|x.x.x|PaySysPro Webmoney Web Merchant Interface|The Webmoney Web Merchant Interface component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39608/
Component|com_mmsblog|MMS Blog Component for Joomla! 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Joomla MMS Blog 2.3|The MMS Blog component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39607/
Component|com_orgchart|OrgChart Component for Joomla! 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Joomla OrgChart 1.0|The OrgChart component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39606/
Component|com_jtm|JTM Reseller Joomla! Component 'author' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|TM Reseller JTM Reseller 1.9 Beta|The JTM Reseller component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39584/
Component|com_jnewspaper|Online News Paper Manager Component Multiple SQL Injection Vulnerabilities|x.x.x|x.x.x|Emultisoft Web Solutions Online News Paper Manager 1.0|The Online News Paper Manager component for Joomla! is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39582/
Component|com_gbufacebook|GBU Facebook Joomla! Component 'face_id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|GBU grafici GBU Facebook 1.0.5|The GBU Facebook component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39576/
Component|com_google|google-joomla 3D map Joomla! Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|inetlanka google-joomla 3D map (com_google) 1.2|The google-joomla 3D map component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39560/
Component|com_gadgetfactory|Gadget Factory Joomla! Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|theFactory Gadget Factory 1.0|The Gadget Factory component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39547/
Component|com_zimbcore|ZiMB Manager Joomla! Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|ZiMB LLC. ZiMB Manager 0.1|The ZiMB Manager component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39546/
Component|com_if_surfalert|iF surfALERT Joomla! Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|inertialFATE iF surfALERT 1.2|The iF surfALERT component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39566/
Component|com_drawroot|inetlanka drawroot Joomla! Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|inetlanka drawroot 1.1|The inetlanka drawroot component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39562/
Component|option=com_multiroot|Multiple Root Joomla! Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Multiple Root Multiple Root 1.0|The Multiple Root component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39552/
Component|com_multimap|Multiple Map Joomla! Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Multiple Map Multiple Map 1.0|The Multiple Map component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39551/
Component|com_matamko|Matamko Joomla! Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Matamko Matamko 1.01|The Matamko component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39550/
Component|com_zimbcomment|ZiMB Comment Joomla! Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|ZiMB LLC. ZiMB Comment 0.8.1|The ZiMB Comment component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39548/
Component|com_archeryscores|Archery Scores Component for Joomla! 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Lispeltuut Archery Scores 1.0.6|The Archery Scores component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39545/
Component|com_joltcard|'com_joltcard' Component 'cardID' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|JOLT media com_joltcard|The 'com_joltcard' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39541/
Component|com_pandafminigames|'com_pandafminigames' Component Multiple SQL Injection Vulnerabilities|x.x.x|x.x.x|com_pandafminigames|The 'com_pandafminigames' component for Joomla! is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39542/
Component|com_manager|'com_manager' Component 'Itemid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla com_manager 1.5.3|The 'com_manager' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39519/
Component|com_iproperty|Intellectual Property Joomla! Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|the Thinkery Intellectual Property 1.5.3|The Intellectual Property component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39495/
Component|com_beeheardlite com_beeheard|BeeHeard Components for Joomla! 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|CMS Tactics BeeHeard Lite (com_beeheardlite) 1.0 - (com_beeheard) 1.0|The BeeHeard Lite 'com_beeheardlite' and BeeHeard 'com_beeheard' components for Joomla! are prone to a local file-include vulnerability because they fail to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39506/
Component|com_blogfactory|Deluxe Blog Factory Joomla! Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|theFactory Deluxe Blog Factory (com_blogfactory) 1.1.2|The Deluxe Blog Factory component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39508/
Component|com_delicious|Delicious Joomla! Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|e-builds' attic Delicious 0.0.1|The Delicious component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39513/
Component|com_lovefactory|Love Factory Component for Joomla! 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Love Factory Love Factory 1.3.4|The Love Factory component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39512/
Component|com_mtfireeagle|MT Fire Eagle Component for Joomla! 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Moto-Treks MT Fire Eagle 1.2|The MT Fire Eagle component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39509/
Component|com_photobattle|Photo Battle Joomla! Component 'view' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Photo Battle Photo Battle 1.0.1|The Photo Battle component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39504/
Component|com_s5clanroster|S5 Clan Roster 'com_s5clanroster' Joomla! Component Multiple Local File Include Vulnerabilities|x.x.x|x.x.x|Shape 5 S5 Clan Roster|The S5 Clan Roster 'com_s5clanroster' component for Joomla! is prone to multiple local file-include vulnerabilities because it fails to properly sanitize user-supplied input.An attacker can exploit these vulnerabilities to obtain potentially sensitive information and to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39503/
Component|com_wgpicasa|wgPicasa Joomla! Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|wgJoomla wgPicasa 1.0|The wgPicasa component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39497/
Component|com_mediamall|media Mall Factory Joomla! Component 'category' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|theFactory media Mall Factory (com_mediamall) 1.0.4|The media Mall Factory component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39488/
Component|com_jacomment|JA Comment Joomla! Component 'view' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Joomlart JA Comment|The JA Comment component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39516/
Component|com_qpersonel|'com_qpersonel' Component 'katid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla com_qpersonel 1.02|The 'com_qpersonel' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39466/
Component|com_allvideos|JoomlaWorks AllVideos Joomla! Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|JoomlaWorks AllVideos|The AllVideos component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39375/
Component|com_arcadegames|Arcade Games Component 'index.php' Local File Include Vulnerability|x.x.x|x.x.x|Joomla com_arcadegames 1.0|The Arcade Games component 'com_arcadegames' for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/40176/
Component|com_mv_restaurantmenumanager|Multi-Venue Restaurant Menu Manager Joomla! Component 'mid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Focusplus Developments Multi-Venue Restaurant Menu Manager 1.5.2 Stable Update 3|The Multi-Venue Restaurant Menu Manager component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39382/
Component|com_agenda|Projects Agenda Component for Joomla! 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla! Projects Agenda 1.0.1|The Joomla! Projects Agenda component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39380/
Component|com_onlineexam|Online Examination Component 'index.php' Local File Include Vulnerability|x.x.x|x.x.x|Joomla com_onlineexam 1.5|The Online Examination component 'com_onlineexam' for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/40177/
Component|com_market|Online Market Joomla! Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Joomla Online Market 2.0|The Online Market component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/40175/
Component|com_ca|'com_ca' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_ca|The 'com_ca' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39373/
Component|com_sermonspeaker|SermonSpeaker Joomla! Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|SermonSpeaker 3.3.1|The SermonSpeaker component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39410/
Component|com_jvehicles|Jvehicles Component for Joomla! Component 'aid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Jvehicles Jvehicles <= 2.0|The Jvehicles component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39409/
Component|com_flexicontent|FLEXIcontent Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|FLEXIcontent 1.5|The FLEXIcontent component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39408/
Component|com_sweetykeeper|Sweety Keeper Joomla! Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|JoomlaCorner Sweety Keeper|The Sweety Keeper component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39399/
Component|com_market|Agile Technologies Components for Joomla! 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Agile Technologies Online Market (com_market) 2.x|An attacker can exploit this vulnerability to obtain potentially sensitive information and to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/40175/
Component|com_flashgames|Agile Technologies Components for Joomla! 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Agile Technologies Online Flash Games! (com_flashgames) 1.5|An attacker can exploit this vulnerability to obtain potentially sensitive information and to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/40175/
Component|com_memory|Agile Technologies Components for Joomla! 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Agile Technologies Memory Book! (com_memory) 1.2|An attacker can exploit this vulnerability to obtain potentially sensitive information and to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/40175/
Component|com_worldrates|Agile Technologies Components for Joomla! 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Agile Technologies com_worldrates|An attacker can exploit this vulnerability to obtain potentially sensitive information and to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/40175/
Component|com_record|Agile Technologies Components for Joomla! 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Agile Technologies com_record|An attacker can exploit this vulnerability to obtain potentially sensitive information and to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/40175/
Component|com_onlineexam|Agile Technologies Components for Joomla! 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Agile Technologies com_onlineexam 1.5|An attacker can exploit this vulnerability to obtain potentially sensitive information and to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/40175/
Component|com_myfiles|Agile Technologies Components for Joomla! 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Agile Technologies com_myfiles 1.0|An attacker can exploit this vulnerability to obtain potentially sensitive information and to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/40175/
Component|com_joommail|Agile Technologies Components for Joomla! 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Agile Technologies com_joommail 1.0|An attacker can exploit this vulnerability to obtain potentially sensitive information and to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/40175/
Component|com_diary|Agile Technologies Components for Joomla! 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Agile Technologies com_diary 1.5|An attacker can exploit this vulnerability to obtain potentially sensitive information and to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/40175/
Component|com_cvmaker|Agile Technologies Components for Joomla! 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Agile Technologies com_cvmaker version 1.0|An attacker can exploit this vulnerability to obtain potentially sensitive information and to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/40175/
Component|com_arcadegames|Agile Technologies Components for Joomla! 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Agile Technologies com_arcadegames 1.0|An attacker can exploit this vulnerability to obtain potentially sensitive information and to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/40175/
Component|com_advertising|Agile Technologies Components for Joomla! 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Agile Technologies com_advertising 0.25|An attacker can exploit this vulnerability to obtain potentially sensitive information and to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/40175/
Component|com_addressbook|Agile Technologies Components for Joomla! 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Agile Technologies com_addressbook 1.5|An attacker can exploit this vulnerability to obtain potentially sensitive information and to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/40175/
Component|com_preventive|Preventive and Reservation Joomla! Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Ternaria Informatica Preventive and Reservation 1.0.5|The Preventive and Reservation component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39387/
Component|com_spsnewsletter|'com_spsnewsletter' Component for Joomla! 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|com_spsnewsletter|The modernbridge 'com_spsnewsletter' component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39388/
Component|com_tweetla|TweetLA Joomla! Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Peter Hocherl TweetLA 1.0.1|The TweetLA component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39386/
Component|com_travelbook|TRAVELbook Joomla! Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Peter Hocherl TRAVELbook 1.0.1|The TRAVELbook component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39385/
Component|com_jprojectmanager|JProject Manager Joomla! Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Ternaria Informatica JProject Manager 1.0|The JProject Manager component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39383/
Component|com_webeecomment|Webee Comments Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Joomla Webee Comments 2.0|The Webee Comments component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39342/
Component|com_articles|'com_articles' Component 'sid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_articles|The 'com_articles' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39307/
Component|com_realtyna|Realtyna Translator Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Realtyna Translator 1.0.14|The Realtyna Translator component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39337/
Component|com_foobla_suggestions|foobla Suggestions Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Joomla foobla Suggestions 1.5.1 2|The foobla Suggestions component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39341/
Component|com_pcchess|PC Chess Joomla! Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Joomla Resource PC Chess 0.7|The PC Chess component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39367/
Component|com_huruhelpdesk|Huru Helpdesk Joomla! Component 'cid[0]' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|James R. Erickson Huru Helpdesk 0.88|The Huru Helpdesk component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39366/
Component|com_properties|'com_properties' Component 'aid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_properties|The 'com_properties' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39374/
Component|com_rokmodule|RocketTheme RokModule Joomla! Component 'moduleid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|RocketTheme RokModule 1.1|The RocketTheme RokModule component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39378/
Component|com_jajobboard|JA Job Board 'com_jajobboard' Joomla! Component Multiple Local File Include Vulnerabilities|x.x.x|x.x.x|JA Job Board jajobboard 1.4.4|The JA Job Board 'com_jajobboard' component for Joomla! is prone to multiple local file-include vulnerabilities because it fails to properly sanitize user-supplied input.An attacker can exploit these vulnerabilities to obtain potentially sensitive information and to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39384/
Component|com_jfeedback|Jfeedback! Joomla! Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Ternaria Informatica Jfeedback! 1.2|The Jfeedback! component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39390/
Component|com_alphauserpoints|AlphaUserPoints Joomla! Component 'view' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Alphaplug AlphaUserPoints 1.5.5|The AlphaUserPoints component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39393/
Component|com_awdwall|AWD Solution AWDwall Component for Joomla! 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|AWD Solution AWDwall <= 1.5.4|The AWD Solution AWDwall component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the underlying computer; other attacks are also possible.|http://www.securityfocus.com/bid/39331/
Component|com_javoice|JA Voice Component 'view' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Joomla JA Voice|The JA Voice component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39343/
Component|com_vjdeo|VJDEO Component for Joomla! 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Ternaria VJDEO 1.0|The VJDEO component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39266/
Component|com_awiki|aWiki Component for Joomla! 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Joomlish aWiki 3.1 beta|The aWiki component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39267/
Component|com_joomlaflickr|joomla-flickr Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Roberto Aloi joomla-flickr <= 1.0.3|The joomla-flickr component is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39251/
Component|com_jukebox|JOOFORGE Jukebox Component for Joomla! 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|JOOFORGE com_jukebox 1.7|The JOOFORGE Jukebox component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39248/
Component|com_datafeeds|Affiliate Feeds Component for Joomla! 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Affiliate Feeds Affiliate Feeds|The Affiliate Feeds component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39246/
Component|com_jwhmcs|J!WHMCS Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Gohigheris J!WHMCS 1.5|The J!WHMCS component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39243/
Component|com_hsconfig|Highslide JS Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Joomla Highslide JS|The Highslide JS component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39239/
Component|com_sebercart|Seber Cart Component 'view' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Seber Seber Cart 1.0.0.12|The Seber Cart component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39237/
Component|com_news_portal|News Portal Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|iJoomla News Portal 1.5|The News Portal component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39222/
Component|com_fss|Freestyle FAQ Lite Component 'faqid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla Freestyle FAQ Lite 1.3|The Freestyle FAQ Lite component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39220/
Component|com_fabrik|Fabrik Component 'index.php' Local File Include Vulnerability|x.x.x|x.x.x|Fabrik Fabrik 2.0|The Fabrik component 'com_fabrik' for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/40328/
Component|com_serie|'com_serie' Component 'spielerid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_serie|The 'com_serie' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39217/
Component|com_xobbix|'com_xobbix' Component 'prodid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_xobbix|The 'com_xobbix' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39259/
Component|com_appointment|The Best Makers Appointment Component for Joomla! Local File Include Vulnerability|x.x.x|x.x.x|thebestmakers Appointment 1.5|The Appointment component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39254/
Component|com_svmap|'com_svmap' Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|com_svmap|The 'com_svmap' component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39214/
Component|com_shoutbox|'com_shoutbox' Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|com_shoutbox|The 'com_shoutbox' component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39213/
Component|com_loginbox|'com_loginbox' Component 'view' Parameter Local File Include Vulnerability|x.x.x|x.x.x|com_loginbox|The 'com_loginbox' component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39212/
Component|com_bca-rss-syndicator|'com_bca-rss-syndicator' Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|com_bca-rss-syndicator|The 'com_bca-rss-syndicator' component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39208/
Component|com_joomlaupdater|'com_joomlaupdater' Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|com_joomlaupdater|The 'com_joomlaupdater' component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39207/
Component|com_jinventory|JInventory Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|JoomlaMo JInventory 1.23.2|The JInventory component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39203/
Component|com_jp_jobs|'com_jp_jobs' Component 'id' Parameter SQL Injection Vulnerabili|x.x.x|x.x.x|Joomla com_jp_jobs 1.4.1|The 'com_jp_jobs' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39191/
Component|com_menu|'com_menu' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_menu|The 'com_menu' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39184/
Component|com_joomlapicasa2|Picasa Component Local File Include Vulnerability|x.x.x|x.x.x|Roberto Aloi Joomla! Picasa 2.0|The Joomla! Picasa component is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to view and execute arbitrary local files in the context of the webserver process. This may aid in further attacks.|http://www.securityfocus.com/bid/39200/
Component|com_ranking|'com_ranking' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_ranking|The 'com_ranking' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39195/
Component|com_redshop|'com_redshop' Component 'view' Parameter Local File Include Vulnerability|x.x.x|x.x.x|com_redshop|The 'com_redshop' component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39206/
Component|com_redtwitter|'com_redtwitter' Component 'view' Parameter Local File Include Vulnerability|x.x.x|x.x.x|com_redtwitter|The 'com_redtwitter' component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39211/
Component|com_wisroyq|'com_wisroyq' Component 'controller' Parameter Local File Include Vulnera|x.x.x|x.x.x|com_wisroyq|The 'com_wisroyq' component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39210/
Component|com_football|'com_football' Component 'leagueID' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_football|The 'com_football' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39190/
Component|com_tour|'com_tour' Component 'cid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_tour|The 'com_tour' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39146/
Component|com_trading|'com_trading' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_trading|The 'com_trading' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39143/
Component|com_weberpcustomer|webERPcustomer Component for Joomla! Local File Include Vulnerability|x.x.x|x.x.x|JoomlaMo webERPcustomer 1.2.1|The webERPcustomer component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39178/
Component|com_jvehicles|Jvehicles Component for Joomla! Local File Include Vulnerability|x.x.x|x.x.x|Jvehicles Jvehicles 1.0|The Jvehicles component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39177/
Component|com_econtent|E-Content Component for Joomla! Local File Include Vulnerability|x.x.x|x.x.x|E-Contents Manager E-Content 1.0.1|The E-Content component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39176/
Component|com_userstatus|User Status Component for Joomla! Local File Include Vulnerability|x.x.x|x.x.x|JoomlaMo User Status 1.21.16|The User Status component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39174/
Component|com_forme|'com_forme' Component 'fid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_forme|The 'com_forme' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39173/
Component|com_network|'com_network' Component 'cid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_network|The 'com_network' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39147/
Component|com_dwgraphs|DW Graph Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Joomla DW Graph 1.0|The DW Graph component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/39108/
Component|com_guide|'com_guide' Component 'season' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_guide|The 'com_guide' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39055/
Component|com_actions|'com_actions' Component 'actionid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_actions|The 'com_actions' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39057/
Component|com_spec|'com_spec' Component 'pro_id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_spec|The 'com_spec' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39050/
Component|com_items|'com_items' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_items|The 'com_items' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39100/
Component|com_television|'com_television' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_television|The 'com_television' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39098/
Component|com_xmap|'com_xmap' Component 'Itemid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_xmap|The 'com_xmap' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39035/
Component|com_radio|'com_radio' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_radio|The 'com_radio' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39010/
Component|com_business|'com_business' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_business|The 'com_business' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39009/
Component|com_departments|'com_departments' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_departments|The 'com_departments' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39008/
Component|com_weblinks|'com_weblinks' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_weblinks|The 'com_weblinks' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39032/
Component|com_units|'com_units' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_units|The 'com_units' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39006/
Component|com_teacher|'com_teacher' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_teacher|The 'com_teacher' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39003/
Component|com_science|'com_science' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_science|The 'com_science' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39002/
Component|com_agency|'com_agency' Component 'aid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_agency|The 'com_agency' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39001/
Component|com_topmenu|'com_topmenu' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_topmenu|The 'com_topmenu' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39000/
Component|com_adds|'com_adds' Component 'catid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_adds|The 'com_adds' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38999/
Component|com_personal|'com_personal' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_personal|The 'com_personal' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39005/
Component|com_tariff|'com_tariff' Component 'detail' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_tariff|The 'com_tariff' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/39004/
Component|com_dcs_flashgames|dcsFlashGames Component 'catid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Adam Corley dcsFlashGames|The dcsFlashGames component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38981/
Component|com_solution|'com_solution' Component 'con' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_solution|The 'com_solution' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38997/
Component|com_jresearch|'com_jresearch' Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|com_jresearch|The 'com_jresearch' component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/38917/
Component|com_software|'com_software' Component 'software_id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_software|The 'com_software' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38942/
Component|com_wallpapers|'com_wallpapers' Component 'cid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_wallpapers|The 'com_wallpapers' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38941/
Component|com_universal|'com_universal' Component 'mosConfig_absolute_path' Remote File Include Vulnerability|x.x.x|x.x.x|Joomla com_universal 1.0|The 'com_universal' component for Joomla! is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/38949/
Component|com_cb|'com_cb' Component 'cat' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_cb|The 'com_cb' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38916/
Component|com_aml_2|'com_aml_2' Component 'art' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_aml_2|The 'com_aml_2' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38914/
Component|com_cx|'com_cx' Component 'postid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_cx|The 'com_cx' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38915/
Component|com_properties|'com_properties' Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|com_properties|The 'com_properties' component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/38912/
Component|com_smestorage|SMEStorage 'com_smestorage' Component for Joomla! Local File Include Vulnerability|x.x.x|x.x.x|Roman Gelembjuk SMEStorage 1.0|The SMEStorage component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/38911/
Component|com_gds|'com_gds' Component 'sid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_gds|The 'com_flash' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38910/
Component|com_flash|'com_flash' Component 'sid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_flash|The 'com_flash' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38890/
Component|com_giftexchange|Gift Exchange Component 'pkg' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Socialables Gift Exchange 1.0beta|The Gift Exchange ('com_giftexchange') component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38869/
Component|com_jeformcr|'com_jeformcr' Component 'view' Parameter Local File Include Vulnerability|x.x.x|x.x.x|com_jeformcr|The 'com_jeformcr' component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/38866/
Component|com_vxdate|VXDate Component for Joomla! Cross-Site Scripting and SQL-Injection Vulnerabilities|x.x.x|x.x.x|VXDate|VXDate Component for Joomla! is prone to a cross-site scripting vulnerability and an SQL-injection vulnerability because the application fails to sufficiently sanitize user-supplied input.A successful exploit may allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38788/
Component|com_include|'com_include' Component 'ID_NLE' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_include|The 'com_include' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38784/
Component|com_ckforms|'com_ckforms' Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Cookex Agency CKForms 1.3.3|The 'com_ckforms' component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/38783/
Component|com_alert|'com_alert' Component 'q_item' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_alert|The 'com_alert' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38827/
Component|com_ckforms|CKForms Component 'fid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Cookex Agency CKForms 1.3.3|The CKForms component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38785/
Component|com_as|'com_as' Component 'catid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_as|The 'com_as' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38757/
Component|com_route|'com_route' Component 'kid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_route|The 'com_route' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38754/
Component|com_sectionex|Stack Ideas 'com_sectionex' Component for Joomla! Local File Include Vulnerability|x.x.x|x.x.x|Stack Ideas com_sectionex|The 'com_sectionex' component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/38751/
Component|com_ganalytics|'com_ganalytics' Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|com_ganalytics|The 'com_ganalytics' component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/38749/
Component|com_linkr|'com_linkr' Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|com_linkr|The 'com_linkr' component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/38747/
Component|com_janews|'com_janews' Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|com_janews|The 'com_janews' component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/38746/
Component|com_rpx|Ulti Joomla Ulti RPX Joomla! Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Ulti Joomla Ulti RPX 2.1|The Ulti Joomla Ulti RPX component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/38743/
Component|com_gcalendar|G4J GCalendar Suite Joomla! Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|G4J GCalendar Suite 2.1.5|The G4J GCalendar Suite component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information or execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/38742/
Component|com_rokdownloads|RokDownloads Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|RocketTheme RokDownloads < 1.0|The RokDownloads component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/38741/
Component|com_org|'com_org' Component 'letter' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_org|The 'com_org' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38736/
Component|com_org|'com_org' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_org|The 'com_org' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38726/
Component|com_nfnaddressbook|'com_nfnaddressbook' Component 'record_id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_nfnaddressbook|The 'com_nfnaddressbook' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38724/
Component|com_ninjarsssyndicator|Ninja RSS Syndicator Component Local File Include Vulnerability|x.x.x|x.x.x|Ninja RSS Syndicator 1.0.8|The Ninja RSS Syndicator component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|chttp://www.securityfocus.com/bid/38761/
Component|com_bidding|'com_bidding' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_bidding|The 'com_bidding' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38755/
Component|com_juliaportfolio|'com_juliaportfolio' Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|com_juliaportfolio|The 'com_juliaportfolio' component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/38715/
Component|com_d-greinar|'com_d-greinar' Component 'maintree' Parameter Cross-Site Scripting Vulnerability|x.x.x|x.x.x|com_d-greinar|The Joomla! 'com_d-greinar' component is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.|http://www.securityfocus.com/bid/38714/
Component|com_sbsfile|'com_sbsfile' Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|com_sbsfile|The 'com_sbsfile' component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/38713/
Component|com_seek|'com_seek' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|'com_seek' Component 'id' Parameter SQL Injection Vulnerability|The 'com_seek' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38711/
Component|com_races|'com_races' Component 'raceId' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_races|The 'com_races' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38712/
Component|com_family|'com_family' Component 'categoryid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_family|The 'com_family' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38695/
Component|com_start|'com_start' Component 'mitID' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_start|The 'com_start' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38693/
Component|com_leader|'com_leader' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_leader|The 'com_leader' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38694/
Component|com_gigfe|'com_gigfe' Component 'styletype' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_gigfe|The 'com_gigfe' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38681/
Component|com_party|'com_party' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_party|The 'com_party' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38679/
Component|com_blog|'com_blog' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_blog|The 'com_blog' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38668/
Component|com_acstartseite|'com_acstartseite' Component SQL Injection Vulnerability|x.x.x|x.x.x|com_acstartseite|The 'com_acstartseite' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38269/
Component|com_acteammember|'com_acteammember' Component SQL Injection Vulnerability|x.x.x|x.x.x|com_acteammember|The 'com_acteammember' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38270/
Component|plugins/system/cdscriptegrator/libraries/highslide/js/jsloader.php|Core Design Scriptegrator Component Local File Include Vulnerability|x.x.x|x.x.x|Core Design Scriptegrator|The Core Design Scriptegrator component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/38296/
Component|com_otzivi|'com_otzivi' Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|com_otzivi|The 'com_otzivi' component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/38295/
Component|com_communitypolls|Core Joomla Community Polls Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Core Joomla Community Polls 1.5.2|The Core Joomla Community Polls component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/38330/
Component|com_recipe|'com_recipe' Component Multiple SQL Injection Vulnerabilities|x.x.x|x.x.x|com_recipe|The 'com_recipe' component for Joomla! is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|The 'com_recipe' component for Joomla! is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Component|com_sqlreport|'com_sqlreport' Component SQL Injection Vulnerability|x.x.x|x.x.x|com_sqlreport|The 'com_sqlreport' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38361/
Component|com_hdflvplayer|HD FLV Player Component for Joomla! 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|hdflvplayer.net HD FLV Player|The HD FLV Player component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38401/
Component|com_yanc|'com_yanc' Component 'listid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_yanc|The 'com_yanc' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38454/
Component|com_myblog|'com_myblog' Component 'task' Parameter Local File Include Vulnerability|x.x.x|x.x.x|com_myblog|The 'com_myblog' component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/38530/
Component|com_hezacontent|'com_hezacontent' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_hezacontent 1.0|The 'com_hezacontent' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38618/
Component|com_about|'com_about' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_about|The 'com_about' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38653/
Component|com_color|'com_color' Component 'l' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_color|The 'com_color' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38680/
Component|com_products|'com_products' Component 'intCategoryId' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_products|The 'com_products' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38682/
Component|com_rwcards|'com_rwcards' Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|com_rwcards|The 'com_rwcards' component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/38267/
Component|com_hdvideoshare|'com_hdvideoshare' Component 'secid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_hdvideoshare|The 'com_hdvideoshare' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38244/
Component|com_videos|'com_videos' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_videos|The 'com_videos' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38243/
Component|plugins/content/jw_allvideos/includes/download.php|JoomlaWorks AllVideos Joomla! Component Directory Traversal Vulnerability|x.x.x|x.x.x|JoomlaWorks AllVideos|The AllVideos component for Joomla! is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.Exploiting the issue may allow an attacker to obtain sensitive information that could aid in further attacks.|http://www.securityfocus.com/bid/38238/
Component|com_flashmagazinedeluxe|'com_flashmagazinedeluxe' Component 'mag_id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_flashmagazinedeluxe|The 'com_flashmagazinedeluxe' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38246/
Component|com_webeecomment|Webee Component SQL Injection and HTML Injection Vulnerabilities|x.x.x|x.x.x|Joomla Webee <= 1.2|The Joomla! Webee component is prone to an SQL-injection vulnerability and HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input.An attacker may leverage the HTML-injection issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials, control how the site is viewed, and launch other attacks.The attacker may exploit the SQL-injection issue to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38204/
Component|com_jquarks|JQuarks Component SQL Injection Vulnerability|x.x.x|x.x.x|IP-Tech JQuarks <= 0.2.3|The JQuarks component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38203/
Component|com_easybook|EasyBook Component Multiple HTML Injection Vulnerabilities|x.x.x|x.x.x|Easy-Joomla! EasyBook 2.0.0rc4|Joomla! EasyBook component is prone to multiple HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in dynamically generated content.Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.|http://www.securityfocus.com/bid/38209/
Component|com_kide|Kide Shoutbox Security Bypass Vulnerability|x.x.x|x.x.x|JoniJnm Kide Shoutbox 0.4.6|The Joomla! Kide Shoutbox component is prone to a security-bypass vulnerability.Attackers can exploit this vulnerability to bypass certain security restrictions and gain unauthorized access to the affected application in the context of another user.|http://www.securityfocus.com/bid/38206/
Component|com_zcalendar|'com_zcalendar' Component 'eid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_zcalendar|The 'com_zcalendar' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38192/
Component|com_photoblog|'com_photoblog' Component 'blog' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|webguerilla Photoblog <= alpha 3b|The 'com_photoblog' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38136/
Component|com_productbook|'com_productbook' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_productbook|The 'com_productbook' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38137/
Component|com_yelp|'com_yelp' Component 'cid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla JEvents Search plugin 1.5.2com_yelp|The 'ccom_yelp' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38022/
Component|com_dms|Documents Seller Component 'category_id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Ossolution Team Document Seller 2.5.1|The Documents Seller component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38024/
Component|com_autartitarot|AutartiTarot Component Directory Traversal Vulnerability|x.x.x|x.x.x|Autartica AutartiTarot|The AutartiTarot component for Joomla! is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.Exploiting the issue may allow an attacker to obtain sensitive information that could aid in further attacks.NOTE: Successful exploitation requires having 'Public Back-end' group credentials.|http://www.securityfocus.com/bid/38034/
Component|com_gambling|'com_gambling' Component 'gamblingEvent' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_gambling|The 'com_gambling' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38033/
Component|com_jequizmanagement|JE Quiz Component 'eid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|JExtensions JE Quiz 1.b01|The JE Quiz component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38032/
Component|com_job|'com_job' Component 'id_job' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_job|The 'com_job' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38031/
Component|com_simplefaq|'com_simplefaq' Component 'catid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_simplefaq|The 'com_simplefaq' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38015/
Component|com_jeeventcalendar|'com_jeeventcalendar' Component 'event_id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_jeeventcalendar|The 'com_jeeventcalendar' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38012/
Component|com_dms|'com_dms' Component 'category_id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_dms|The 'com_dms' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38017/
Component|com_ccnewsletter|'com_ccnewsletter' Component Local File Include Vulnerability|x.x.x|x.x.x|Chill Creations com_ccnewsletter 1.0.5|The 'com_ccnewsletter' component for Joomla! is prone to a local file-include vulnerability because it fails to sufficiently sanitize user-supplied input data.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/37987/
Component|?v= &v=|jVideoDirect Component for Joomla! 'v' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|jVideoDirect jVideoDirect 1.1 RC3b|The jVideoDirect component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37990/
Component|plugins/editors/tinymce/jscripts/tiny_mce/plugins/tinybrowser/folders.php|TinyBrowser Joomla! Component 'folders.php' Local File Include Vulnerability|x.x.x|x.x.x|Lunarvis TinyBrowser 1.41.6|The TinyBrowser component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/
Component|com_casino|'com_casino' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_casino|The 'com_casino' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37938/
Component|com_ContentBlogList|'com_ContentBlogList' Component Multiple SQL Injection Vulnerabilities|x.x.x|x.x.x|oomla ContentBlogList 1.3|The 'com_ContentBlogList' component for Joomla! is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37937/
Component|?newyear= &newyear=|JBDiary Component Multiple SQL Injection Vulnerabilities|x.x.x|x.x.x|Joomla JBDiary 1.6|The JBDiary component for Joomla! is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37936/
Component|com_gameserver|'com_gameserver' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_gameserver|The 'com_gameserver' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37934/
Component|com_jbpublishdownfp|JbPublishDownFp Component 'cid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla JbPublishDownFp 1.4|The JbPublishDownFp component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37932/
Component|?view=mochigames &view=mochigames|Mochigames Component 'cid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla Mochigames 0.51|The Mochigames component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37931/
Component|com_gurujibook|'com_gurujibook' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_gurujibook|The 'com_gurujibook' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37933/
Component|?view=gameserver &view=gameserver|Game Server Component 'grp' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|IndianPulse Game Server 1.0|The Game Server component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37920/
Component|com_biographies|'com_biographies' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_biographies|The 'com_biographies' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37922/
Component|com_book|'com_book' Component 'cid[]' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_book|The 'com_book' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37907/
Component|com_acprojects|'com_acprojects' Component SQL Injection Vulnerability|x.x.x|x.x.x|com_acprojects|The 'com_acprojects' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37897/
Component|com_uploader|'com_uploader' Component Arbitrary File Upload Vulnerability|x.x.x|x.x.x|com_uploader|The 'com_uploader' component for Joomla! is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to adequately sanitize user-supplied input.An attacker can exploit this vulnerability to upload arbitrary code and run it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.|http://www.securityfocus.com/bid/37840/
Component|com_marketplace|'com_marketplace' Component 'catid' Parameter Cross-Site Scripting Vulnerability|x.x.x|x.x.x|Joomla com_marketplace 1.2|The Joomla! 'com_marketplace' component is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.|http://www.securityfocus.com/bid/37819/
Component|com_tienda|'com_tienda' Component 'categoria' Parameter Cross-Site Scripting Vulnerability|x.x.x|x.x.x|com_tienda|The Joomla! 'com_artistavenue' component is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.|http://www.securityfocus.com/bid/37798/
Component|com_articlemanager|'com_articlemanager' Component 'artid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_articlemanager|The 'com_articlemanager' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37799/
Component|com_jashowcase|'com_jashowcase' Component Directory Traversal Vulnerability|x.x.x|x.x.x|com_jashowcase|The 'com_jashowcase' component for Joomla! is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.Exploiting the issue may allow an attacker to obtain sensitive information that could aid in further attacks.|http://www.securityfocus.com/bid/37692/
Component|com_jcollection|'com_jcollection' Component Directory Traversal Vulnerability|x.x.x|x.x.x|com_jcollection|The 'com_jcollection' component for Joomla! is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.Exploiting the issue may allow an attacker to obtain sensitive information that could aid in further attacks.|http://www.securityfocus.com/bid/37691/
Component|com_dashboard|'com_dashboard' Component Directory Traversal Vulnerability|x.x.x|x.x.x|com_dashboard|The 'com_dashboard' component for Joomla! is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.Exploiting the issue may allow an attacker to obtain sensitive information that could aid in further attacks.|http://www.securityfocus.com/bid/37689/
Component|com_jvideodirect|'com_jvideodirect' Component Directory Traversal Vulnerability|x.x.x|x.x.x|com_jvideodirect|The 'com_jvideodirect' component for Joomla! is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.Exploiting the issue may allow an attacker to obtain sensitive information that could aid in further attacks.|http://www.securityfocus.com/bid/37694/
Component|com_ksadvertiser|KISS Software Advertiser Component for Joomla! 'pid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|KISS Software Advertiser 1.5.2 RC2|The KISS Software Advertiser component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37682/
Component|com_livechat|Live Chat Joomla! Component 'last' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joompolitan Live Chat|The Live Chat component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37681/
Component|com_jobads|Jobads 'type' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla Jobads|The Jobads component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37686/
Component|com_dm_orders|DM Orders Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla DM Orders|he DM Orders component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37655/
Component|com_dms|Document Seller for Docman 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Ossolution Team Document Seller for Docman 2.1|The Document Seller for Docman component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37660/
Component|com_kk|'com_kk' Joomla! Component 'kat' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_kk|The 'com_kk' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37645/
Component|com_perchagallery|'com_perchagallery' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_perchagallery|The 'com_perchagallery' component for Joomla is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37642/
Component|com_jembed|jEmbed Component 'catid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla jEmbed|The jEmbed component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37627/
Component|com_bfsurvey_pro|BF Survey Pro 'catid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Tamlyn Creative BF Survey Pro|The BF Survey Pro component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/37584/
Component|com_j-projects|J-Projects Component 'project' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla J-ProjectsThe J-Projects component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.|The J-Projects component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37608/
Component|com_doqment|'com_doqment' Joomla! Component 'cid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|RSJoomla! com_doqment|The 'com_doqment' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37606/
Component|com_cartikads|'com_cartikads' Component Arbitrary File Upload Vulnerability|x.x.x|x.x.x|Cartika Hosting com_cartikads 2.0|The 'com_cartikads' component for Joomla! is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to adequately sanitize user-supplied input.An attacker can exploit this vulnerability to upload arbitrary code and run it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.|http://www.securityfocus.com/bid/37604/
Component|com_smf|Shape5 Bridge of Hope Template for Joomla! 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Shape5 Bridge of Hope Template|The Shape5 Bridge of Hope template for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37602/
Component|com_dailymeals|Dailymeals Joomla! Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Alexander Schell Dailymeals|The Dailymeals component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/37596/
Component|index.php?option=com_content&view=article&id=|joomlabamboo JB Simpla Joomla! Template 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|joomlabamboo JB Simpla|JB Simpla template for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.UPDATE (February 3, 2010): The vendor indicates that this issue is not exploitable as described.|http://www.securityfocus.com/bid/37579/
Component|com_avosbillets|'com_avosbillets' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_avosbillets|The 'com_avosbillets' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37576/
Component|com_cartweberp|CARTwebERP Joomla! Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Joomla CARTwebERP|The CARTwebERP component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/37581/
Component|com_tpjobs|'com_tpjobs' Component 'id_c[]' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_tpjobs|The 'com_tpjobs' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37591/
Component|com_alfresco|http://www.securityfocus.com/bid/37591/|x.x.x|x.x.x|Alfresco Software Joomla! Module for Alfresco 1.0|Joomla! Module for Alfresco is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37578/
Component|com_otzivi|'com_otzivi' Component 'Itemid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_otzivi|The 'com_otzivi' component for Joomla is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37595/
Component|com_bfsurvey_pro|BF Survey Pro 'catid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Tamlyn Creative BF Survey Pro|Joomla! BF Survey Pro component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37585/
Component|com_bfsurvey|'com_bfsurvey' Joomla! Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|com_bfsurvey|The 'com_bfsurvey' component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/37572/
Component|com_aprice|'com_aprice' Component 'analog' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_aprice|The 'com_aprice' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37575/
Component|com_biblestudy|Bible Study Joomla! Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Tom Fuller Bible Study 6.1|The Bible Study component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/37583/
Component|rd_download.php|Run Digital Download Component for Joomla! Unspecified Unauthorized Access Vulnerability|x.x.x|x.x.x|run digital Download 0.5|The Run Digital Download component for Joomla! is prone to an unspecified unauthorized-access vulnerability.Exploiting this issue could allow attackers to gain unauthorized access to the affected application.|http://www.securityfocus.com/bid/37548/
Component|com_rd_download|'com_rd_download' Component Directory Traversal Vulnerability|x.x.x|x.x.x|com_rd_download|The 'com_rd_download' component for Joomla! is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.Exploiting the issue may allow an attacker to obtain sensitive information that could aid in further attacks.|http://www.securityfocus.com/bid/37538/
Component|com_airmonoblock|'com_airmonoblock' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_airmonoblock|The 'com_airmonoblock' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37542/
Component|com_artistavenue|'com_artistavenue' Component 'Itemid' Parameter Cross-Site Scripting Vulnerability|x.x.x|x.x.x|com_artistavenue|The Joomla! 'com_artistavenue' component is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.|http://www.securityfocus.com/bid/37537/
Component|com_noticia|'com_noticia' Component 'Itemid' Parameter Cross-Site Scripting Vulnerability|x.x.x|x.x.x|com_noticia|The Joomla! 'com_noticia' component is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.|http://www.securityfocus.com/bid/37526/
Component|com_qpersonel|Q-Personel Component 'personel_sira' Parameter Cross-Site Scripting Vulnerability|x.x.x|x.x.x|Q-Proje Q-Personel 1.0.2(RC2)|The Q-Personel component for Joomla! is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.Q-Personel 1.0.2(RC2) is vulnerable; other versions may be affected as well.|http://www.securityfocus.com/bid/37503/
Component|com_kkcontent|'com_kkcontent' Component 'catID' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_kkcontent|The 'com_kkcontent' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37527/
Component|com_beeheard|BeeHeard Component 'category_id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|BeeHeard|The BeeHeard component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37495/
Component|com_calendario|'com_calendario' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_calendario|The 'com_calendario' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37493/
Component|com_webcamxp|'com_webcamxp' Component 'Itemid' Parameter Cross-Site Scripting Vulnerability|x.x.x|x.x.x|Andy Stewart com_webcamxp|The Joomla! 'com_webcamxp' component is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.|http://www.securityfocus.com/bid/37480/
Component|modules/mod_joomulus/tagcloud.swf|Joomulus Component 'tagcloud.swf' Cross-Site Scripting Vulnerability|x.x.x|x.x.x|Joomla Bear Joomulus 2.0|The Joomulus component for Joomla! is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.|http://www.securityfocus.com/bid/37479/
Component|com_jm-recommend|'com_jm-recommend' Component 'Itemid' Parameter Cross-Site Scripting Vulnerability|x.x.x|x.x.x|imedevnet com_jm-recommend|The Joomla! 'com_jm-recommend' component is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.|http://www.securityfocus.com/bid/37478/
Component|com_facileforms|'com_facileforms' Component 'Itemid' Parameter Cross-Site Scripting Vulnerability|x.x.x|x.x.x|Limedevnet com_facileforms|The Joomla! 'com_facileforms' component is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.|http://www.securityfocus.com/bid/37477/
Component|com_trabalhe_conosco|'com_trabalhe_conosco' Component 'Itemid' Parameter Cross-Site Scripting Vulnerability|x.x.x|x.x.x|Limedevnet com_trabalhe_conosco|The Joomla! 'com_trabalhe_conosco' component is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.|http://www.securityfocus.com/bid/37476/
Component|com_kif_nexus|iF Portfolio Nexus 'controller' Parameter Remote File Include Vulnerability|x.x.x|x.x.x|inertialFATE iF Portfolio Nexus|The iF Portfolio Nexus ('com_if_nexus') component for Joomla! is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/37473/
Component|com_dhforum|'com_dhforum' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|'com_dhforum' Component 'id' Parameter SQL Injection Vulnerability|The 'com_dhforum' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37475/
Component|com_memory|Memory Book Component for Joomla! SQL Injection and Arbitrary File Upload Vulnerabilities|x.x.x|x.x.x|Agile Technologies Memory Book 1.2|The Memory Book component for Joomla! is prone to an SQL-injection vulnerability and an arbitrary-file-upload vulnerability.Exploiting these issues could allow an attacker to compromise the application, upload arbitrary files, execute arbitrary code, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37496/
Component|com_adagency|'com_adagency' Joomla! Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|com_adagency|The 'com_adagency' component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/37499/
Component|com_schools|'com_schools' Component 'schoolid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_schools|The 'com_schools' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37469/
Component|com_carman|Webformatique Car Manager Joomla! Component 'msg' Parameter Cross Site Scripting Vulnerability|x.x.x|x.x.x|webformatique Car Manager <= 2.1|The Webformatique Car Manager component for Joomla! is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.|http://www.securityfocus.com/bid/37458/
Component|index.php?view=longview&catid=|JEEMA Article Collection Component 'catid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|JEEMA Web Solutions JEEMA Article Collection|The JEEMA Article Collection component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37449/
Component|com_digistore|DigiStore Component Multiple SQL Injection Vulnerabilities|x.x.x|x.x.x|Joomla DigiStore|The DigiStore component for Joomla! is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37433/
Component|components/com_jcalpro/cal_popup.php|JCal Pro Component 'mosConfig_absolute_path' Parameter Remote File Include Vulnerability|x.x.x|x.x.x|Anything Digital Development JCal Pro 1.5.3.6|The JCal Pro component for Joomla! is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/37438/
Component|com_hotbrackets|HotBrackets Tournament Brackets Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla HotBrackets Tournament Brackets|The HotBrackets Tournament Brackets component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37439/
Component|com_mediaslide|'com_mediaslide' Component Directory Traversal Vulnerability|x.x.x|x.x.x|com_mediaslide|The 'com_mediaslide' component for Joomla! is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.Exploiting the issue may allow an attacker to obtain sensitive information that could aid in further attacks.|http://www.securityfocus.com/bid/37440/
Component|com_eventmanager|Event Manager Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|JForJoomla Event Manager 1.5|The Event Manager component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37426/
Component|com_jbook|'com_jbook' Component 'Itemid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_jbook|The 'com_jbook' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38199/
Component|com_personel|'com_personel' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_personel|The 'com_personel' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37404/
Component|com_joomportfolio|'com_joomportfolio' Component 'secid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_joomportfolio|The 'com_joomportfolio' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37403/
Component|com_acmisc|'com_acmisc' Component 'Itemid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_acmisc|The 'com_acmisc' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38210/
Component|com_jphoto|'com_jphoto' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_jphoto|The 'com_jphoto' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37279/
Component|com_mamboleto/mamboleto.php|Mamboleto Component 'mamboleto.php' Remote File Include Vulnerability|x.x.x|x.x.x|Fernando Soares Mamboleto 2.0 RC3|The Mamboleto component for Joomla! is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/37280/
Component|com_jsjobs|JS Jobs Component Multiple SQL Injection Vulnerabilities|x.x.x|x.x.x|Joomla JS Jobs 1.0.5 .6|The JS Jobs component for Joomla! is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37281/
Component|com_job|'com_job' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_job|The 'com_job' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37254/
Component|yt_color|YOOtheme Warp5 Joomla! Component 'yt_color' Parameter Cross Site Scripting Vulnerability|x.x.x|x.x.x|YOOtheme Warp5|The Warp5 component for Joomla! is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.|http://www.securityfocus.com/bid/37239/
Component|created_by_alias=|You!Hostit! Template Cross-Site Scripting Vulnerability|x.x.x|x.x.x|Youjoomla You!Hostit! 1.0.1|The Joomla! You!Hostit! template is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.|http://www.securityfocus.com/bid/37260/
Component|com_mojo|mojoBlog Component Multiple Remote File Include Vulnerabilities|x.x.x|x.x.x|Joomla mojoBlog RC0.15|The mojoBlog component for Joomla! is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied input.Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/37179/
Component|com_kide|'Kide' Component 'Shoutbox' Parameter HTML Injection Vulnerability|x.x.x|x.x.x|JoniJnm.es Kide Shoutbox 0.4.6|The kide component of Joomla is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input.Attacker-supplied HTML and script code could be executed in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.|http://www.securityfocus.com/bid/41955/
Component|com_joaktree|Joaktree Component 'treeId' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla Joaktree 1.0|The Joaktree component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37178/
Component|com_quicknews|Quick News Component 'newsid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla Quick News|The Quick News component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37161/
Core||404 Error Page Cross Site Scripting Vulnerability|1.5.0|1.5.11||Joomla! is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.|http://www.securityfocus.com/bid/37148/
Component|com_musicgallery|http://www.securityfocus.com/bid/37148/|x.x.x|x.x.x|Itamar Elharar MusicGallery|The MusicGallery component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37146/
Component|com_lyftenbloggie|LyftenBloggie Joomla! Component 'pid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Lyften Designs LyftenBloggie 1.0.4|The LyftenBloggie component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37140/
Component|com_gcalendar|GCalendar Joomla! Component 'gcid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|G4J GCalendar 2.1.4|The GCalendar component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37141/
Component|com_gcalendar|Google Calendar Component 'gcid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla Google Calendar 1.1.2|The Google Calendar ('com_gcalendar') component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37134/
Component|com_mygallery|'com_mygallery' Component 'cid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_mygallery|The 'com_mygallery' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37121/
Component|services/portfolio?view=item&id= services/portfolio?controller=sections&view=item&id=|iF Portfolio Nexus Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|inertialFATE iF Portfolio Nexus|The iF Portfolio Nexus component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37050/
Component|com_joomclip|JoomClip Component 'cat' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla JoomClip|The JoomClip component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37049/
Component|components/com_ezine/class/php/d4m_ajax_pagenav.php|eZine Component 'd4m_ajax_pagenav.php' Remote File Include Vulnerability|x.x.x|x.x.x|Design for Joomla! eZine 2.1|The eZine component for Joomla! is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/37043/
Component|com_jumi|'com_jumi' Component for Joomla! Backdoor Vulnerability|x.x.x|x.x.x|com_jumi|The 'com_jumi' component for Joomla is prone to a backdoor vulnerability.Attackers can exploit this issue to execute arbitrary commands in the context of the application. Successful attacks will compromise the affected application and possibly the webserver or computer.|http://www.securityfocus.com/bid/36883/
Component|com_photoblog|'com_photoblog' Component 'category' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|webguerilla Photoblog alpha 3a|The 'com_photoblog' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/36809/
Component|com_jshop|'com_jshop' Component 'pid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_jshop|The 'com_jshop' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/36808/
Component|com_ajaxchat|Ajax Chat Component 'ajcuser.php' Remote File Include Vulnerability|x.x.x|x.x.x|Fiji Web Design Ajax Chat 1.0|The Ajax Chat component for Joomla! is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/36731/
Component|com_booklibrary|com_booklibrary Component 'releasenote.php' Remote File Include Vulnerability|x.x.x|x.x.x|Joomla com_booklibrary 1.0|The 'com_booklibrary' component for Joomla! is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/36732/
Component|com_jd-wp|JD-WordPress Component 'wp-feed.php' Remote File Include Vulnerability|x.x.x|x.x.x|Joomla JD-WordPress 2.0 RC2|The JD-WordPress component for Joomla! is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/36730/
Component|com_awdwall|AWD Wall Component 'cbuser' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|AWD Solution AWDwall 1.5 - 1.5.4|The AWD Wall ('com_awdwall') component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38194/
Component|com_recerca|'com_recerca' SQL Injection Vulnerability|x.x.x|x.x.x|com_recerca|The 'com_recerca' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/36627/
Component|com_soundset|Soundset Component 'cat_id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Soundset Soundset 1.0|The Soundset (com_soundset) component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/36597/
Component|com_cbresumebuilder|CB Resume Builder 'group_id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|JoomlaCache CB Resume Builder|The CB Resume Builder ('com_cbresumebuilder') component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/36598/
Component|com_icrmbasicdemo|iCRM Basic Joomla! Component Security Bypass and SQL Injection Vulnerabilities|x.x.x|x.x.x|iCRM Basic iCRM Basic 1.4.2.31|iCRM Basic is prone to a security-bypass vulnerability and an SQL-injection vulnerability because it fails to adequately sanitize user-supplied input.Exploiting the security-bypass issue may allow an attacker to bypass certain security restrictions and perform unauthorized actions. The attacker can exploit the SQL-injection issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database. This may compromise the application and may aid in further attacks.|http://www.securityfocus.com/bid/36533/
Component|com_fastball|Fastball Component SQL Injection Vulnerability|x.x.x|x.x.x|Fastball Productions Fastball 1.2|The Fastball component ('com_fastball') for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/36520/
Component|com_tupinambis|Tupinambis Component SQL Injection Vulnerability|x.x.x|x.x.x|Tupinambis 1.0|The Tupinambis component ('com_tupinambis') for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/36511/
Component|com_sportfusion|SportFusion Component SQL Injection Vulnerability|x.x.x|x.x.x|Kinfusion SportFusion <= 0.2.3|The SportFusion component ('com_sportfusion') for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/36481/
Component|com_facebook|JoomlaFacebook Component SQL Injection Vulnerability|x.x.x|x.x.x|JoomlaFacebook|The JoomlaFacebook component ('com_facebook') for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/36484/
Component|com_surveymanager|Survey Manager Component SQL Injection Vulnerability|x.x.x|x.x.x|Focusplus Developments Survey Manager 1.5|The Survey Manager ('com_surveymanager') component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/36464/
Component|com_jinc|'com_jinc' Component 'newsid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Lhacky! Extensions Cave JINC 0.2|The 'com_jinc' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/36471/
Component|index.php?view=videos&type=member&user_id=|MyRemote Video Gallery 'user_id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Jomtube Team MyRemote Video Gallery 1.0 Beta|The MyRemote Video Gallery component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/36470/
Component|com_jbudgetsmagic|JBudgetsMagic 'bid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla JBudgetsMagic <= 0.4|The JBudgetsMagic component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/36461/
Component|com_fbb|F!BB Component SQL Injection and HTML Injection Vulnerabilities|x.x.x|x.x.x|Joomla F!BB 1.5.96 RC|The Joomla! F!BB component is prone to an SQL-injection vulnerability and HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input.An attacker may leverage the HTML-injection issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials, control how the site is viewed, and launch other attacks.The attacker may exploit the SQL-injection issue to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/38220/
Component|com_album|'com_album' Joomla! Component Local File Include Vulnerability|x.x.x|x.x.x|Joomla com_album 1.14|The 'com_album' component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.|http://www.securityfocus.com/bid/36441/
Component|com_jreservation|JForJoomla JReservation Joomla! Component 'pid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|JForJoomla JReservation|The JForJoomla JReservation component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/36446/
Component|com_koesubmit|'com_koesubmit' Mambo/Joomla! Component 'koesubmit.php' Remote File Include Vulnerability|x.x.x|x.x.x|com_koesubmit|The 'com_koesubmit' Mambo/Joomla! component is prone to a remote file-include vulnerability because is fails to sufficiently sanitize user-supplied input.Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/36447/
Component|com_foobla_suggestions|Foobla Suggestions Component 'idea_id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Foobla Suggestions 1.5.11|The Foobla Suggestions component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/36425/
Component|com_turtushout|TurtuShout Component SQL Injection Vulnerability|x.x.x|x.x.x|TurtuShout 0.11|The TurtuShout component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/36414/
Component|com_djcatalog|djCatalog Component Multiple SQL Injection Vulnerabilities|x.x.x|x.x.x|Joomla djCatalog 1.5.x|The djCatalog component for Joomla! is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/36412/
Component|com_jlord_rs|Foobla RSS Feed Creator Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Foobla RSS Feed Creator|The Foobla RSS Feed Creator component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/36427/
Component|com_hbssearch|Hotel Booking System Multiple Cross Site Scripting and SQL Injection Vulnerabilities|x.x.x|x.x.x|Joomla HBS Hotel Booking System 1.5|The Hotel Booking System module for Joomla! is prone to a cross-site scripting vulnerability and multiple SQL-injection vulnerabilities because the application fails to sufficiently sanitize user-supplied input.Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/36380/
Component|components/com_alphauserpoints/assets/ajax/checkusername.php index.php?option=com_user&view=reset&tmpl=component|AlphaUserPoints Component 'username2points' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Alphaplug AlphaUserPoint|The AlphaUserPoints component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/36383/
Component|com_mediaalert|'com_mediaalert' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_mediaalert|The 'com_mediaalert' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/36356/
Component|com_pressrelease|'com_pressrelease' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_pressrelease|The 'com_pressrelease' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/36351/
Component|com_speech|'com_speech' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_speech|The 'com_speech' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/36352/
Component|com_lucygames|Lucy Games Component 'gameid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Lucy Games Lucy Games 1.5.4|The Lucy Games component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/36334/
Component|com_joomloc|Joomloc Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|L-aubrotel Web Services Joomloc 1.0|The Joomloc component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/36322/
Component|com_tpdugg|TPDugg Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|TemplatePlaza.com TPDugg 1.1|The TPDugg component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/36321/
Component|com_joomlub|Joomlub Component 'aid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|L-aubrotel Web Services Joomlub|The Joomlub component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/36287/
Component|com_gameserver|Game Server Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|IndianPulse Game Server 1.0|The Game Server component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/36213/
Component|com_artportal|Art Portal Component 'portalid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Artetics.com Art Portal 1.0|The Art Portal component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/36206/
Component|com_digifolio|DigiFolio Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|UWiX Joomla! Extensions DigiFolio 1.52|The DigiFolio component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/36172/
Component|com_wats|Webamoeba Ticket System Component HTML-Injection Vulnerability|x.x.x|x.x.x|Webamoeba Webamoeba Ticket System 3.0|The Joomla! Webamoeba Ticket System component is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input.Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.|http://www.securityfocus.com/bid/38258/
Component|com_siirler|Siirler Bileseni Component 'sid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Q-Proje Siirler Bileseni 1.2.RC|The Siirler Bileseni component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/36127/
Component|com_jtips|jTips ('com_jtips') Component 'season' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_jtips|The jTips 'com_jtips' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/36123/
Component|com_ninjamonial|'com_ninjamonial' Component 'testimID' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|NinjaForge.com NinjaMonials 1.1|The 'com_ninjamonial' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/36122/
Core|com_content|'com_content' Component 'ItemID' Parameter SQL Injection Vulnerability|1.0.0|1.0.0||Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/36064/
Component|com_kunena|Kunena ('com_kunena') Joomla! Component 'func' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Kunena Team Kunena 1.5.4|The Kunena 'com_kunena' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/36020/
Component|com_jfusion|JFusion ('com_jfusion') Component 'Itemid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|JFusion JFusion 1.1.1 Beta|The JFusion 'com_jfusion' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/35912/
Component|com_mscomment|MS Comment Component Security Bypass and Cross-Site Scripting Vulnerabilities|x.x.x|x.x.x|Joomla MS Comment Component 0.8.0b|The MS Comment component for Joomla! is prone to a security-bypass vulnerability because it fails to properly sanitize user-supplied input. The component is also prone to a security-bypass vulnerability because it fails to reset the CAPTCHA after a submission.An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.|http://www.securityfocus.com/bid/38250/
Core|com_mailto|'com_mailto' Timeout Protection Security Bypass Vulnerability|1.5.0|1.5.13||The 'com_mailto' component of Joomla! is prone to a remote security-bypass vulnerability.An attacker may leverage the issue to use webservers that are hosting the vulnerable software to send unsolicited email.|http://www.securityfocus.com/bid/35899/
Component|com_testimonialku|Joomlaku Testimonialku Component for Joomla! Multiple HTML Injection Vulnerabilities|x.x.x|x.x.x|Joomlaku Testimonialku Component 2.0|The Joomlaku Testimonialku component for Joomla! is prone to multiple HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in dynamically generated content.Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.|http://www.securityfocus.com/bid/38230/
Component|com_groups|Permis ('com_groups') Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla permis 1.0|The Permis 'com_groups' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/35849/
Component|com_user|'com_user' Component 'view' Parameter URI Redirection Vulnerability|x.x.x|x.x.x|com_user|The 'com_user' component for Joomla! is prone to a remote URI-redirection vulnerability because the application fails to properly sanitize user-supplied input.A successful exploit may aid in phishing attacks.|http://www.securityfocus.com/bid/35836/
Component|com_aclassf|Almond Classifieds Component for Joomla! Cross-Site Scripting and SQL-Injection Vulnerabilities|x.x.x|x.x.x|AlmondSoft.Com Almond Classifieds Component for Joomla! 7.5|Almond Classifieds Component for Joomla! is prone to a cross-site scripting vulnerability and an SQL-injection vulnerability because the application fails to sufficiently sanitize user-supplied input.A successful exploit may allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/35815/
Component|ajaxim/|UIajaxIM Component Arbitrary Script Injection Vulnerability|x.x.x|x.x.x|Universal Informatique UIajaxIM 1.1|The 'UIajaxIM' component for Joomla! is prone to a vulnerability that an attacker could exploit to execute arbitrary script code in the context of the webserver. The issue occurs because the component fails to properly sanitize user-supplied input.Successful exploits may compromise the application.|http://www.securityfocus.com/bid/35798/
Component|com_joomloads|'com_joomloads' Component 'packageId' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_joomloads|The 'com_joomloads' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/35784/
Core||Remote File Upload Vulnerability And Information Disclosure Weakness|1.5.1|1.5.12||Joomla! is prone to a remote file-upload vulnerability and an information-disclosure weakness.Attackers can exploit these issues to obtain sensitive information or to upload arbitrary code and execute it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.|http://www.securityfocus.com/bid/35780/
Component|com_jobline|Jobline Component 'search' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Olle Johansson Jobline 1.1.3 .1|The Jobline component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/35728/
Component|com_category|'com_category' Component SQL Injection Vulnerability|x.x.x|x.x.x|com_category|The 'com_category' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/35638/
Component|com_propertylab|'com_propertylab' Component 'auction_id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_propertylab|The 'com_propertylab' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/35622/
Core||Cross Site Scripting and Information Disclosure Vulnerabilities|1.5.0|1.5.11||Joomla! is prone to multiple cross-site scripting and information-disclosure vulnerabilities.An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, and obtain sensitive information.|http://www.securityfocus.com/bid/35544/
Component|com_bookflip|BookFlip Component 'book_id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|F-Cimag-In BookFlip 2.1|The BookFlip component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/35519/
Component|com_k2|K2 Component 'category' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|JoomlaWorks K2 1.0.1 beta|The K2 component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/35517/
Component|com_php|'joomla-php' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Fiji Web Design joomla-php|The 'joomla-php' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/35515/
Component|com_pinboard|PinME! Joomla! Component 'task' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|PinME! 2.1|The PinME component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/35493/
Component|com_amocourse|'com_amocourse' Component 'catid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_amocourse|The Joomla! 'com_amocourse' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/35489/
Component|com_pinboard|PinME! Joomla! Component Arbitrary File Upload Vulnerability|x.x.x|x.x.x|PinME! 2.1|The PinME! component for Joomla! and Mambo is prone to a vulnerability that lets attackers upload arbitrary files. The issue occurs because the application fails to adequately validate user-supplied input.An attacker can exploit this vulnerability to upload arbitrary code and execute it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.|http://www.securityfocus.com/bid/35485/
Component|com_tickets|Joomla! and Mambo Tickets Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Tickets Tickets <= 2.1|The Tickets component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/35460/
Component|com_acajoom|Acajoom Component for Mambo/Joomla! Backdoor Vulnerability|x.x.x|x.x.x|Joobi Ltd Acajoom 4.0 - 3.2.6|Acajoom is prone to a backdoor vulnerability.Attackers can exploit this issue to execute arbitrary commands in the context of the application. Successful attacks will compromise the affected application and possibly the webserver or computer.|http://www.securityfocus.com/bid/35459/
Component|com_jumi|'com_jumi' Component 'fileid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_jumi|The Joomla! 'com_jumi' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/35384/
Component|com_vehiclemanager|OrdaSoft Joomla! Components 'mosConfig_absolute_path' Remote File Include Vulnerability|x.x.x|x.x.x|OrdaSoft Vehicle Manager Basic 1.0|OrdaSoft Joomla! components are prone to a remote file-include vulnerability because they fail to sufficiently sanitize user-supplied input.Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/35269/
Component|com_realestatemanager|OrdaSoft Joomla! Components 'mosConfig_absolute_path' Remote File Include Vulnerability|x.x.x|x.x.x|OrdaSoft Real Estate Manager Basic 1.0|OrdaSoft Joomla! components are prone to a remote file-include vulnerability because they fail to sufficiently sanitize user-supplied input.Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/35269/
Component|com_booklibrary|OrdaSoft Joomla! Components 'mosConfig_absolute_path' Remote File Include Vulnerability|x.x.x|x.x.x|OrdaSoft BookLibrary Basic 1.5.2.4|OrdaSoft Joomla! components are prone to a remote file-include vulnerability because they fail to sufficiently sanitize user-supplied input.Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/35269/
Component|com_media_library|OrdaSoft Joomla! Components 'mosConfig_absolute_path' Remote File Include Vulnerability|x.x.x|x.x.x|OrdaSoft MediaLibrary Basic 1.5.3 |OrdaSoft Joomla! components are prone to a remote file-include vulnerability because they fail to sufficiently sanitize user-supplied input.Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/35269/
Component|com_akobook|AkoBook Component 'Itemid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Arthur Konze AkoBook 2.3|The Joomla! AkoBook component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/35268/
Component|com_sh404sef|sh404SEF Component URI Cross-Site Scripting Vulnerability|x.x.x|x.x.x|Yannick Gaultier sh404SEF|The sh404SEF component for Joomla! is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.|http://www.securityfocus.com/bid/38191/
Component|com_moofaq|Ideal MooFAQ Joomla! Component 'file_includer.php' Local File Include Vulnerability|x.x.x|x.x.x|Ideal MooFAQ 1.0|The MooFAQ component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the underlying computer; other attacks are also possible.|http://www.securityfocus.com/bid/35259/
Component|com_school|ComSchool Component 'classid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|ComSchool ComSchool 1.4|The Joomla! ComSchool component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/35257/
Component|com_mosres|Joomla! and Mambo 'com_mosres' Component Multiple SQL Injection Vulnerabilities|x.x.x|x.x.x|Momres Component 1.0f|The 'com_momres' component for Joomla! and Mambo is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/35202/
Component|com_omphotogallery|Omilen Photo Gallery Joomla! Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|Omnilen IT Solutions Omnilen Photo Gallery 0.5b|The Omilen Photo Gallery component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the underlying computer; other attacks are also possible.|http://www.securityfocus.com/bid/35201/
Component|com_seminar|Seminar for Joomla! 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Dirk Vollmar Seminar for Joomla! 1.28|Seminar for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/35192/
Component|com_juser|JUser Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla Equipment JUser 2.0.4|The Joomla! JUser component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/35160/
Component|com_jvideo|JVideo! Component 'user_id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Infinovision JVideo! <= 0.4|The Joomla! JVideo! component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/35146/
Component|com_agoragroup|AgoraGroups Joomla! Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|JoomlaMe AgoraGroups 0.3.5 .3|The AgoraGroups module for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/35118/
Component|com_rsgallery2|RSGallery2 Component for Mambo/Joomla! Backdoor Vulnerability|x.x.x|x.x.x|RSGallery2 RsGallery2 <= 1.14.3|RSGallery2 is prone to a backdoor vulnerability.Attackers can exploit this issue to execute arbitrary commands in the context of the application. Successful attacks will compromise the affected application and possibly the webserver or computer.|http://www.securityfocus.com/bid/35106/
Component|com_bsadv|Boy Scout Advancement 'id' Parameter Multiple SQL Injection Vulnerabilities|x.x.x|x.x.x|Boy Scout Advancement 0.3|Boy Scout Advancement (BSAdv) for Joomla! is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/35087/
Component|com_casino_blackjack|Casino Component 'Itemid' Parameter Multiple SQL Injection Vulnerabilities|x.x.x|x.x.x|Oddish Technologies Casino 0.3.1|The Casino component for Joomla! is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/35041/
Component|com_gsticketsystem|com_gsticketsystem 'catid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_gsticketsystem|The 'com_gsticketsystem' module for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/35025/
Component|com_artforms|ArtForms Joomla! Component 'mosConfig_absolute_path' Multiple Remote File Include Vulnerabilities|x.x.x|x.x.x|InterJoomla ArtForms 2.1b7|The ArtForms Joomla! component is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying computer; other attacks are also possible.|http://www.securityfocus.com/bid/34986/
Component|com_aclassf|Almond Classifieds for Joomla! 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|AlmondSoft.Com Almond Classifieds Component for Joomla! 5.6.2|Almond Classifieds for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/34843/
Component|com_rsmonials|RSMonials Joomla! Component Multiple HTML Injection Vulnerabilities|x.x.x|x.x.x|RS Web Solutions RSMonials 1.5.1|The RSMonials component for Joomla! is prone to multiple HTML-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.|http://www.securityfocus.com/bid/34684/
Component|com_cmimarketplace|cmimarketplace Component 'viewit' Parameter Directory Traversal Vulnerability|x.x.x|x.x.x|Magnetic Merchandising Inc. cmimarketplace 0.1|The 'cmimarketplace' component for Joomla! is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.Exploiting the issue may allow an attacker to obtain sensitive information that could aid in further attacks.|http://www.securityfocus.com/bid/34431/
Component|com_gigcal|Joomla! and Mambo gigCalendar Component 'banddetails.php' SQL Injection Vulnerability|x.x.x|x.x.x|gigCalendar 1.0|The gigCalendar component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/33859/
Component|com_gigcal|Joomla! and Mambo gigCalendar Component 'venuedetails.php' SQL Injection Vulnerability|x.x.x|x.x.x|gigCalendar 1.0|The gigCalendar component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/33863/
Component|com_reservation|Webformatique Reservation Manager Joomla! Component 'ItemID' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|webformatique Reservation Manager Pro 1.1.1 - 1.7|The Webformatique Reservation Manager component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/33976/
Component|com_carman|Webformatique Car Manager Joomla! Component 'ItemID' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|webformatique Car Manager 2.1|The Webformatique Car Manager component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.Car Manager 2.1.0 is vulnerable; other versions may also be affected.|http://www.securityfocus.com/bid/33978/
Component|com_shoutbox|Djice Shoutbox Module Unspecified HTML Injection Vulnerability|x.x.x|x.x.x|Jabouille Jean Charles Djice Shoutbox 1.0|Djice Shoutbox for Joomla! is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.|http://www.securityfocus.com/bid/34076/
Core||Multiple Cross Site Scripting Vulnerabilities|1.5.0|1.5.9||Joomla! is prone to multiple cross-site scripting vulnerabilities because the application fails to sufficiently sanitize user-supplied input.An attacker can exploit these issues to steal cookie-based authentication credentials and launch other attacks.|http://www.securityfocus.com/bid/34360/
Component|com_rdautos|RD-Autos Component 'makeid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|RD-Media RD-Autos 1.5.7|The RD-Autos component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/34364/
Component|com_messaging|The Tricky.net Joomla! Messaging Component 'controller' Parameter Local File Include Vulnerability|x.x.x|x.x.x|The Tricky.net Messaging component 1.5|The Tricky.net Messaging component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may aid in other attacks.|http://www.securityfocus.com/bid/34365/
Component|com_bookjoomlas|BookJoomlas Component 'gbid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Nikola Arezina BookJoomlas 1.0|The BookJoomlas component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/34392/
Component|com_rssreader|Simple RSS Reader Component Remote File Include Vulnerability|x.x.x|x.x.x|Joomla Simple RSS Reader 1.0|The Simple RSS Reader component for Joomla! is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/32265/
Component|com_xevidmegahd|'com_xevidmegahd' Component 'catid' Parameter SQL Injection Vulnerabilit|x.x.x|x.x.x|com_xevidmegahd|The 'com_xevidmegahd' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/33203/
Component|com_jashowcase|'com_jashowcase' Component 'catid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_jashowcase|The 'com_jashowcase' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/33202/
Component|com_newsflash|'com_newsflash' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_newsflash|The 'com_newsflash' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/33201/
Component|plugins/editors/xstandard/attachmentlibrary.php|XStandard Component Directory Traversal Vulnerability|x.x.x|x.x.x|Joomla XStandard|The XStandard component for Joomla! is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.Exploiting the issue may allow an attacker to obtain sensitive information that could aid in further attacks.|http://www.securityfocus.com/bid/33143/
Component|com_phocadocumentation|Phoca Documentation Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Phoca Documentation|The Phoca Documentation component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/33114/
Component|com_simple_review|Joomla! and Mambo Simple Review Component 'category' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Simple Review 1.3.5|The Joomla! and Mambo Simple Review component is prone to an SQL-injection vulnerability because it fails to adequately sanitize user-supplied input.A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/33102/
Component|com_na_newsdescription|'com_na_newsdescription' Component 'newsid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_na_newsdescription|The 'com_na_newsdescription' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/33116/
Component|com_paxgallery|Pax Gallery 'gid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla Resource Pax Gallery 0.1|The Pax Gallery component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/33035/
Component|com_liveticker|LiveTicker 'tid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|raven-worx LiveTicker 1.0|The LiveTicker component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/33010/
Component|com_mdigg|mDigg Component for Joomla! 'category' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla Apps mDigg Component 2.2.8|The mDigg component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/33009/
Component|com_ice|Ice Gallery Component 'catid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Markus Donhauser Ice Gallery 0.5 beta 2|The Ice Gallery component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/33008/
Component|com_hbssearch|HBS 'com_hbssearch' Joomla! Component 'r_type' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla HBS com_hbssearch 1.0|The Joomla HBS 'com_hbssearch' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/32951/
Component|com_volunteer|Apps Volunteer Management Component 'job_id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla Apps Volunteer Management 2.0|The Volunteer Management component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/32973/
Component|com_flashmagazinedeluxe|ElearningForce Flash Magazine Deluxe Joomla! Component SQL Injection Vulnerability|x.x.x|x.x.x|Elearningforce Flash Magazine Deluxe|Flash Magazine Deluxe Joomla! component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/33455/
Component|com_beamospetition|'com_beamospetition' Component SQL Injection and Cross Site Scripting Vulnerabilities|x.x.x|x.x.x|Arthur Konze com_beamospetition 1.0.12|The 'com_beamospetition' component for Joomla! is prone to an SQL-injection vulnerability and a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/33391/
Component|com_prod|BazaarBuilder Component 'cid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|SureNames Internet Solution BazaarBuilder 5.0|The Joomla! BazaarBuilder component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/33380/
Component|com_waticketsystem|WATicketSystem Component 'catid' SQL Injection Vulnerability|x.x.x|x.x.x|James Kennard WATicketSystem < 2.0.8|The Joomla! WATicketSystem component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/33353/
Component|com_pccookbook|Joomla! and Mambo 'com_pccookbook' Component 'recipe_id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_pccookbook|The Joomla! and Mambo 'com_pccookbook' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/33346/
Component|com_news|Joomla! and Mambo 'com_news' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_news|The Joomla! and Mambo 'com_news' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/33350/
Component|com_gigcal|Joomla! and Mambo gigCalendar Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|gigCalendar 1.0|The gigCalendar component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/33332/
Component|com_rdautos|RD-Autos Component SQL Injection Vulnerability|x.x.x|x.x.x|RD-Media RD-Autos 1.5.2|The RD-Autos component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/33297/
Component|com_eventing|Eventing Component for Joomla! 'com_eventing' SQL Injection Vulnerability|x.x.x|x.x.x|Eventing Eventing <= 1.6.5|The 'com_eventing' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/33296/
Component|com_camelcitydb2|CamelcityDB Component SQL Injection Vulnerability|x.x.x|x.x.x|Joomla CamelcityDB 2.2|The CamelcityDB 'com_camelcitydb2' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/33254/
Component|com_fantasytournament|'com_fantasytournament' Component Multiple SQL Injection Vulnerabilities|x.x.x|x.x.x|Joomla Fantasy Tournament 2009.1.5|The 'com_fantasytournament' component for Joomla! is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/33252/
Component|com_gigcal|Joomla! and Mambo gigCalendar Component SQL Injection Vulnerability|x.x.x|x.x.x|gigCalendar 1.0|The gigCalendar component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/33241/
Component|com_portfol|Portfol Component 'vcatid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Mivaco Portfol 1.2|The Portfol component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/33218/
Component|com_thyme|eXtrovert Software Thyme Joomla! Component SQL Injection Vulnerability|x.x.x|x.x.x|EXtrovert Software Thyme Calendar 1.0|The Thyme component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/32417/
Component|com_jmovies|JMovies Joomla! Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|JOOMItaly JMovies 1.1|JMovies Joomla! component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/32615/
Component|com_mydyngallery|Joomla! and Mambo Mydyngallery Component 'directory' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Mydyngallery|Mydyngallery is prone to an SQL-injection vulnerability because it fails to adequately sanitize user-supplied input.A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/32639/
Component|com_livechat|Joomla Live Chat Multiple SQL Injection and Open Proxy Vulnerabilities|x.x.x|x.x.x|Joompolitan Joomla Live Chat|Joomla Live Chat is prone to multiple SQL-injection vulnerabilities and an open-proxy vulnerability because the application fails to sufficiently sanitize user-supplied input.Exploiting these issues could allow attackers to perform certain proxy actions, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/32803/
Component|com_tech_article|Tech Articles Joomla! Component 'item' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla Tech Articles 1.0|The Tech Articles component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/32897/
Component|com_tophotelmodule|HBS Multiple Components 'showhoteldetails' SQL Injection Vulnerability|x.x.x|x.x.x|Joomla HBS com_tophotelmodule 1.0|Multiple Joomla HBS components are prone to an SQL-injection vulnerability because they fail to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the applications, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/32952/
Component|com_lowcosthotels|HBS Multiple Components 'showhoteldetails' SQL Injection Vulnerability|x.x.x|x.x.x|Joomla HBS com_lowcosthotels|Multiple Joomla HBS components are prone to an SQL-injection vulnerability because they fail to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the applications, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/32952/
Component|com_allhotels|HBS Multiple Components 'showhoteldetails' SQL Injection Vulnerability|x.x.x|x.x.x|Joomla HBS com_allhotels|Multiple Joomla HBS components are prone to an SQL-injection vulnerability because they fail to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the applications, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/32952/
Component|com_5starhotels|HBS Multiple Components 'showhoteldetails' SQL Injection Vulnerability|x.x.x|x.x.x|Joomla HBS com_5starhotels|Multiple Joomla HBS components are prone to an SQL-injection vulnerability because they fail to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the applications, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/32952/
Component|com_contactinfo|Digital Greys Contact Information Module Joomla! Component SQL Injection Vulnerability|x.x.x|x.x.x|Digital Greys Contact Information Module 2.1|The Contact Information Module component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/32260/
Component|com_books|Joomla! and Mambo Books Component 'book_id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla Books|The Books component ('com_books') for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/32255/
Component|com_catalogproduction|Joomla! and Mambo Catalog Production Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla Catalog Production|Joomla! and Mambo Catalog Production ('com_catalogproduction') component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/32259/
Component|com_jb2|JooBlog Component 'PostID' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|JooBlog 0.1.1|The JooBlog component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/32236/
Core||Multiple HTML Injection Vulnerabilities|1.5.0|1.5.7||Joomla! is prone to multiple HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data.Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user; other attacks are also possible.|http://www.securityfocus.com/bid/32263/
Component|com_dadamail|Dada Mail Manager Component Remote File Include Vulnerability|x.x.x|x.x.x|Joomla Dada Mail Manager 2.6|The Dada Mail Manager component for Joomla! is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/32135/
Component|com_ongumatimesheet20|Onguma Time Sheet Component Remote File Include Vulnerability|x.x.x|x.x.x|Luigi Massa Onguma Time Sheet 2.0|The Onguma Time Sheet component for Joomla! is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/32095/
Component|com_treeg|Flash Tree Gallery Component Remote File Include Vulnerability|x.x.x|x.x.x|Biba Flash Tree Gallery 1.0|The Flash Tree Gallery component for Joomla! is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/32041/
Component|com_simpleboard|Mambo and Joomla! SimpleBoard 'image_upload.php' Arbitrary File Upload Vulnerability|x.x.x|x.x.x|Two Shoes Mambo Factory SimpleBoard 1.0.1|SimpleBoard is prone to a vulnerability that lets remote attackers upload and execute arbitrary script code on an affected computer with the privileges of the webserver process. The issue occurs because the application fails to check file extensions properly.|http://www.securityfocus.com/bid/31981/
Component|com_ab_gallery|Archaic Binary Gallery 'com_ab_gallery' Component Directory Traversal Vulnerability|x.x.x|x.x.x|Joomla Archaic Binary Gallery 1.0|The Joomla! Archaic Binary Gallery component is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.Exploiting the issue may allow an attacker to obtain sensitive information that could aid in further attacks.|http://www.securityfocus.com/bid/31901/
Component|com_kbase|KBase Joomla! Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla KBase 1.2|The KBase component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/31902/
Component|com_rwcards|RWCards Component 'captcha_image.php' Local File Include Vulnerability|x.x.x|x.x.x|Joomla RWCards Component 3.0.11|The RWCards component for Joomla! is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this vulnerability to access potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the underlying computer; other attacks are also possible.|http://www.securityfocus.com/bid/31892/
Component|com_ionfiles|ionFiles Component 'download.php' Directory Traversal Vulnerability|x.x.x|x.x.x|Joomla com_ionfiles Component 4.4.2|The Joomla! ionFiles component is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.Exploiting the issue may allow the attacker to obtain sensitive information that could aid in further attacks.|http://www.securityfocus.com/bid/31877/
Component|com_dailymessage|Joomla! and Mambo Daily Message Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joseph L. LeBlanc Daily Message 1.0.3|The Daily Message component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/31870/
Component|com_ds-syndicate|DS-Syndicate Joomla! Component 'feed_id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla DS-Syndicate component|The DS-Syndicate component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/31819/
Component|com_nicetalk|Nice Talk Joomla! Component 'tagid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|azrul.com Nice Talk|The Nice Talk component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/31818/
Component|com_ownbiblio|OwnBiblio Joomla! Component 'catid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla OwnBiblio 1.5.3|The OwnBiblio component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/31725/
Component|com_jeux|'com_jeux' Joomla! Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_jeux|The 'com_jeux' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/31731/
Component|com_mad4joomla|Joomla! and Mambo Mad4Joomla Mailforms Component SQL Injection Vulnerability|x.x.x|x.x.x|Mad4Media Mad4Joomla Mailforms|The Mad4Joomla Mailforms component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/31712/
Component|com_imagebrowser|Image Browser Component 'index.php' Directory Traversal Vulnerability|x.x.x|x.x.x|Joomla Image Browser 0.1.5|Joomla Image Browser is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.Exploiting the issue may allow the attacker to obtain sensitive information that could aid in further attacks.|http://www.securityfocus.com/bid/31458/
Core||Remote Vulnerabilites and Weaknesses|1.5.0|1.5.6||Joomla! CMS is prone to multiple remote vulnerabilities and a weakness, including:- An RNG (random number generator) weakness.- A security vulnerability that may allow attackers to send unsolicited spam email.- A URL-redirection vulnerability.- An input-validation vulnerability.Remote attackers can exploit these issues to send unsolicited spam email, redirect victims to attacker-controlled sites, and conduct phishing attacks. Attackers can also exploit the RNG weakness to aid in brute-force attacks. Other attacks are also possible.|http://www.securityfocus.com/bid/31103/
Core|com_user|'com_user' Component Token Input Validation Vulnerability|1.5.0|1.5.5||The 'com_user' component for Joomla! is prone to an input-validation vulnerability because it fails to sufficiently sanitize user-supplied data.Exploiting this issue could allow an attacker to obtain administrative privileges and compromise the application.|http://www.securityfocus.com/bid/30667/
Component|com_utchat|com_utchat component Mambo and Joomla! Component Multiple Remote File Include Vulnerabilities|x.x.x|x.x.x|Yann Sallou com_utchat 0.2|The com_utchat component for Mambo and Joomla! is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.Exploiting these issues can allow an attacker to compromise the application and the underlying computer; other attacks are also possible.|http://www.securityfocus.com/bid/30571/
Component|com_ezstore|Joomla! and Mambo EZ Store Component SQL Injection Vulnerability|x.x.x|x.x.x|EZ Store|The EZ Store component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/30527/
Component|com_dtregister|Joomla! and Mambo DT Register Component 'eventId' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|DTH Development DT Register <= 2.2.3|The DT Register component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/30256/
Component|com_n-forms|n-forms Joomla! and Mambo 'com_n-forms' Component SQL Injection Vulnerability|x.x.x|x.x.x|Joomla com_n-forms 1.01|The 'n-forms' component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/30201/
Core||Multiple Unauthorized Access Vulnerabilities|1.5.0|1.5.3||Joomla! is prone to multiple unspecified unauthorized-access vulnerabilities.An attacker can exploit these issues to gain unauthorized administrative access to the affected application. Successfully exploiting these issues will compromise the affected application.|http://www.securityfocus.com/bid/30125/
Core||Multiple Unauthorized Access Vulnerabilities|1.0.1|1.0.15||Joomla! is prone to multiple unspecified unauthorized-access vulnerabilities.An attacker can exploit these issues to gain unauthorized administrative access to the affected application. Successfully exploiting these issues will compromise the affected application.|http://www.securityfocus.com/bid/30125/
Component|com_altas|Joomla! and Mambo altas Component 'index.php' Multiple SQL Injection Vulnerabilities|x.x.x|x.x.x|Joomla com_altas 1|he altas component for Joomla! and Mambo is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/30092/
Component|com_dbquery|Joomla! and Mambo DBQuery Component 'mosConfig_absolute_path' Remote File Include Vulnerability|x.x.x|x.x.x|Green Mountain Information Technology and Consulting DBQuery 1.4.1|The DBQuery component for Joomla! and Mambo is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/30093/
Component|com_vr|Joomla! and Mambo QuickTime VR Component 'room_id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla QuickTime VR Component 0.1|The QuickTime VR component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/30065/
Component|com_is|Joomla! and Mambo 'com_is' Component Multiple SQL Injection Vulnerabilities|x.x.x|x.x.x|MAXX-marketing com_is 1.0.1|The 'com_is' component for Joomla! and Mambo is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/30063/
Component|com_brightweblinks|Joomla! and Mambo Brightcode Weblinks Component 'catid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Theo van der Sluijs Brightcode WebLinks 1.5|The Brightcode Weblinks component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/30060/
Component|com_versioning|Joomla! and Mambo Versioning Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|JoomProd Versioning 1.0.2|The Versioning component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/30050/
Component|com_xewebtv|Joomla! and Mambo 'com_xewebtv' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla com_xewebtv|The 'com_xewebtv' component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/30006/
Component|com_beamospetition|Joomla! and Mambo 'com_beamospetition' Component 'pet' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla com_beamospetition|The 'com_beamospetition' component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/30005/
Component|com_jabode|Joomla! and Mambo jabode 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|John-Paul jabode|The jabode component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/29994/
Component|com_netinvoice|nBill Joomla! and Mambo Component SQL Injection Vulnerability|x.x.x|x.x.x|nBill 1.2 SP1|The nBill component for the Joomla! and Mambo content managers is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/29951/
Component|com_facileforms|Joomla! and Mambo FacileForms Component 'ff_compath' Parameter Remote File Include Vulnerability|x.x.x|x.x.x|FacileForms FacileForms <= 1.4.6|The FacileForms component for Joomla! and Mambo is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.Exploiting this issue may allow an attacker to compromise the application and the underlying computer; other attacks are also possible.|http://www.securityfocus.com/bid/29904/
Component|com_expshop|EXP Shop Joomla! 'com_expshop' Component SQL Injection Vulnerability|x.x.x|x.x.x|EXP TEAM EXP Shop 1.0|The EXP Shop component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/29869/
Component|com_galleries|Joomla! and Mambo galleries Component 'aid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Vinay Kr. Singh galleries 1.0|The galleries component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/29706/
Component|com_yvcomment|yvComment Joomla! Component 'ArticleID' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|yvComment yvComment 1.16|The yvComment component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/29596/
Component|com_rapidrecipe|Rapid-Source Rapid-Recipe Joomla! Component 'recipe_id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Rapid-Source Rapid-Recipe 1.6.7 - J-1.5|The Rapid-Recipe component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/29593/
Component|com_gameq|Joomla! GameQ Component 'category_id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|GameQ for Joomla!|The GameQ component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/29592/
Component|com_simpleshop|Joomla! and Mambo Simple Shop Component 'catid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Galore Simple Shop 3.4|The Simple Shop component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/29565/
Component|com_jotloader|Joomla! and Mambo JotLoader Component 'cid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Vladimir Kanich JotLoader <= 1.2.1|The JotLoader component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/29554/
Component|com_joomradio|Joomla! and Mambo JoomRadio Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|EXP TEAM JoomRadio 1.0|The JoomRadio component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/29504/
Component|com_equotes|Joomla! and Mambo eQuotes Component SQL Injection Vulnerability|x.x.x|x.x.x|CommunityGrove eQuotes 0.9.4|The eQuotes ('com_equotes') component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/29498/
Component|com_biblestudy|Joomla! and Mambo Bible Study Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Tom Fuller Bible Study|The Bible Study component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/29473/
Component|com_mycontent|Joomla! and Mambo myContent Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Mark Fabrizio myContent 1.1.13|The myContent component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/29468/
Component|com_mambads|Joomla! and Mambo MambAds Component 'ma_cat' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|MambAds MambAds 1.0.rc1|The MambAds component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/29433/
Component|com_artist|Joomla! and Mambo Artists Component 'idgalery' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|JoomlaResource Artists Component|The Artists component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/29407/
Component|com_xsstream-dm|Joomla! and Mambo xsstream-dm Component 'movie' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla xsstream-dm Component 0.01 Beta|The xsstream-dm component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/29144/
Component|com_datsogallery|Joomla! and Mambo Datsogallery Component 'sub_votepic.php' SQL Injection Vulnerability|x.x.x|x.x.x|Datsogallery 1.6|The Datsogallery component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/29138/
Component|com_webhosting|Joomla! and Mambo Webhosting Component 'catid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Webhosting Component|The Webhosting component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/29000/
Component|com_ahsshop|Joomla! and Mambo Ahsshop Component 'vara' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Netvistun Ahsshop 1.51|The Ahsshop component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/28549/
Component|com_myalbum|Joomla! and Mambo MyAlbum Component 'album' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Huseyin Bora Abaci MyAlbum 1.0|The MyAlbum component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/28496/
Component|com_alphacontent|Joomla! and Mambo Alphacontent Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Bernard Gilly Alphacontent Component 2.5.8|The Alphacontent component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/28443/
Component|com_rekry|Joomla! and Mambo Rekry Component 'op_id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Matti Kiviharju Rekry Component 1.0|The Rekry component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/28422/
Component|com_d3000|Joomla! and Mambo Download3000 Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Download3000 com_d3000 1.0|The Download3000 component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/28428/
Component|com_cinema|Joomla! and Mambo Cinema Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla! Italia Cinema 1.0|The Cinema component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/28427/
Component|com_custompages|Custompages Component 'cpage' Parameter Remote File Include Vulnerability|x.x.x|x.x.x|SSTREAMTV Custompages 1.1|The Joomla! Custompages component is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/28409/
Component|com_datsogallery|Joomla! and Mambo Datsogallery Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Datsogallery 1.3.1|The Datsogallery component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/28361/
Component|com_joovideo|Joomla! and Mambo joovideo Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomlapixel joovideo 1.2.2|The joovideo component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/28318/
Component|com_accombo|Joomla! and Mambo Accombo Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Niall McCullagh accombo 1.4|The 'accombo' component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/28325/
Component|com_alberghi|Joomla! and Mambo Alberghi Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Vamba Alberghi 2.1.3|The Alberghi component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/28331/
Component|com_restaurante|Joomla! and Mambo Comp Restaurante Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Detodas Comp Restaurante 1.0|The Comp Restaurante component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/28324/
Component|com_acajoom|Joomla! and Mambo Acajoom Component 'mailingid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joobi Ltd Acajoom 1.1.5|The Acajoom component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/28305/
Component|com_guide|Joomla! and Mambo 'com_guide' Component 'category' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_guide|The 'guide' component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/28271/
Component|com_actualite|Joomla! and Mambo actualite Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Pyxicom actualite 1.0|The 'actualite' component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/28565/
Component|com_onlineflashquiz|Elearningforce Online FlashQuiz 1.0.2|x.x.x|x.x.x|Elearningforce Online FlashQuiz 1.0.2|The Elearningforce Online FlashQuiz component for Joomla! is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.Exploiting this issue can allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/28574/
Component|com_lms|Joomla! and Mambo Joomlearn LMS Component 'cat' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla Showroom Joomlearn LMS < 2.6|The Joomlearn LMS component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/28586/
Component|com_joomlaxplorer|Joomla! and Mambo joomlaXplorer Component Multiple Input Validation Vulnerabilities|x.x.x|x.x.x|joomlaXplorer 1.6|The Joomla! and Mambo joomlaXplorer component is prone to a cross-site scripting issue and a directory-traversal issue because the application fails to properly sanitize user-supplied input.Attackers can exploit these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of an affected site, steal cookie-based authentication credentials, or download arbitrary files; information harvested could aid in further attacks.|http://www.securityfocus.com/bid/28746/
Component|com_extplorer|Joomla! and Mambo eXtplorer Component 'dir' Parameter Directory Traversal Vulnerability|x.x.x|x.x.x|eXtplorer 2.0.0 RC2|The Joomla! and Mambo eXtplorer component is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.Exploiting the issue may allow an attacker to access sensitive information that could aid in further attacks.|http://www.securityfocus.com/bid/28764/
Component|com_jomcomment|Mambo and Joomla! Jom Comment Component User Credential SQL Injection Vulnerability|x.x.x|x.x.x|azrul.com Jom Comment 2.0 build 345|Jom Comment component for Mambo! and Joomla is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/28812/
Component|com_flippingbook|Joomla! and Mambo FlippingBook Component 'book_id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|FlippingBook 1.0.4|The FlippingBook component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/28886/
Component|com_comprofiler|Joomla! and Mambo Community Builder 'com_profiler' Component SQL Injection Vulnerability|x.x.x|x.x.x|Joomlapolis Community Builder <= 1.0.1|The Community Builder 'com_profiler' component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/28911/
Component|com_filiale|Joomla! and Mambo Filiale Component 'idFiliale' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Filiale 1.0.4|The Filiale component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/28900/
Component|com_jpad|Joomla! and Mambo Jpad Component 'cid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Theo van der Sluijs Jpad 1.0 - BrightCode Notepad|The Jpad component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/28923/
Component|com_joomla-visites|Visites Component mosConfig_absolute_path Remote File Include Vulnerability|x.x.x|x.x.x|Visocrea Visites 1.1 RC2|The Visites component for Joomla! is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/28942/ http://www.exploit-db.com/exploits/14476/
Component|com_hello_world|Joomla! and Mambo 'com_hello_world' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_hello_world|The Joomla! and Mambo 'com_hello_world' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27956/
Component|com_referenzen|Joomla! and Mambo Referenzen Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|portal-2 Referenzen|The Joomla! and Mambo Referenzen component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27926/
Component|com_asortyment|Joomla! and Mambo 'com_asortyment' Component 'katid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_asortyment|The Joomla! and Mambo 'com_asortyment' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27923/
Component|com_most|Joomla! and Mambo 'com_most' Component 'secid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_most|The Joomla! and Mambo 'com_most' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27922/
Component|com_clasifier|Joomla! and Mambo 'com_clasifier' Component 'cat_id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_clasifier|The Joomla! and Mambo 'com_clasifier' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27917/
Component|com_joomlavvz|Joomla! and Mambo 'com_joomlavvz' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_joomlavvz|The Joomla! and Mambo 'com_joomlavvz' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27921/
Component|com_productshowcase|Joomla! and Mambo ProductShowcase Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Numa Technologies Corporation ProductShowcase 1.5|The ProductShowcase component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/28202/
Component|com_ensenanzas|Joomla! and Mambo 'ensenanzas' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_ensenanzas|The 'ensenanzas' component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/28196/
Component|com_ewriting|Joomla! and Mambo 'com_ewriting' Component 'Itemid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Bárbara Irene Meclazcke eWriting 1.2.1|The eWriting component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/28179/
Component|com_candle|Joomla! and Mambo 'Candle' Component 'cID' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Son Vu Candle 1.0|The 'Candle' component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/28174/
Core||Multiple Remote Vulnerabilities|1.0.0|1.0.14||Joomla! is prone to multiple remote vulnerabilities, including:- Multiple cross-site request-forgery vulnerabilities- A cross-site scripting vulnerability- Multiple privilege-escalation vulnerabilitiesAttackers can exploit these issues to compromise the affected application, execute arbitrary code within the context of the webserver process, or steal cookie-based authentication credentials; other attacks are also possible.|http://www.securityfocus.com/bid/28111/
Component|com_musica|Joomla! and Mambo 'com_musica' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_musica|The 'com_musica' component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/28061/
Component|com_simpleboard|Joomla! and Mambo 'com_simpleboard' Component 'catid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Mamboportal.com Simpleboard 1.0.3 stable|The 'com_simpleboard' component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/28018/
Component|com_inter|Joomla! and Mambo 'com_inter' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_inter|The Joomla! and Mambo 'com_inter' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27994/
Component|com_wines|Joomla! and Mambo 'com_wines' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_wines|The 'com_wines' component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27975/
Component|com_blog|Joomla! and Mambo 'com_blog' Component 'pid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_blog|The 'com_blog' component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27971/
Component|com_publication|Joomla! and Mambo 'com_publication' Component 'pid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_publication|The Joomla! and Mambo 'com_publication' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27970/
Component|com_genealogy|Joomla! and Mambo com_genealogy Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_genealogy|The Joomla! and Mambo 'com_genealogy' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database|http://www.securityfocus.com/bid/27887/
Component|com_formtool|Joomla! and Mambo com_formtool Component 'catid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_formtool|The Joomla! and Mambo 'com_formtool' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27884/
Component|com_iigcatalog|Joomla! and Mambo com_iigcatalog Component 'cat' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_iigcatalog|The Joomla! and Mambo 'com_iigcatalog' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27883/
Component|com_team|Joomla! and Mambo 'com_team' Component SQL Injection Vulnerability|x.x.x|x.x.x|com_team|The 'com_team' component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27881/
Component|com_pccookbook|Joomla! and Mambo 'com_pccookbook' Component 'user_id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_pccookbook|The Joomla! and Mambo 'com_pccookbook' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27864/
Component|com_downloads|Joomla! and Mambo com_downloads Component 'cat' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_downloads|The Joomla! and Mambo 'com_downloads' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27860/
Component|com_detail|Joomla! and Mambo com_detail Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_detailThe Joomla! and Mambo 'com_detail' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.|The Joomla! and Mambo 'com_detail' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27853/
Component|com_profile|Joomla! and Mambo com_profile Component 'oid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_profile|The Joomla! and Mambo 'com_profile' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27851/
Component|com_quran|Joomla! and Mambo Portfolio Manager Component 'categoryId' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Portfolio Manager 1.0|Joomla! and Mambo Portfolio Manager component is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27849/
Component|com_galeria|Joomla! and Mambo com_galeria Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_profilecom_galeria|The Joomla! and Mambo 'com_galeria' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27833/
Component|com_scheduling|Joomla! and Mambo com_scheduling Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_scheduling|The Joomla! and Mambo 'com_scheduling' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27830/
Component|com_filebase|Joomla! and Mambo com_filebase Component 'filecatid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_filebase|The Joomla! and Mambo 'com_filebase' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27829/
Component|com_lexikon|Joomla! and Mambo com_lexikon Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_lexikon|The Joomla! and Mambo 'com_lexikon' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27828/
Component|com_salesrep|Joomla! and Mambo 'com_salesrep' Component 'rid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_salesrep|The Joomla! and Mambo 'com_salesrep' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27827/
Component|com_ricette|Joomla! and Mambo com_ricette Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_ricette|The Joomla! and Mambo 'com_ricette' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27834/
Component|com_mcquiz|MCQuiz Component 'tid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|MCQuiz MCQuiz 0.9|The Joomla! MCQuiz component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27809/
Component|com_quran|Joomla!, Mambo and PHP-Nuke Quran Component SQL Injection Vulnerability|x.x.x|x.x.x|PHP Nuke Quran 1.1|The 'Quran' component for Joomla!, Mambo, and PHP-Nuke is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27842/
Component|com_paxxgallery|PAXXGallery Component 'userid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|PAXXGallery 0.2|The Joomla! PAXXGallery component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27811/
Component|com_smslist|Joomla! and Mambo 'com_smslist' Component 'listid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_smslist|The Joomla! and Mambo 'com_smslist' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27818/
Component|com_sg|Joomla! and Mambo 'com_sg' Component 'pid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_sg|The Joomla! and Mambo 'com_sg' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27821/
Component|com_activities|Joomla! and Mambo 'com_activities' Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_activities|The Joomla! and Mambo 'com_activities' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27820/
Component|faq|Joomla! and Mambo faq Component 'catid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|faq|The Joomla! and Mambo 'faq' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27822/
Component|com_quiz|Joomla! and Mambo 'com_quiz' Component 'tid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|DataHellas Quiz 0.81|The Joomla! and Mambo Quiz component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27808/
Component|com_mediaslide|MediaSlide Component 'albumnum' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla MediaSlide 0.5|The Joomla! MediaSlide component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27805/
Core||Undefined RG_EMULATION Remote File Include Vulnerability|1.0.13|1.0.14||Joomla! is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/27795/
Component|com_xfaq|Joomla! and Mambo 'com_xfaq' XfaQ Component 'aid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|GFi XfaQ 1.2|The Joomla! and Mambo XfaQ component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27784/
Component|com_uhp|User Home Pages Component 'com_uhp' Arbitrary File Upload Vulnerability|x.x.x|x.x.x|Ravenswood IT Services UHP 0.7|The Joomla! User Home Pages component is prone to a vulnerability that lets attackers upload arbitrary files because it fails to verify the type of file being uploaded.Exploiting this issue could allow attackers to upload and execute arbitrary script code in the context of the affected webserver process.|http://www.securityfocus.com/bid/27780/
Component|com_model|Joomla! and Mambo com_model Component 'objid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_model|The Joomla! and Mambo 'com_model' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27781/
Component|com_omnirealestate|Joomla! and Mambo 'com_omnirealestate' Component 'objid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_omnirealestate|The 'com_omnirealestate' component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27783/
Component|com_iomezun|Joomla! and Mambo com_iomezun Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_iomezun|The Joomla! and Mambo 'com_iomezun' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27748/
Component|com_comments|Joomla! and Mambo com_comments Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Phil Taylor com_comments Component 0.5.8.5g|The Joomla! and Mambo 'com_comments' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27731/
Core||XML-RPC Blogger API Unspecified Vulnerability|1.5.0|1.5.0||Joomla! is prone to an unspecified vulnerability that affects XML-RPC in combination with the blogger API.Attackers could exploit this issue to modify and delete articles.Currently, very little is known about this issue. We will update this BID as more information emerges.|
Component|com_gallery|Joomla! and Mambo com_gallery Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_gallery|The Joomla! and Mambo 'com_gallery' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27695/
Component|com_neogallery|Joomla! and Mambo com_neogallery Component 'catid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla com_neogallery Component 1.1|The Joomla! and Mambo 'com_neogallery' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27692/
Component|com_noticias|Joomla! and Mambo com_noticias Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_noticias|The Joomla! and Mambo 'com_noticias' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27691/
Component|com_doc|Joomla! and Mambo com_doc Component 'sid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_doc|The Joomla! and Mambo 'com_doc' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27679/
Component|com_sermon|Joomla! and Mambo com_sermon Component 'gid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla com_sermon 0.2|The Joomla! and Mambo 'com_sermon' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27673/
Component|com_downloads|Joomla! and Mambo com_downloads Component 'filecatid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_downloads|The Joomla! and Mambo 'com_downloads' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27648/
Component|com_ynews|Joomla! and Mambo YNews Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Manuel Kaspar YNews 1.0|Joomla! and Mambo YNews component is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27649/
Component|com_awesom|Awesom! for Joomla! and Mambo SQL Injection Vulnerability|x.x.x|x.x.x|amazOOP Awesom! 0.3.2|Awesom! for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27607/
Component|com_shambo2|Joomla! and Mambo 'com_shambo2' Component SQL Injection Vulnerability|x.x.x|x.x.x|com_shambo2|The com_shambo2 component for Mambo and Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27609/
Component|com_marketplace|Joomla! and Mambo com_marketplace Component 'catid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Joomla com_marketplace Component <= 1.2.1|The Joomla! and Mambo 'com_marketplace' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27600/
Component|com_directory|mosDirectory Component 'catid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Phil Taylor mosDirectory 2.3.2|The Joomla! mosDirectory component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27585/
Component|com_neoreferences|Joomla! and Mambo NeoReferences Component 'catid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Neoweb SARL Neoreferences 1.3.1|The NeoReferences component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27564/
Component|com_catalogshop|Joomla! and Mambo CatalogShop Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|K.J. Strickland CatalogShop 1.0 b1|The CatalogShop component for Mambo and Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27558/
Component|com_restaurant|Joomla! and Mambo com_restaurant Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_restaurant|The Joomla! and Mambo 'com_restaurant' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27551/
Component|com_akogallery|Joomla! and Mambo AkoGallery Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|Arthur Konze AkoGallery 2.5 beta|The AkoGallery component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27557/
Component|com_jokes|com_jokes Component 'cat' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_jokes|The Joomla! 'com_jokes' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27522/
Component|com_estateagent|EstateAgent Component 'index.php' SQL Injection Vulnerability|x.x.x|x.x.x|Joomla EstateAgent 0.1|The Joomla! EstateAgent component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27520/
Component|com_recipes|com_recipes Component 'id' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_recipes|The Joomla! 'com_recipes' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27519/
Component|com_buslicense|Mambo/Joomla 'com_buslicense' Component 'aid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_buslicense|The 'com_buslicense' component for Mambo/Joomla is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27508/
Component|com_musepoes|Mambo/Joomla 'com_musepoes' Component 'aid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_musepoes|The 'com_musepoes' component for Mambo/Joomla is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27507/
Component|com_glossary|Mambo/Joomla Glossary 'com_glossary' Component SQL Injection Vulnerability|x.x.x|x.x.x|com_glossary|The 'com_glossary' component for Mambo/Joomla is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.NOTE: The original report states that this issue affects 'com_glossary' 2.0. The vendor states that 2.02 is not affected due to the use of 'intval' and that 2.0 is not likely affected.|http://www.securityfocus.com/bid/27505/
Component|com_mamml|com_mamml Component 'index.php' SQL Injection Vulnerability|x.x.x|x.x.x|com_mamml|The Joomla! 'com_mamml' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27503/
Component|com_fq|com_fq Component 'index.php' SQL Injection Vulnerability|x.x.x|x.x.x|com_fq|The Joomla 'com_fq' component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/27501/
Component|com_smf|Joomla-SMF Forum Multiple Cross-Site Scripting Vulnerabilities|x.x.x|x.x.x|Joomla Joomla-SMF Forum Component|Joomla-SMF Forum is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.|http://www.securityfocus.com/bid/27218/
Component|com_directory|mosDirectory Component mosConfig_absolute_path Remote File Include Vulnerability|x.x.x|x.x.x|Phil Taylor mosDirectory 2.3.2 -r3|The mosDirectory component for Joomla! is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/27014/
Component|com_rsgallery|Mambo/Joomla! RSGallery CATID Parameter SQL Injection Vulnerability|x.x.x|x.x.x|RSGallery2 RsGallery 2.0 beta 5|Mambo/Joomla! RSGallery is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/26704/
Core||Index.PHP Multiple SQL Injection Vulnerabilities|1.5.0|1.5.0||Joomla! is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/26707/
Component|com_juser|Equipment JUser Component MosConfig_Absolute_Path Remote File Include Vulnerability|x.x.x|x.x.x|Joomla Equipment JUser 1.0.14|The JUser component for Joomla! is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/26499/
Component|com_colorlab|Com_Colorlab Component MosConfig_Live_Site Remote File Include Vulnerability|x.x.x|x.x.x|com_colorlab|The Joomla! Com_Colorlab component is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/26059/
Core||Search Component SearchWord Cross-Site Scripting Vulnerability|1.0.13|1.0.13||The Joomla! Search component is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.|http://www.securityfocus.com/bid/26031/
Component|com_joomla_flash_uploader|Flash Uploader mosConfig_Absolute_Path Multiple Remote File Include Vulnerabilities|x.x.x|x.x.x|Michael Dempfle com_jfu 2.5.1 - 2.5.2|The Joomla! Flash Uploader component is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied input.Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/26044/
Component|com_jcs|JContentSubscription MosConfig_Absolute_Path Multiple Remote File Include Vulnerabilities|x.x.x|x.x.x|Joomla Equipment JContentSubscription 1.5.8|JContentSubscription is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.Exploiting these issues may allow an attacker to compromise the application and the underlying webserver; other attacks are also possible.|http://www.securityfocus.com/bid/26003/
Component|com_mp3_allopass|Mambo/Joomla! MP3 Allopass MosConfig_Absolute_Path Multiple Remote File Include Vulnerabilities|x.x.x|x.x.x|Quoc-Huy MP3 Allopass 1.0|The MP3 Allopass component is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/26002/
Component|com_wmtrssfeedreader|Webmaster-Tips.net Joomla! RSS Feed Reader Remote File Include Vulnerability|x.x.x|x.x.x|com_wmtrssfeedreader|Webmaster-Tips.net Joomla! RSS Feed Reader is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/25999/
Core||PCLTar.PHP Remote File Include Vulnerability|1.5.0|1.5.0||Joomla is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.An attacker can exploit these issues to execute malicious PHP code in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/25528/
Core||Multiple Input Validation Vulnerabilities|1.5.0|1.5.0||Joomla! is prone to multiple input-validation vulnerabilities because the application fails to sanitize user-supplied input. These issues include a cross-site scripting vulnerability and an SQL-injection vulnerability.A successful exploit may allow an attacker to steal cookie-based authentication credentials, execute malicious script code in a user's browser, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/25508/
Component|com_tour_toto|Tour de France Pool Module mosConfig_absolute_path Remote File Include Vulnerability|x.x.x|x.x.x|Joomla Tour de France Pool 1.0.1|Tour de France Pool for Joomla is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/25183/
Component|com_gmaps|GMaps Component Index.PHP SQL Injection Vulnerability|x.x.x|x.x.x|Firestorm Technologies GMaps 1.00|The Joomla! GMaps component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/25146/
Core||Multiple Security Vulnerabilities|1.0.0|1.0.12||Joomla! is prone to multiple security vulnerabilities, including cross-site scripting, HTTP-response-splitting, and session-fixation issues. These issues occur because of design and configuration weaknesses and because the application fails to properly sanitize user-supplied input in several cases.A successful exploit of these vulnerabilities could allow an attacker to steal cookie-based authentication credentials, inject arbitrary hostile code, or potentially hijack another user's session. Presumably, some of these issues may facilitate remote execution of arbitrary script code in a victim's browser. Other attacks are also possible.|http://www.securityfocus.com/bid/25122/
Component|com_neorecruit|NeoRecruit Component SQL Injection Vulnerability|x.x.x|x.x.x|NeoJoomla NeoRecruit 1.4|NeoRecruit is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/25578/ http://www.exploit-db.com/exploits/14570/
Component|com_restaurante|Comp Restaurante Component Index.PHP Arbitrary File Upload Vulnerability|x.x.x|x.x.x|Detodas Comp Restaurante|The Joomla! Comp Restaurante component is prone to a vulnerability that lets attackers upload arbitrary files because it fails to verify the type of file being uploaded.Exploiting this issue could allow attackers to upload and execute arbitrary script code in the context of the affected webserver process.|http://www.securityfocus.com/bid/25612/
Component|com_joomlaradiov5|Joomla!Radio Component Local File Include Vulnerability|x.x.x|x.x.x|Joomla!Radio 5.0|Joomla! Joomla!Radio component is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.Exploiting this issue may allow an unauthorized user to view files and execute local scripts in the context of the webserver process.|http://www.securityfocus.com/bid/25664/
Component|com_joomlaflashfun|FlashFun Component mosConfig_live_site Remote File Include Vulnerability|x.x.x|x.x.x|RvA's Crappy Webhangout Joomla! FlashFun 1.0|The Joomla! FlashFun component is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/25680/
Component|com_joom12pic|12Pictures Component MosConfig_Live_Site Remote File Include Vulnerability|x.x.x|x.x.x|RvA's Crappy Webhangout Joomla!12Pictures 1.0|The Joomla!12Pictures component is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/25691/
Component|com_slideshow|com_slideshow Admin.Slideshow1.PHP Remote File Include Vulnerability|x.x.x|x.x.x|com_slideshow|The Joomla! com_slideshow component is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/25760/
Component|com_panoramic|Webmaster-Tips.net Joomla! Panoramic Component Remote File Include Vulnerability|x.x.x|x.x.x|com_panoramic|Webmaster-Tips.net Joomla! Panoramic component is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/25946/
Component|com_wmtgallery|Webmaster-Tips.net Joomla! Flash Image Gallery Component Remote File Include Vulnerability|x.x.x|x.x.x|com_wmtgallery|Webmaster-Tips.net Joomla! Flash Image Gallery component is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/25958/
Component|com_wmtportfolio|Webmaster-Tips.net Joomla! WMT Portfolio Remote File Include Vulnerability|x.x.x|x.x.x|com_wmtportfolio|Webmaster-Tips.net Joomla! WMT Portfolio is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/25959/
Component|com_mosmedia|Mambo/Joomla MOSMediaLite MosConfig_Absolute_Path Multiple Remote File Include Vulnerabilities|x.x.x|x.x.x|MOSMediaLite 4.5.1|The MOSMediaLite component is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/25960/
Component|index.php?mosConfig_absolute_path=|Template Module Index.PHP Remote File Include Vulnerability|x.x.x|x.x.x|Joomla Template Module Be2004-2|The Joomla Template module is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.An attacker can exploit these issues to execute malicious PHP code in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/23549/
Component|com_jpack|Joomla/Mambo JoomlaPack Module MosConfig_Absolute_Path Remote File Include Vulnerability|x.x.x|x.x.x|Joomla JoomlaPack 1.0.4a2 RE|JoomlaPack is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/23529/
Core|lib/pcltar.php|PHPConcept PCLTar PCLTar.PHP Remote File Include Vulnerability|1.5.0|1.5.0||PclTar is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.Exploiting this issue may allow an attacker to compromise applications that use the affected library as well as the underlying system; other attacks are also possible.NOTE: This vulnerability was originally thought to affect Joomla! directly. Further analysis has revealed that the issue affects the PclTar library. This record has been updated accordingly.|http://www.securityfocus.com/bid/23613/
Component|com_philaform|Phil-A-Form Component Index.PHP SQL Injection Vulnerability|x.x.x|x.x.x|Joomla Phil-a-Form Component 1.2.0.0|The Joomla Phil-A-Form component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.|http://www.securityfocus.com/bid/24211/
Component|com_jd-wiki|JD Wiki For Joomla Multiple Remote File Include Vulnerabilities|x.x.x|x.x.x|Joomla JD-Wiki 1.0.2|JD-Wiki is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.|http://www.securityfocus.com/bid/24342/
Component|com_letterman|Letterman Subscriber Module Mod_Lettermansubscribe.PHP Cross-Site Scripting Vulnerability|x.x.x|x.x.x|Joomla Letterman Subscriber Module 1.2.4-RC1|The Joomla! Letterman Subscriber module is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.|http://www.securityfocus.com/bid/24479/
Component|com_forum|Joomla/Mambo Mod_Forum Component PHPBB_Root.PHP Remote File Include Vulnerability|x.x.x|x.x.x|com_forum|The 'mod_forum' component for Joomla and Mambo is prone to a remote file-include vulnerability because the application fails to properly sanitize user-supplied input.An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to access the underlying system.|http://www.securityfocus.com/bid/24591/
Component|com_sitemap|Joomla/Mambo Com_SiteMap Component MosConfig_Absolute_Path Remote File Include Vulnerability|x.x.x|x.x.x|com_sitemap|The 'com_sitemap' component for Joomla/Mambo is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/24592/
Core||Administration Module Multiple Cross-Site Scripting Vulnerabilities|1.0.12|1.0.12||Joomla! is prone to multiple cross-site scripting vulnerabilities because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.These issues affect Joomla! 1.0.12; other versions may also be affected.For an exploit to succeed, the victim must be authenticated with administrator privileges. Successful attacks can cause malicious code to be persistently injected into active sections of a vulnerable website.|http://www.securityfocus.com/bid/24663/
Component|com_expose|Pony Gallery Component Index.PHP SQL Injection Vulnerability|x.x.x|x.x.x|Joomla Expose Component RC35|Joomla Expose component is prone to a vulnerability that lets attackers upload arbitrary files.This issue occurs because the application fails to sufficiently sanitize user-supplied input. Exploiting this issue could allow an attacker to upload and execute arbitrary script code in the context of the affected webserver process. This may help the attacker compromise the application; other attacks are possible.|http://www.securityfocus.com/bid/24958/
Component|com_ponygallery|Pony Gallery Component Index.PHP SQL Injection Vulnerability|x.x.x|x.x.x|Joomla Pony Gallery Component 1.5|The Joomla Pony Gallery component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/24972/
Core||Search Component Remote Command Execution Vulnerability|1.5.0|1.5.0||Joomla! is prone to a remote command-execution vulnerability because it fails to adequately sanitize user-supplied data.Attackers can exploit this issue to execute arbitrary commands with the privileges of the affected application. Successful attacks may facilitate a compromise of the application and underlying webserver; other attacks are also possible.Joomla! 1.5 beta 2 is reported vulnerable; prior versions may be affected as well. Note that the stable version 1.0.13 is not affected by this issue.|http://www.securityfocus.com/bid/24997/
Core||Joomlaboard Component Multiple Remote File Include Vulnerabilities|1.1.0|1.1.5||The Joomlaboard component is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to access the underlying system.|http://www.securityfocus.com/bid/23129/
Component|com_resman|WebFormatique Car Manager Joomla Component Index.PHP SQL Injection Vulnerability|x.x.x|x.x.x|webformatique Car Manager <= 1.1|Webformatique Car Manager component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.|http://www.securityfocus.com/bid/23131/
Component|com_rwcards|RWCards Component SQL Injection Vulnerability|x.x.x|x.x.x|Joomla RWCards Component 2.4.3|Joomla RWCards Component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.|http://www.securityfocus.com/bid/23126/
Component|com_ezine|D4JeZine Component Index.PHP SQL Injection Vulnerability|x.x.x|x.x.x|DesignForJoomla D4J eZine 2.8|The Joomla! D4JeZine component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation. This issue may help the attacker gain unauthorized access.|http://www.securityfocus.com/bid/23165/
Component|contact_type.php|Mambo/Joomla Taskhopper MosConfig_Absolute_Path Multiple Remote File Include Vulnerabilities|x.x.x|x.x.x|Taskhopper 1.1|Taskhopper is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/23408/
Component|com_mosmedia|Mambo/Joomla Com_Mosmedia MosConfig_Absolute_Path Multiple Remote File Include Vulnerabilities|x.x.x|x.x.x|com_mosmedia|The 'com_mosmedia' component is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/23432/
Component|mod_as_category|Joomla/Mambo Autostand Category Module MosConfig_Absolute_Path Remote File Include Vulnerability|x.x.x|x.x.x|Autostand Category 1.1|Autostand Category is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/23490/
Component|com_articles|Mambo/Joomla New Article Component Absolute_Path Multiple Remote File Include Vulnerabilities|x.x.x|x.x.x|Mambo New Article Component 1.1|Mambo/Joomla New Article component is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/23513/
Core||Multiple Input Validation Vulnerabilities|1.0.0|1.0.3||Joomla is prone to multiple input validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.The application is prone to multiple SQL injection vulnerabilities, multiple unspecified cross-site scripting vulnerabilities and a possibly security related error dealing with Media component file management functions.|http://www.securityfocus.com/bid/15526/
Core||Vcard Access Information Disclosure Vulnerability|1.0.0|1.0.5||Joomla is prone to an information disclosure vulnerability. This issue is due to a failure in the application to properly secure sensitive and privileged information.An attacker can exploit this issue to retrieve Vcard data. Such data consists of email addresses and other personal information. The information obtained may aid an attacker in harvesting email addresses for use in spam and malicious code attacks; other attacks are also possible.|http://www.securityfocus.com/bid/16185/
Core||IncludePath Remote File Include Vulnerability|1.0.0|1.0.0||Joomla is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and gain access to the underlying system.|http://www.securityfocus.com/bid/18363/
Core||Multiple Input Validation Vulnerabilities|1.0.0|1.0.9||Joomla! is prone to multiple input-validation vulnerabilities. The issues include cross-site scripting and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.A successful exploit of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.|http://www.securityfocus.com/bid/18742/
Component|com_lmo|Liga Manager Online Joomla! Component Remote File Include Vulnerability|x.x.x|x.x.x|Joomla Liga Manager Online 2.0|Liga Manager Online Joomla! Component is prone to a remote file-include vulnerability.This issue is due to a failure in the application to properly sanitize user-supplied input. An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process.This may allow the attacker to compromise the application and gain access to the underlying system.|http://www.securityfocus.com/bid/19234/
Component|com_jd-wiki|JD Wiki For Joomla Main.PHP Remote File Include Vulnerability|x.x.x|x.x.x|Joomla JD-Wiki 1.0.2|JD-Wiki is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.|http://www.securityfocus.com/bid/19373/
Component|com_webring|Webring Remote File Include Vulnerability|x.x.x|x.x.x|Joomla Webring Component 1.0|The Joomla Webring component is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to access the underlying system.|http://www.securityfocus.com/bid/19492/
Component|com_webring|Joomla Webring Component Admin.Webring.Docs.PHP SQL Injection Vulnerability|x.x.x|x.x.x|Joomla Webring Component 1.0|The Joomla Webring component is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.|http://www.securityfocus.com/bid/19511/
Component|com_zoommedia|Z00m Media Gallery Component mosConfig_absolute_path Remote File Include Vulnerability|x.x.x|x.x.x|Z00m Media Gallery Z00m Media Gallery 2.5.1 RC1 - RC2|The Joomla Z00m Media Gallery component is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/19601/
Component|com_kochsuite|Kochsuite Component mosConfig_absolute_path Remote File Include Vulnerability|x.x.x|x.x.x|Joomla Kochsuite 0.9.4|The Joomla Kochsuite component is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.|http://www.securityfocus.com/bid/19590/
Core||Poll Component Multiple User Session Validation Vulnerability|1.0.10|1.0.10||The Joomla poll component is prone to multiple user-session-validation vulnerabilities.An attacker can exploit these issues to bypass session validation; this may lead to other attacks.|http://www.securityfocus.com/bid/19592/
Component|com_comprofiler|Mambo/Joomla Com_comprofiler Plugin.class.PHP Remote File Include Vulnerability|x.x.x|x.x.x|Joomla com_comprofiler Component 1.0 RC2|The Mambo and Joomla com_comprofiler component is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.|http://www.securityfocus.com/bid/19725/
Core||Mambo/Joomla CMS ID SQL Injection Vulnerability|1.0.10|1.0.10||Mambo/Joomla CMS are prone to a common SQL-injection because the applications fail to properly sanitize user-supplied input before using it in an SQL query.A successful exploit could allow an attacker to compromise the applications, access or modify data, or exploit vulnerabilities in the underlying database implementation.|http://www.securityfocus.com/bid/19734/
Core||Mambo/Joomla CMS Multiple SQL Injection Vulnerabilities|1.0.10|1.0.10||Mambo/Joomla CMS are prone to multiple SQL-injection vulnerabilities because the applications fail to properly sanitize user-supplied input before using it in an SQL query.A successful exploit could allow an attacker to compromise the applications, access or modify data, or exploit vulnerabilities in the underlying database implementation.|http://www.securityfocus.com/bid/19719/
Core||Multiple Security Vulnerabilities|1.0.0|1.0.10||Joomla! is prone to multiple security vulnerabilities, including varius cross-site scripting, code-injection, input-validation, and access-control-bypass issues. These issues are caused by design and configuration weaknesseses and by a failure in the application to properly sanitize user-supplied input in several cases.A number of these issues may have already been documented in other BIDs.A successful exploit of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, inject arbitrary hostile code, or even exploit vulnerabilities in the underlying system or database implementation. Presumably, some of these issues may facilitate remote unauthorized access. Other attacks are also possible.|http://www.securityfocus.com/bid/19749/
Component|com_banners|Banner Component Index.PHP SQL Injection Vulnerability|x.x.x|x.x.x|com_banners|The Joomla Banner component is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.|http://www.securityfocus.com/bid/20159/
Core|com_contact|VirtueMart Joomla ECommerce Edition Multiple Input Validation Vulnerabilities|1.0.11|1.0.11|VirtueMart Joomla eCommerce Edition 1.0.11|VirtueMart Joomla eCommerce Edition is prone to multiple input-validation vulnerabilities because the application fails to properly sanitize user-supplied input.An attacker can exploit these issues to execute arbitrary HTML and script code in the browser of a victim user in the context of the affected website. This may allow the attacker to steal cookie-based authentication credentials, to control how the site is rendered to the user, and to launch other attacks.|http://www.securityfocus.com/bid/20236/
Component|com_bsqsitestats|BSQ Sitestats Joomla Component Multiple Input Validation Vulnerabilities|x.x.x|x.x.x|Joomla BSQ Sitestats 1.8|BSQ Sitestats is prone to multiple input-validation vulnerabilities because it fails to sufficiently sanitize user-supplied data.Exploiting these issues may allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation; other attacks are possible.|http://www.securityfocus.com/bid/20267/
Component|com_bsqsitestats|BSQ Sitestats Joomla Component HTML Injection and SQL Injection Vulnerabilities|x.x.x|x.x.x|Joomla BSQ Sitestats <= 2.2.1|BSQ Sitestats is prone to multiple input-validation vulnerabilities because it fails to sufficiently sanitize user-supplied data.Exploiting these issues may allow an attacker to steal cookie-based authentication credentials, control how the site is rendered to the user, access or modify data, or exploit latent vulnerabilities in the underlying database implementation. Other attacks are also possible.|http://www.securityfocus.com/bid/20614/
Component|com_jce|JCE Admin Component for Joomla Multiple Local File-Include Vulnerabilities|x.x.x|x.x.x|Joomla JCE Admin <= 1.1 beta 2|JCE Admin Component for Joomla is prone to multiple local file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.Successful exploits may allow remote attackers to view arbitrary files and to execute local scripts in the context of the webserver process. Other attacks may also possible.|http://www.securityfocus.com/bid/21491/
Component|com_jce|JCE Admin Component for Joomla Multiple Cross Site Scripting Vulnerabilities|x.x.x|x.x.x|Joomla JCE Admin <= 1.1 beta 2|JCE Admin Component is prone to multiple cross-site scripting vulnerabilities because the application fails to sufficiently sanitize user-supplied input.An attacker can exploit these issues to steal cookie-based authentication credentials and launch other attacks.|http://www.securityfocus.com/bid/21496/
Core||BE IT EasyPartner Joomla! Component Remote File Include Vulnerabilities|1.0.0|1.0.11||Joomla! is prone to an unspecified cross-site scripting vulnerability and multiple unspecified vulnerabilities.An attacker could likely exploit these vulnerabilities to access or modify sensitive information or to execute script code in the browser of an unsuspecting user; other attacks may also be possible.An attacker can leverage a cross-site scripting vulnerability to have arbitrary script code execute in the context of the affected site. A successful exploit will allow the attacker to steal cookie-based authentication credentials that can aid in further attacks; other attacks are also possible.|http://www.securityfocus.com/bid/21810/
Core||CMS Multiple SQL Injection Vulnerabilities|1.5.0|1.5.0||Joomla CMS is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in an SQL query.A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.|http://www.securityfocus.com/bid/22122/
Component|com_virtuemart|VirtueMart Joomla ECommerce Edition Multiple Input Validation Vulnerabilities|x.x.x|x.x.x|VirtueMart Joomla eCommerce Edition 1.0.7|VirtueMart Joomla eCommerce Edition is prone to multiple input-validation vulnerabilities because the application fails to properly sanitize user-supplied input.Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, obtain sensitive information, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.|http://www.securityfocus.com/bid/22123/
Component|com_countries|'com_countries' Component 'locat' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_countries|The 'com_countries' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/37561/
Component|com_remository|'com_remository' Component Arbitrary File Upload Vulnerability|x.x.x|x.x.x|com_remository|The 'com_remository' component for Joomla! is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to adequately sanitize user-supplied input.An attacker can exploit this vulnerability to upload arbitrary code and run it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.|http://www.securityfocus.com/bid/42794/
Component|com_remository|'com_remository' Component Multiple SQL Injection Vulnerabilities|x.x.x|x.x.x|com_remository|The 'com_remository' component for Joomla! is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/42658/
Core||'return' Parameter Open Redirection Vulnerability|1.0.0|1.0.15||Joomla! is prone to an open-redirection vulnerability because the application fails to properly sanitize user-supplied input.A successful exploit may aid in phishing attacks; other attacks are possible.|http://www.securityfocus.com/bid/42629/
Core||'return' Parameter Open Redirection Vulnerability|1.5.0|1.5.0||Joomla! is prone to an open-redirection vulnerability because the application fails to properly sanitize user-supplied input.A successful exploit may aid in phishing attacks; other attacks are possible.|http://www.securityfocus.com/bid/42629/
Component|com_fabrik|'com_fabrik' Component 'tableid' Parameter SQL Injection Vulnerability|x.x.x|x.x.x|com_fabrik|The 'com_fabrik' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.securityfocus.com/bid/42605/
Component|com_gantry|Gantry Framework 3.0.10 (Joomla) Blind SQL Injection Exploit|x.x.x|x.x.x|com_gantry|Gantry Framework 3.0.10 (Joomla) Blind SQL Injection Exploit|http://www.exploit-db.com/exploits/14911/
Component|com_clantools|Joomla Component Clantools version 1.2.3 Multiple Blind SQL Injection Vulnerability|x.x.x|x.x.x|com_clantools|Joomla Component Clantools version 1.2.3 Multiple Blind SQL Injection Vulnerability|http://www.exploit-db.com/exploits/14902/
Component|com_clantools|Joomla Component Clantools version 1.5 Blind SQL Injection Vulnerability|x.x.x|x.x.x|com_clantools|Joomla Component Clantools version 1.5 Blind SQL Injection Vulnerability|http://www.exploit-db.com/exploits/14901/
Component|com_magazine_3_0_1|iJoomla Magazine 3.0.1 Remote File Inclusion Vulnerability|x.x.x|x.x.x|com_magazine_3_0_1|iJoomla Magazine 3.0.1 Remote File Inclusion Vulnerability|http://www.exploit-db.com/exploits/14896/
Component|com_jefaqpro|Joomla Component (com_jefaqpro) Multiple Blind SQL Injection Vulnerabilities|x.x.x|x.x.x|com_jefaqpro|Joomla Component (com_jefaqpro) Multiple Blind SQL Injection Vulnerabilities|http://www.exploit-db.com/exploits/14846/
Component|com_picsell|Joomla Component (com_picsell) Local File Disclosure Vulnerability|x.x.x|x.x.x|com_picsell|Joomla Component (com_picsell) Local File Disclosure Vulnerability|http://www.exploit-db.com/exploits/14845/
Component|com_remository|Joomla Component (com_remository) Remote Upload File|x.x.x|x.x.x|com_remository|Joomla Component (com_remository) Remote Upload File|http://www.exploit-db.com/exploits/14811/
Core||Joomla 1.5 URL Redirecting Vulnerability|1.5.0|1.5.0||Joomla 1.5 URL Redirecting Vulnerability|http://www.exploit-db.com/exploits/14722/
Component|com_zoomportfolio|Joomla Component (com_zoomportfolio) SQL Injection Vulnerability|x.x.x|x.x.x|com_zoomportfolio|Joomla Component (com_zoomportfolio) SQL Injection Vulnerability|http://www.exploit-db.com/exploits/14718/
Component|com_Fabrik|Joomla Component (com_Fabrik) SQL Injection Vulnerability|x.x.x|x.x.x|com_Fabrik|Joomla Component (com_Fabrik) SQL Injection Vulnerability|http://www.exploit-db.com/exploits/14707/
Component|com_biblioteca|Joomla Component Biblioteca 1.0 Beta Multiple SQL Injection Vulnerabilities|x.x.x|x.x.x|com_biblioteca|Joomla Component Biblioteca 1.0 Beta Multiple SQL Injection Vulnerabilities|http://www.exploit-db.com/exploits/14703/
Component|com_zina|Joomla Component com_zina SQL Injection Vulnerability|x.x.x|x.x.x|com_zina|Joomla Component com_zina SQL Injection Vulnerability|http://www.exploit-db.com/exploits/14702/
Component|com_extcalendar|Joomla Component com_extcalendar Blind SQL Injection Vulnerability|x.x.x|x.x.x|com_extcalendar|Joomla Component com_extcalendar Blind SQL Injection Vulnerability|http://www.exploit-db.com/exploits/14694/
Component|com_ongallery|Joomla Component OnGallery SQL Injection Vulnerability|x.x.x|x.x.x|com_ongallery|Joomla Component OnGallery SQL Injection Vulnerability|http://www.exploit-db.com/exploits/14659/
Component|com_jgrid|Joomla Component Jgrid 1.0 Local File Inclusion Vulnerability|x.x.x|x.x.x|com_jgrid|Joomla Component Jgrid 1.0 Local File Inclusion Vulnerability|http://www.exploit-db.com/exploits/14656/
Component|com_equipment|Joomla Component (com_equipment) SQL Injection Vulnerability|x.x.x|x.x.x|com_equipment|Joomla Component (com_equipment) SQL Injection Vulnerability|http://www.exploit-db.com/exploits/14655/
Component|com_teams|Joomla Component Teams Multiple Blind SQL Injection Vulnerabilities|x.x.x|x.x.x|com_teams|Joomla Component Teams Multiple Blind SQL Injection Vulnerabilities|http://www.exploit-db.com/exploits/14598/
Component|com_amblog|Joomla Component Amblog 1.0 Multiple SQL Injection Vulnerabilities|x.x.x|x.x.x|com_amblog|Joomla Component Amblog 1.0 Multiple SQL Injection Vulnerabilities|http://www.exploit-db.com/exploits/14596/
Component|com_jomtube|Joomla Component com_jomtube (user_id) Blind SQL Injection / SQL Injection|x.x.x|x.x.x|com_jomtube|Joomla Component com_jomtube (user_id) Blind SQL Injection / SQL Injection|http://www.exploit-db.com/exploits/14434/
Component|com_cgtestimonial|Joomla Component cgTestimonial 2.2 Multiple Remote Vulnerabilities|x.x.x|x.x.x|com_cgtestimonial|Joomla Component cgTestimonial 2.2 Multiple Remote Vulnerabilities|http://www.exploit-db.com/exploits/14569/
Component|com_spielothek|Joomla Component Spielothek 1.6.9 Multiple Blind SQL Injection|x.x.x|x.x.x|com_spielothek|Joomla Component Spielothek 1.6.9 Multiple Blind SQL Injection|http://www.exploit-db.com/exploits/14518/
Component|com_pbbooking|Joomla Component PBBooking 1.0.4_3 Multiple Blind SQL Injection|x.x.x|x.x.x|com_pbbooking|Joomla Component PBBooking 1.0.4_3 Multiple Blind SQL Injection|http://www.exploit-db.com/exploits/14499/
Component|index.php?option=com_content&view=article&id=|Minify4Joomla Upload and Persistent XSS Vulnerability|x.x.x|x.x.x|com_content|Minify4Joomla Upload and Persistent XSS Vulnerability|http://www.exploit-db.com/exploits/14293/
Component|ixxo-cart-plus-demo/index.php|IXXO Cart for Joomla SQLi Vulnerability|x.x.x|x.x.x|IXXO Cart|IXXO Cart for Joomla SQLi Vulnerability|http://www.exploit-db.com/exploits/14291/
Component|com_ninjamonials|Joomla NijnaMonials Component (com_ninjamonials) Blind SQL Injection Vulnerability|x.x.x|x.x.x|com_ninjamonials|Joomla NijnaMonials Component (com_ninjamonials) Blind SQL Injection Vulnerability|http://www.exploit-db.com/exploits/14211/
Core||Persistant XSS Vulnerability|1.5.15|1.5.15||Persistant XSS Vulnerability|http://1337day.com/exploits/11088
Core||Joomla 1.5.12 connect back exploit|1.5.12|1.5.12||Joomla 1.5.12 connect back exploit|http://1337day.com/exploits/10723
Core||Joomla 1.5.12 read/exec remote files|1.5.12|1.5.12||Joomla 1.5.12 read/exec remote files|http://1337day.com/exploits/10722
Core||Joomla 1.5.x (Token) Remote Admin Change Password Vulnerability|1.5.0|1.5.0||Joomla 1.5.x (Token) Remote Admin Change Password Vulnerability|http://1337day.com/exploits/3527
Component|com_jgen|JGen Component  (com_jgen) SQL-i Vulnerability|x.x.x|x.x.x|com_jgen|JGen Component  (com_jgen) SQL-i Vulnerability|http://www.exploit-db.com/exploits/14998/ http://1337day.com/exploits/14073
Component|com_mtree|Mosets Tree 2.1.5 Shell Upload Vulnerability|x.x.x|x.x.x|com_mtree 2.1.5|Mosets Tree 2.1.5 Shell Upload Vulnerability|http://www.exploit-db.com/exploits/14995/ http://1337day.com/exploits/14070
Component|com_fss|FreeStyle SQL Injection Vulnerability|x.x.x|x.x.x|com_fss 1.5.6|Joomla FreeStyle SQL Injection Vulnerability|http://1337day.com/exploits/14101
Component|com_restaurantguide|Component com_restaurantguide Multiple Vulnerabilities|x.x.x|x.x.x|com_restaurantguide|Joomla Component com_restaurantguide Multiple Vulnerabilities|http://1337day.com/exploits/14108
Component|com_track|Component com_track SQL Injection Vulnerability|x.x.x|x.x.x|com_track|Joomla Component com_track SQL Injection Vulnerability|http://1337day.com/exploits/14086
Component|jootools|JooStock NasdaQ v1.5.0 Persistent Xss Vulnerability|x.x.x|x.x.x||Joomla JooStock NasdaQ v1.5.0 Persistent Xss Vulnerability|http://1337day.com/exploits/14124
Component|com_jcalendar|com_jcalendar Persistent Xss Vulnerability|x.x.x|x.x.x|com_jcalendar|Joomla com_jcalendar Persistent Xss Vulnerability|http://1337day.com/exploits/14123
Component|com_ticket|Component com_ticket LFI vulnerability|x.x.x|x.x.x|com_ticket|Joomla Component com_ticket LFI vulnerability|http://1337day.com/exploits/14116
Component|com_ezautos|Component com_ezautos SQL Injection Vulnerability|x.x.x|x.x.x|com_ezautos|Joomla Component com_ezautos SQL Injection Vulnerability|http://1337day.com/exploits/14162
Component|com_timetrack|TimeTrack Component v1.2.4 Multiple SQL Injection Vulnerabilities|x.x.x|x.x.x|com_timetrack|Joomla TimeTrack Component v1.2.4 Multiple SQL Injection Vulnerabilities|http://1337day.com/exploits/14161
Component|com_estate|Component com_estate blind Sql Injection Vulnerability|x.x.x|x.x.x|com_estate|Joomla Component com_estate blind Sql Injection Vulnerability|http://1337day.com/exploits/14164
Component|com_content|Component com_content File Upload Vulnerability|x.x.x|x.x.x|com_content|Joomla Component com_content File Upload Vulnerability|http://1337day.com/exploits/14165
Component|com_elite_experts|Component com_elite_experts SQL Injection Vulnerability|x.x.x|x.x.x|com_elite_experts|Joomla Component com_elite_experts SQL Injection Vulnerability|http://1337day.com/exploits/14191
Component|com_jeguestbook|JE Guestbook 1.0 Joomla Component Multiple Remote Vulnerabilities|x.x.x|x.x.x|com_jeguestbook|JE Guestbook 1.0 Joomla Component Multiple Remote Vulnerabilities|http://1337day.com/exploits/14266
Component|com_programas|Component com_programas SQL Injection Vulnerability|x.x.x|x.x.x|com_programas|Joomla Component com_programas SQL Injection Vulnerability|http://1337day.com/exploits/14287
Component|com_jedirectory|JE Directory <=  SQL Injection Exploit|x.x.x|x.x.x|com_jedirectory|Joomla JE Directory <=  SQL Injection Exploit|http://1337day.com/exploits/14289
Component|com_jeformcr|Component com_jeformcr LFI Vulnerability|x.x.x|x.x.x||Joomla Component com_jeformcr LFI Vulnerability|http://1337day.com/exploits/14376
Component|com_joomlapicasa2|Component com_joomlapicasa2 LFI Vulnerability|x.x.x|x.x.x|com_joomlapicasa2|Joomla Component com_joomlapicasa2 LFI Vulnerability|http://1337day.com/exploits/14377
Component|com_lurm|Component com_lurm RFI Vulnerability|x.x.x|x.x.x|com_lurm|Joomla Component com_lurm RFI Vulnerability|http://1337day.com/exploits/14378
Component|com_clubmanager|Component com_clubmanager Exploit|x.x.x|x.x.x|com_clubmanager|Joomla Component com_clubmanager Exploit|http://1337day.com/exploits/14383
Component|com_bsadv|Component com_bsadv Directory Traversal Vulnerability|x.x.x|x.x.x|com_bsadv|Joomla Component com_bsadv Directory Traversal Vulnerability|http://1337day.com/exploits/14384
Component|com_cbe|Community Builder Enhenced (CBE) Component LFI/RCE Vulnerability|x.x.x|x.x.x|com_cbe|Joomla Community Builder Enhenced (CBE) Component LFI/RCE Vulnerability|http://1337day.com/exploits/14395
Component|com_jscalendar|JS Calendar 1.5.1 Joomla Component Multiple Remote Vulnerabilities|x.x.x|x.x.x|com_jscalendar|JS Calendar 1.5.1 Joomla Component Multiple Remote Vulnerabilities|http://1337day.com/exploits/14397
Core||XSS Vulnerability|1.6.3|1.6.3||This vulnerability takes advantage of the recent Joomla 1.6.3 XSS vulnerability ( http://seclists.org/fulldisclosure/2011/Jun/519 ) to execute a CSRF vulnerability to create a superuser account.|http://www.exploit-db.com/exploits/17496/
Core||SQL-injection vulnerabilities|1.6.0|1.6.0||Joomla! is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.|http://www.exploit-db.com/exploits/16992/
Core||SQL-injection vulnerabilities|2.5.0|2.5.1||Joomla! Time Based SQL Injection Exploit.|http://www.exploit-db.com/exploits/18618/
Component|com_osproperty|Joomla com_osproperty Unrestricted File Upload|x.x.x|x.x.x|com_osproperty|Joomla com_osproperty Unrestricted File Upload|http://www.exploit-db.com/exploits/19829/
Component|com_ksadvertiser|Joomla com_KSAdvertiser Remote File & Bypass Upload Vulnerability|x.x.x|x.x.x|com_ksadvertiser|Joomla com_KSAdvertiser Remote File & Bypass Upload Vulnerability|http://www.exploit-db.com/exploits/19792/
Component|com_ponygallery|SQL injection Vulnerability|x.x.x|x.x.x|com_ponygallery|SQL injection Vulnerability|http://www.exploit-db.com/exploits/18741/
Component|com_bearleague|SQL injection Vulnerability|x.x.x|x.x.x|com_bearleague|SQL injection Vulnerability|http://www.exploit-db.com/exploits/18729/
Component|com_estateagent|SQL injection Vulnerability|x.x.x|x.x.x|com_estateagent|SQL injection Vulnerability|http://www.exploit-db.com/exploits/18728/
Component|com_discussions|SQL injection Vulnerability|x.x.x|x.x.x|com_discussions|SQL injection Vulnerability|http://www.exploit-db.com/exploits/18380/
Component|com_dshop|SQL injection Vulnerability|x.x.x|x.x.x|com_dshop|SQL injection Vulnerability|http://www.exploit-db.com/exploits/18251/
Component|com_qcontacts|SQL injection Vulnerability|x.x.x|x.x.x|com_qcontacts|QContacts 1.0.6 (Joomla component) SQL injection|http://www.exploit-db.com/exploits/18218/
Component|com_jobprofile|SQL injection Vulnerability|x.x.x|x.x.x|com_jobprofile|Joomla Component Jobprofile SQL injection Vulnerability|http://www.exploit-db.com/exploits/18192/
Component|com_alameda|SQL injection Vulnerability|x.x.x|x.x.x|com_alameda|Component Alameda SQL injection Vulnerability|http://www.exploit-db.com/exploits/18058/
Component|com_hmcommunity|Multiple Vulnerabilities|x.x.x|x.x.x|com_hmcommunity|Joomla Compenent com_hmcommunity Multiple Vulnerabilities|http://www.exploit-db.com/exploits/18050/
Component|com_osproperty|Unrestricted File Upload|x.x.x|x.x.x|com_osproperty|Joomla com_osproperty Unrestricted File Upload|http://1337day.com/exploits/18983
Component|com_ksadvertiser|Remote File & Bypass Upload Vulnerability|x.x.x|x.x.x|com_ksadvertiser|Joomla com_KSAdvertiser Remote File & Bypass Upload Vulnerability|http://1337day.com/exploits/18964
Component|com_redshop|Blind SQL Injection Vulnerability|x.x.x|x.x.x|com_redshop|Joomla Component redSHOP 1.5 Blind SQL Injection Vulnerability|http://1337day.com/exploits/18842
Component|com_szallasok|SQL Injection Vulnerability|x.x.x|x.x.x|com_szallasok|Joomla Component (com_szallasok) SQL Injection Vulnerability|http://1337day.com/exploits/18755
Component|com_peliculas|SQL Injection Vulnerability|x.x.x|x.x.x|com_peliculas|Joomla Component com_peliculas Sql Injection Vulnerability|http://1337day.com/exploits/18716
Component|com_hwdvideoshare|Arbitrary File Upload Vulnerability|x.x.x|x.x.x|com_hwdvideoshare|Joomla Components - hwdVideoShare Arbitrary File Upload Vulnerability|http://1337day.com/exploits/18663
Component|com_dionefileuploader|Arbitrary File Upload Vulnerability|x.x.x|x.x.x|com_dionefileuploader|Joomla Components - Dione FileUploader Arbitrary File Upload Vulnerability|http://1337day.com/exploits/18643
Component|com_maianmedia|Arbitrary File Upload Vulnerability|x.x.x|x.x.x|com_maianmedia|Joomla Components - Maian Media Arbitrary File Upload Vulnerability|http://1337day.com/exploits/18642
Component|com_jcalpro|SQL Injection Vulnerability|x.x.x|x.x.x|com_jcalpro|Joomla Component - JCal Pro Calendar - SQL Injection Vulnerability|http://1337day.com/exploits/18629
Component|com_filecabinet|SQL Injection Vulnerability|x.x.x|x.x.x|com_filecabinet|Joomla component  com_filecabinet Sql injection vulnerability|http://1337day.com/exploits/18619
Component|com_jfancy|Arbitrary File Upload Vulnerability|x.x.x|x.x.x|com_jfancy|Joomla Modules - jFancy  Arbitrary File Upload Vulnerability|http://1337day.com/exploits/18545
Component|com_artuploader|Arbitrary File Upload Vulnerability|x.x.x|x.x.x|com_artuploader|Joomla Modules - Art Uploader Arbitrary File Upload Vulnerability|http://1337day.com/exploits/18544
Component|com_joomsport|Multiple Vulnerabilities|x.x.x|x.x.x|com_joomsport|Joomla Component (com_joomsport) <= Multiple Vulnerabilities|http://1337day.com/exploits/18542
Component|com_dv|Arbitrary File Upload Vulnerability|x.x.x|x.x.x|com_dv|Joomla Components - DentroVideo Arbitrary File Upload Vulnerability|http://1337day.com/exploits/18540
Component|com_virtuemart|SQL Injection Vulnerability|x.x.x|x.x.x|com_virtuemart|Joomla Component (com_virtuemart) SQL injection Vulnerability|http://1337day.com/exploits/18192
Component|com_videogallery|Multiple Vulnerabilities|x.x.x|x.x.x|com_videogallery|Joomla com_videogallery (SQLi/LFI) Multiple Vulnerabilites|http://1337day.com/exploits/18125
Component|com_ccnewsletter|SQL Injection Vulnerability|x.x.x|x.x.x|com_ccnewsletter|Joomla Module (mod_ccnewsletter) Sql Injection Vulnerablity|http://1337day.com/exploits/18117
Component|com_ponygallery|SQL Injection Vulnerability|x.x.x|x.x.x|com_ponygallery|Joomla Component (com_ponygallery) SQL injection Vulnerability|http://1337day.com/exploits/18054
Component|com_jomestate|SQL Injection Vulnerability|x.x.x|x.x.x|com_jomestate|Joomla com_jomestate SQLi vulnerability|http://1337day.com/exploits/18048
Component|com_invest|LFI Vulnerability|x.x.x|x.x.x|com_invest|Joomla Component com_invest LFI Vulnerability|http://1337day.com/exploits/18039
Component|com_photomapgallery|SQL Injection Vulnerability|x.x.x|x.x.x|com_photomapgallery|Joomla Component (com_photomapgallery) SQL Injection Vulnerability|http://1337day.com/exploits/18035
Component|com_estateagent|SQL Injection Vulnerability|x.x.x|x.x.x|com_estateagent|Joomla Component (com_estateagent) SQL Injection Vulnerability|http://1337day.com/exploits/18029
Core||Information Disclosure and Security Bypass Vulnerabilities|2.5.0|2.5.4||Joomla! is prone to an information-disclosure and security-bypass vulnerabilities|http://www.securityfocus.com/bid/54073/
Core||Cross Site Scripting Vulnerability|2.5.0|2.5.4||Joomla! is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input|http://www.securityfocus.com/bid/53381/
Core||Cross Site Scripting Vulnerability|2.5.3|2.5.3||Joomla! 'Host' HTTP Header Cross Site Scripting Vulnerability|http://www.securityfocus.com/bid/53277/
Core||Predictable Password Generation And Information Disclosure Vulnerabilities|1.5.9|1.5.22||Joomla! Predictable Password Generation And Information Disclosure Vulnerabilities|http://www.securityfocus.com/bid/52750/
Core||Predictable Password Generation And Information Disclosure Vulnerabilities|2.5.0|2.5.3||Joomla! Predictable Password Generation And Information Disclosure Vulnerabilities|http://www.securityfocus.com/bid/52750/
Core||Unspecified Information Disclosure Vulnerabilities|1.5.0|1.5.23||Joomla! Unspecified Information Disclosure Vulnerabilities|http://www.securityfocus.com/bid/50188/
Core||Unspecified Information Disclosure Vulnerabilities|1.7.0|1.7.1||Joomla! Unspecified Information Disclosure Vulnerabilities|http://www.securityfocus.com/bid/50188/
Core||Unspecified Information Disclosure Vulnerabilities|1.6.x|1.6.x||Joomla! Unspecified Information Disclosure Vulnerabilities|http://www.securityfocus.com/bid/50188/
Core||Unspecified Information Disclosure Vulnerabilities|1.0.x|1.0.x||Joomla! Unspecified Information Disclosure Vulnerabilities|http://www.securityfocus.com/bid/50188/
Core||SQL Injection Vulnerability|2.5.0|2.5.0||Joomla! 'index.php' SQL Injection Vulnerability|http://www.securityfocus.com/bid/52549/
Core||Unspecified Parameter SQL Injection Vulnerability|2.5.0|2.5.1||Joomla! Unspecified Parameter SQL Injection Vulnerability|http://www.securityfocus.com/bid/52312/
Core||Unspecified Parameter SQL Injection Vulnerability|1.7.x|1.7.x||Joomla! Unspecified Parameter SQL Injection Vulnerability|http://www.securityfocus.com/bid/52312/
Core||Remote Privilege Escalation Vulnerability|2.5.0|2.5.2||Joomla! 'index.php' Remote Privilege Escalation Vulnerability|http://www.securityfocus.com/bid/52534/
Core||Predictable Password Generation Vulnerability|2.5.0|2.5.2||Joomla! Predictable Password Generation Vulnerability|http://www.securityfocus.com/bid/52535/
Core||Unspecified Cross Site Scripting Vulnerability|2.5.0|2.5.1||Joomla! Unspecified Cross Site Scripting Vulnerability|http://www.securityfocus.com/bid/52314/
Core||Multiple Information Disclosure Vulnerabilities|2.5.0|2.5.0||Joomla! Multiple Information Disclosure Vulnerabilities|http://www.securityfocus.com/bid/51857/
Core||Multiple Information Disclosure Vulnerabilities|1.7.0|1.7.||Joomla! Multiple Information Disclosure Vulnerabilities|http://www.securityfocus.com/bid/51857/
Core||Multiple Unspecified Cross Site Scripting and Information Disclosure Vulnerabilities|1.7.0|1.7.3||Joomla! Multiple Unspecified Cross Site Scripting and Information Disclosure Vulnerabilities|http://www.securityfocus.com/bid/51663/
Core||Multiple Unspecified Cross Site Scripting and Information Disclosure Vulnerabilities|1.6.x|1.6.x||Joomla! Multiple Unspecified Cross Site Scripting and Information Disclosure Vulnerabilities|http://www.securityfocus.com/bid/51663/
Core||Password Enumeration Weakness and Cross Site Scripting Vulnerability|1.7.0|1.7.2||Joomla! Password Enumeration Weakness and Cross Site Scripting Vulnerability|http://www.securityfocus.com/bid/50664/
Core||Password Enumeration Weakness and Cross Site Scripting Vulnerability|1.5.0|1.5.24||Joomla! Password Enumeration Weakness and Cross Site Scripting Vulnerability|http://www.securityfocus.com/bid/50664/
Core||Cross Site Scripting Vulnerability|1.5.x|1.5.x||Joomla! 1.6.3 and Prior Cross Site Scripting Vulnerability|http://www.securityfocus.com/bid/50634/
Core||Cross Site Scripting Vulnerability|1.6.0|1.6.3||Joomla! 1.6.3 and Prior Cross Site Scripting Vulnerability|http://www.securityfocus.com/bid/50634/
Core||Multiple Cross Site Scripting Vulnerabilities|1.7.0|1.7.0||Joomla! 1.7.0 and Prior Multiple Cross Site Scripting Vulnerabilities|http://www.securityfocus.com/bid/49853/
Core||Multiple Cross Site Scripting Vulnerabilities|1.6.x|1.6.x||Joomla! 1.7.0 and Prior Multiple Cross Site Scripting Vulnerabilities|http://www.securityfocus.com/bid/49853/
Core||Multiple Cross Site Scripting Vulnerabilities|1.5.x|1.5.x||Joomla! 1.7.0 and Prior Multiple Cross Site Scripting Vulnerabilities|http://www.securityfocus.com/bid/49853/
Core||Multiple Cross Site Scripting Vulnerabilities|1.6.0|1.6.5||Joomla! 1.6.5 and Prior Multiple Cross Site Scripting Vulnerabilities|http://www.securityfocus.com/bid/48805/
Core||Multiple Vulnerabilities|1.6.0|1.6.3||Joomla 1.6.3 and Prior Multiple Vulnerabilities|http://www.securityfocus.com/bid/48475/
Core||Multiple Vulnerabilities|1.5.x|1.5.x||Joomla 1.6.3 and Prior Multiple Vulnerabilities|http://www.securityfocus.com/bid/48475/





