<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="http://docs.joomla.org/skins/common/feed.css?303"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>http://docs.joomla.org/api.php?action=feedcontributions&amp;user=CirTap&amp;feedformat=atom</id>
		<title>Joomla! Documentation - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="http://docs.joomla.org/api.php?action=feedcontributions&amp;user=CirTap&amp;feedformat=atom"/>
		<link rel="alternate" type="text/html" href="http://docs.joomla.org/Special:Contributions/CirTap"/>
		<updated>2013-05-21T11:24:46Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.19.3</generator>

	<entry>
		<id>http://docs.joomla.org/User_talk:E-builds</id>
		<title>User talk:E-builds</title>
		<link rel="alternate" type="text/html" href="http://docs.joomla.org/User_talk:E-builds"/>
				<updated>2012-08-10T23:24:31Z</updated>
		
		<summary type="html">&lt;p&gt;CirTap: regarding your deletion request&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;regarding your deletion request, see my talk page --&amp;lt;span class=&amp;quot;plainlinks&amp;quot;&amp;gt;[[User:CirTap|CirTap]] &amp;lt;small&amp;gt;([[User talk:CirTap|talk]] • [[Special:Contributions/CirTap|contribs]])&amp;lt;/small&amp;gt;&amp;lt;/span&amp;gt;&lt;/div&gt;</summary>
		<author><name>CirTap</name></author>	</entry>

	<entry>
		<id>http://docs.joomla.org/User_talk:CirTap</id>
		<title>User talk:CirTap</title>
		<link rel="alternate" type="text/html" href="http://docs.joomla.org/User_talk:CirTap"/>
				<updated>2012-08-10T23:24:13Z</updated>
		
		<summary type="html">&lt;p&gt;CirTap: /* Request for deletion? How to delete docs.joomla page? */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Welcome stranger! {{1}}Leave a note if you dare, it may happen I reply.&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Request for deletion? How to delete docs.joomla page? ==&lt;br /&gt;
&lt;br /&gt;
I have done some development pages editing on this wiki, and one of the steps requiers deleting the following page, but no templates work (delete, rfd, RFD).&lt;br /&gt;
So how, do I do this.&lt;br /&gt;
&lt;br /&gt;
Page in question [[Setting up a testing environment]]&lt;br /&gt;
Reason: Old and integrated the article into this one: [[Setting up your workstation for joomla development]]&lt;br /&gt;
&lt;br /&gt;
P.S. Sorry to put that here, but I have searched for over an hour now for answers (also a quick look on joomla forum &amp;quot;Dos&amp;quot;). Might update the editing help pages.&lt;br /&gt;
&amp;lt;a href=&amp;quot;e-motiv.net&amp;quot;&amp;gt;e-motiv development&amp;lt;/a&amp;gt;&lt;br /&gt;
&lt;br /&gt;
:The &amp;quot;rfd&amp;quot; templates no not exists. I can't recall if they ever existed in the first place an if so, who delete them.&lt;br /&gt;
:Other pages link to [[Setting up a testing environment]] so deletion is not an option until the links are not resolved (re-linked) properly to another page page.&lt;br /&gt;
:I may add a redirect however to the page, but please let me know if you were referring to&lt;br /&gt;
:* [[Setting up your workstation for joomla development]] **OR**&lt;br /&gt;
:* [[Setting up your workstation for Joomla! development]]&lt;br /&gt;
:They all seem to deal with the same content ...&lt;br /&gt;
: --&amp;lt;span class=&amp;quot;plainlinks&amp;quot;&amp;gt;[[User:CirTap|CirTap]] &amp;lt;small&amp;gt;([[User talk:CirTap|talk]] • [[Special:Contributions/CirTap|contribs]])&amp;lt;/small&amp;gt;&amp;lt;/span&amp;gt;&lt;/div&gt;</summary>
		<author><name>CirTap</name></author>	</entry>

	<entry>
		<id>http://docs.joomla.org/User_talk:CirTap</id>
		<title>User talk:CirTap</title>
		<link rel="alternate" type="text/html" href="http://docs.joomla.org/User_talk:CirTap"/>
				<updated>2012-08-10T23:16:28Z</updated>
		
		<summary type="html">&lt;p&gt;CirTap: /* Request for deletion? How to delete docs.joomla page? */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Welcome stranger! {{1}}Leave a note if you dare, it may happen I reply.&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Request for deletion? How to delete docs.joomla page? ==&lt;br /&gt;
&lt;br /&gt;
I have done some development pages editing on this wiki, and one of the steps requiers deleting the following page, but no templates work (delete, rfd, RFD).&lt;br /&gt;
So how, do I do this.&lt;br /&gt;
&lt;br /&gt;
Page in question [[Setting up a testing environment]]&lt;br /&gt;
Reason: Old and integrated the article into this one: [[Setting up your workstation for joomla development]]&lt;br /&gt;
&lt;br /&gt;
P.S. Sorry to put that here, but I have searched for over an hour now for answers (also a quick look on joomla forum &amp;quot;Dos&amp;quot;). Might update the editing help pages.&lt;br /&gt;
&amp;lt;a href=&amp;quot;e-motiv.net&amp;quot;&amp;gt;e-motiv development&amp;lt;/a&amp;gt;&lt;/div&gt;</summary>
		<author><name>CirTap</name></author>	</entry>

	<entry>
		<id>http://docs.joomla.org/User_talk:CirTap</id>
		<title>User talk:CirTap</title>
		<link rel="alternate" type="text/html" href="http://docs.joomla.org/User_talk:CirTap"/>
				<updated>2012-08-10T22:48:10Z</updated>
		
		<summary type="html">&lt;p&gt;CirTap: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Welcome stranger! {{1}}Leave a note if you dare, it may happen I reply.&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Request for deletion? How to delete docs.joomla page? ==&lt;br /&gt;
&lt;br /&gt;
I have done some development pages editing on this wiki, and one of the steps requiers deleting the following page, but no templates work (delete, rfd, RFD).&lt;br /&gt;
So how, do I do this.&lt;br /&gt;
&lt;br /&gt;
Page in question [[Setting up a testing environment]]&lt;br /&gt;
Reason: Old and integrated the article into this one:Setting up your workstation for joomla development&lt;br /&gt;
&lt;br /&gt;
P.S. Sorry to put that here, but I have searched for over an hour now for answers (also a quick look on joomla forum &amp;quot;Dos&amp;quot;). Might update the editing help pages.&lt;br /&gt;
&amp;lt;a href=&amp;quot;e-motiv.net&amp;quot;&amp;gt;e-motiv development&amp;lt;/a&amp;gt;&lt;/div&gt;</summary>
		<author><name>CirTap</name></author>	</entry>

	<entry>
		<id>http://docs.joomla.org/Migrating_from_Joomla_1.5_to_Joomla_1.6%2B</id>
		<title>Migrating from Joomla 1.5 to Joomla 1.6+</title>
		<link rel="alternate" type="text/html" href="http://docs.joomla.org/Migrating_from_Joomla_1.5_to_Joomla_1.6%2B"/>
				<updated>2011-11-04T18:04:22Z</updated>
		
		<summary type="html">&lt;p&gt;CirTap: /* Before You Get Started */  1.5.24&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;With Joomla 1.6 officially released, there have been a lot of questions as to how to migrate or upgrade to Joomla 1.6 from 1.5. This guide will take you step-by-step through the general procedure of how to migrate to Joomla 1.6.&lt;br /&gt;
Please read through all the material as this is not a light undertaking.&lt;br /&gt;
=Before Upgrading=&lt;br /&gt;
Don't let the numerical closeness of 1.5 and 1.6, mislead you. Joomla 1.6 took three years to develop and has been a major undertaking. Countless hours have been spent by many volunteers from around the world to put it all together. Although much of the code is the same from Joomla 1.5, much of it has been written from the ground up, and the changes are comparable to the changes from Joomla 1.0 to 1.5.&lt;br /&gt;
Because the changes from Joomla 1.5 to 1.6 are so large and because of the massive effort put into getting Joomla 1.6 to where it is today, there is no core upgrade path, this is indeed a migration. In planned future releases of Joomla (which will be released every 6 months), such as Joomla 1.7, 1.8, etc, the changes from version to version will be more incremental and a core upgrade path is planned.&lt;br /&gt;
Now that Joomla 1.6 is finally here and stable, a community initiative led by the developers of Joomla is turning towards [http://extensions.joomla.org/extensions/migration-a-conversion/joomla-migration/11658 jUpgrade] (a 3rd party Joomla extension on the JED originally developed by Matias Aguirre) for help and to help. Many of Joomla's developers (who are all volunteers that freely contribute their time) are volunteering to put the finishing touches on [http://extensions.joomla.org/extensions/migration-a-conversion/joomla-migration/11658 jUpgrade].&lt;br /&gt;
&lt;br /&gt;
[http://extensions.joomla.org/extensions/migration-a-conversion/joomla-migration/11658 jUpgrade] allows you to migrate from Joomla 1.5 to 1.6.&lt;br /&gt;
Lets get started!&lt;br /&gt;
==Review the Requirements==&lt;br /&gt;
Please, please save yourself (and possibly your clients) a lot of headaches and make sure that your server (and in the case of jUpgrade, your browser too) is up for the task.  please review the [http://docs.joomla.org/Joomla_1.6_technical_requirements technical requirements for Joomla! 1.6].  Please review the [http://www.matware.com.ar/joomla/jupgrade.html requirements for jUpgrade] as well.&lt;br /&gt;
==Before You Get Started==&lt;br /&gt;
Before you get started, there are a few things that you are going to have to check and/or think about:&lt;br /&gt;
# Is your Joomla 1.5 version up to date? The most up-to-date version of Joomla 1.5 is 1.5.24. If your version is not up-to-date, upgrade to 1.5.24 before migrating, especially if you are running Joomla 1.5.11 or lower.&lt;br /&gt;
# Do all your extensions have Joomla 1.6 native versions? At the time of the writing of this tutorial there are 108 available on the JED. Please note that jUpgrade is not currently able to upgrade Joomla 3rd party extensions, so those will have to be done via their respective upgrade procedures. This is however a work in progress.&lt;br /&gt;
# Have you modified any core files? Any changes that you have made to core files in Joomla will be lost so please be forewarned.&lt;br /&gt;
# Is there a Joomla 1.6 compatible template available from your template provider? If not, do you feel comfortable making the changes yourself? There are a couple good resources:&lt;br /&gt;
## [http://community.joomla.org/blogs/community/1257-16-templates.html Chad Windnagle's Joomla Community blog]&lt;br /&gt;
## [http://www.slideshare.net/chrisdavenport/template-changes-for-joomla-16 Chris Davenport's &amp;quot;Template Changes for Joomla 1.6&amp;quot; presentation]&lt;br /&gt;
## [[Upgrading a Joomla 1.5 template to Joomla 1.6|Joomla's Docs Template Tutorial]] Please note that although jUpgrade is not able to currently upgrade templates, the developers are working hard at implementing the feature.&lt;br /&gt;
# Is your language pack available in Joomla 1.6?  [http://community.joomla.org/translations/joomla-16-translations.html Find your Joomla1 1.6 Translation].&lt;br /&gt;
# Do you have folder or file permissions issues in your Joomla 1.5 installation?&lt;br /&gt;
# Do you NEED to migrate to Joomla 1.6? Joomla 1.5 is powerful and very mature. For many people there is not a need to rush into Joomla 1.6. Joomla will continue to support Joomla 1.5 for at least another year and three months, releasing security updates and bug squashing updates when needed.&lt;br /&gt;
#: The two main features of Joomla 1.6 that makes it superior to Joomla 1.5 are: Access Control List (ACL) and nested categories. Gone are the days of simply having guests, registered users, authors, and editors, without being able to specify what they can and can't do in the frontend. Also, with 1.6 you can have more flexibility of organizing (and therefore displaying) your content with nicely organized categories within categories. No more being restricted to the section &amp;gt;&amp;gt; category structure. Those are all great things to have (especially the ACL), however, for many 1.5 users, it isn't needed. The main point is to decide for yourself.&lt;br /&gt;
#: For a massive list of changes from Joomla 1.5 to Joomla 1.6, please see [[What's new in Joomla 1.6]].&lt;br /&gt;
&lt;br /&gt;
==Backup, Backup, Backup==&lt;br /&gt;
Skipping this part is perhaps the biggest mistake you can make. If you have a proper backup (or several) you can always revert back if needed. However, if you don't properly backup your site and something goes wrong, you are going to waste a lot of valuable time, and sometimes a lot money, getting things back to the way they were. So please backup!&lt;br /&gt;
&lt;br /&gt;
==== Using Akeeba to backup ====&lt;br /&gt;
&lt;br /&gt;
* Akeeba Backup produces a .jpa file&lt;br /&gt;
&lt;br /&gt;
* The .jpa file contains all the folders/files and database files.&lt;br /&gt;
&lt;br /&gt;
* The .jpa file also contains an installer&lt;br /&gt;
&lt;br /&gt;
* Kickstart.php (from Akeeba) unpacks the .jpa file&lt;br /&gt;
&lt;br /&gt;
* You then run the installer and install your site like a Joomla install.&lt;br /&gt;
&lt;br /&gt;
* The installer has an option to change the configuration for restoring to a different location &lt;br /&gt;
&lt;br /&gt;
After you create the Database for your Joomla download and install Akeeba, it can be download from [http://extensions.joomla.org/extensions/access-a-security/site-security/backup/1606 Joomla extension directory].  There is a link to full instructions there as well.&lt;br /&gt;
&lt;br /&gt;
=Upgrading=&lt;br /&gt;
==Download jUpgrade==&lt;br /&gt;
Download the [http://www.matware.com.ar/downloads/joomla/jupgrade.html latest version of jUpgrade]. It is highly advisible, especially when development still is progressing, to always use the latest available version!&lt;br /&gt;
&lt;br /&gt;
==Optional Testing Environment==&lt;br /&gt;
If you are really nervous by this point and your heart is beating fast, then you should probably set up a testing environment.&lt;br /&gt;
&lt;br /&gt;
=== Install XAMPP ===&lt;br /&gt;
XAMPP is an easy-to-install package that bundles the Apache web server, PHP, XDEBUG, and the MySql database. This allows you to create the environment you need to run Joomla! on your local machine. The latest version of XAMPP is available at [http://www.apachefriends.org/en/xampp.html the XAMPP web site]. Downloads are available for Linux, Windows, Mac OS X and Solaris. Download the package for your platform. &lt;br /&gt;
&lt;br /&gt;
''Important Note Regarding XAMPP and Skype:'' Apache and Skype both use port 80 as an alternative for incoming connections. If you use Skype, go into the Tools-Options-Advanced-Connection panel and deselect the &amp;quot;Use 80 and 443 as alternatives for incoming connections&amp;quot; option. If Apache starts as a service, it will take 80 before Skype starts and you will not see a problem. But, to be safe, disable the option in Skype.&lt;br /&gt;
&lt;br /&gt;
'''Update'''&lt;br /&gt;
&lt;br /&gt;
''As of August 5, 2010, XDebug has been updated (to version 2.1) which fixes some important bugs (for example, watching local variables for nesting functions). The latest XAMPP package (1.7.3) now includes this new version of XDebug. If you just want to update XDebug, you can download the latest module from [http://www.xdebug.org]. There is a handy website that tells you which XDebug binary you need, depending on your phpinfo() information [http://xdebug.org/find-binary.php here]. To use it, you just copy the output of your phpinfo() display and paste it into the form on the site.''&lt;br /&gt;
&lt;br /&gt;
===== Installation on Windows =====&lt;br /&gt;
&lt;br /&gt;
Installation for Windows is very simple. You can use the XAMPP installer executable (for example, &amp;quot;xampp-win32-1.7.3-installer.exe&amp;quot;). Detailed installation instructions for Windows are available [http://www.apachefriends.org/en/xampp-windows.html here]. &lt;br /&gt;
&lt;br /&gt;
For Windows, it is recommended to install XAMPP in &amp;quot;c:\xampp&amp;quot; (not in &amp;quot;c:\program files&amp;quot;). If you do this, your Joomla! (and any other local web site folders) will go into the folder &amp;quot;c:\xampp\htdocs&amp;quot;. (By convention, all web content goes under the &amp;quot;htdocs&amp;quot; folder.)&lt;br /&gt;
&lt;br /&gt;
If you have multiple http servers (like IIS) you can change the xampp listening port. In &amp;lt;xamppDir&amp;gt;\apache\conf\httpd.conf, modify the line Listen 80 to Listen [portnumber] (ex: &amp;quot;Listen 8080&amp;quot;).&lt;br /&gt;
&lt;br /&gt;
===== Installation on Linux =====&lt;br /&gt;
&lt;br /&gt;
Install xammp&lt;br /&gt;
Open Terminal and enter: &lt;br /&gt;
 sudo tar xvfz xampp-linux-1.7.3a.tar.gz -C /opt&lt;br /&gt;
(replace ''xampp-linux-1.7.3a.tar.gz'' with the version of xammp you downloaded).&lt;br /&gt;
It has been reported that the MYSQL database of xampp 1.7.4 does not work with Joomla 1.5.22&lt;br /&gt;
&lt;br /&gt;
This installs ... Apache2, mysql and php5 as well as an ftp server.&lt;br /&gt;
 &lt;br /&gt;
 ''sudo /opt/lampp/lampp start''&lt;br /&gt;
&lt;br /&gt;
and&lt;br /&gt;
 ''sudo /opt/lampp/lampp stop''&lt;br /&gt;
&lt;br /&gt;
starts/stops all the services&lt;br /&gt;
&lt;br /&gt;
==== Test your xammp localhost server ====&lt;br /&gt;
Open your Browser and point it to&lt;br /&gt;
 http://localhost&lt;br /&gt;
The index.php will redirect to&lt;br /&gt;
 http://localhost/xammp&lt;br /&gt;
&lt;br /&gt;
There you will find instructions on how to change default usernames/passwords.  On a PC that does not serve files to the Internet or LAN then changing the defaults is personal choice.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Install jUpgrade ==&lt;br /&gt;
Go to your Joomla backend. e.g. www.yoursite.com/administrator&lt;br /&gt;
&lt;br /&gt;
'''Extensions''' &amp;gt;&amp;gt; '''Install/Uninstall'''&lt;br /&gt;
&lt;br /&gt;
[[Image:Installjupgrade.png|alt=Installing jUpgrade]]&lt;br /&gt;
&lt;br /&gt;
'''Browse''' &amp;gt;&amp;gt; '''Select com_jupgrade''' &amp;gt;&amp;gt; '''Upload File &amp;amp; Install'''&lt;br /&gt;
&lt;br /&gt;
[[Image:browse.png|Browse and Upload Component]]&lt;br /&gt;
&lt;br /&gt;
[[Image:Installjupgrade2.png|alt=Installing jUpgrade]]&lt;br /&gt;
&lt;br /&gt;
== Enable Mootools Upgrade Plugin ==&lt;br /&gt;
# Go to Extensions | Plugin Manager&lt;br /&gt;
# Search for &amp;quot;System - Mootools Upgrade&amp;quot;&lt;br /&gt;
# Enable the plugin&lt;br /&gt;
It is important that this plugin is installed and that it has been set to enabled, as the proper functioning of jUpgrade depends on it.&lt;br /&gt;
&lt;br /&gt;
== Configure Options ==&lt;br /&gt;
As of jUpgrade version 1.1.1, support is present to migrate to Joomla! 1.6, Joomla! 1.7, and an old Molajo build.  As well, for jUpgrade to be successful, you must configure your current table prefix prior to beginning the migration.  The following are the options that can be configured with jUpgrade:&lt;br /&gt;
&lt;br /&gt;
Global:&lt;br /&gt;
* Distribution - Select whether to migrate to Joomla! 1.6, 1.7, or Molajo&lt;br /&gt;
* Prefix for old database - Your current table prefix&lt;br /&gt;
* Prefix for new database - Your selected table prefix for your migrated site&lt;br /&gt;
&lt;br /&gt;
Skips:&lt;br /&gt;
* Skip checks - Skip pre-migration checks&lt;br /&gt;
* Skip download - Skip downloading the package (Note: Must have a package already downloaded to your temp folder or set this and Skip Decompress if set to yes)&lt;br /&gt;
* Skip decompress - Skip decompressing the downloaded package (Note: Must have a package already downloaded and decompressed to site_root/jupgrade if set to Yes)&lt;br /&gt;
&lt;br /&gt;
Templates:&lt;br /&gt;
* Keep original positions - Keep the currently defined positions for modules&lt;br /&gt;
&lt;br /&gt;
Debug:&lt;br /&gt;
* Enable Debug - Enable this to have messages displayed below the migration process concerning the progress, helpful if having issues&lt;br /&gt;
&lt;br /&gt;
[[Image:Jupgrade_options.png|alt=jUpgrade 1.1.1 Options]]&lt;br /&gt;
&lt;br /&gt;
== Migration ==&lt;br /&gt;
'''Components''' &amp;gt;&amp;gt; '''jUpgrade'''&lt;br /&gt;
&lt;br /&gt;
[[Image:Accessjupgrade.png]]&lt;br /&gt;
&lt;br /&gt;
'''Start Upgrade'''&lt;br /&gt;
&lt;br /&gt;
[[Image:Startjupgrade.png|alt=Start jUpgrade]]&lt;br /&gt;
&lt;br /&gt;
[[Image:Runjupgrade.png|alt=Run jUpgrade]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Do not exit the screen''' until everything has finished loading. Scroll down to check if finished.&lt;br /&gt;
&lt;br /&gt;
[[Image:Jupgradefinished.png|alt=jUpgrade Finished]]&lt;br /&gt;
&lt;br /&gt;
'''Success!!!'''&lt;br /&gt;
&lt;br /&gt;
Please note that jUpgrade currently does not migrate templates, only default templates.&lt;br /&gt;
&lt;br /&gt;
==Behind the Scenes==&lt;br /&gt;
As explained in the background information, the changes from Joomla 1.5 and 1.6 are quite significant.  The fact that jUpgrade creates a new Joomla 1.6 installation for us is, in my opinion, pure genius. If the migration process was not 100% successful, your Joomla 1.5 is still perfectly intact and none of your users are affected. You have an opportunity to check out your site both in the frontend and the backend to make sure everything is up to par.  So what actually happens? jUpgrade downloads the latest version of Joomla 1.6 for you to the jupgrade directory (which it creates) in the root folder of your Joomla 1.5 installation. It then extracts all the files from the download. Once extraction has completed, jUpgrade installs Joomla 1.6 and then proceeds to migrate your old database to the new Joomla 1.6 database which it has created.&lt;br /&gt;
Your Joomla 1.6 site will be installed in www.mysites.com/jupgrade assuming that your Joomla 1.5 installation is in your html root.&lt;br /&gt;
==Check Your Joomla! 1.6==&lt;br /&gt;
Please do a full site review of your Joomla 1.6 installation and make sure everything is set up properly.&lt;br /&gt;
Your Joomla 1.6 site will be installed in www.mysites.com/jupgrade assuming that your Joomla 1.5 installation is in your html root.&lt;br /&gt;
Here is a general checklist to check:&lt;br /&gt;
* Banners&lt;br /&gt;
* Categories&lt;br /&gt;
* Contacts&lt;br /&gt;
* Content&lt;br /&gt;
* Menus&lt;br /&gt;
* Modules&lt;br /&gt;
* Newsfeeds&lt;br /&gt;
* Users&lt;br /&gt;
* Weblinks&lt;br /&gt;
* Templates - Work is currently being done on the template upgrade feature of jUpdate and it is not yet fully functional. Your module positions may have to be adjusted in module manager.&lt;br /&gt;
==Backup Joomla! 1.6==&lt;br /&gt;
If everything looks good to go, then let's backup the new Joomla 1.6 installation.&lt;br /&gt;
==Overview of the Rest of the Process==&lt;br /&gt;
Quick overview of what we are going to try to do now:&lt;br /&gt;
# Relocate our Joomla 1.5 installation to a subfolder as a &amp;quot;just in case&amp;quot;.&lt;br /&gt;
# Relocate our Joomla 1.6 installation to the html folder.&lt;br /&gt;
'It should happen in this order' If you do it in reverse order, the Joomla 1.6 files will get mixed with the Joomla 1.5 files (many of 1.5 files will be overwritten) and you will have a big mess!  Your site will likely still work, but it's a security ticking time bomb waiting to go off.&lt;br /&gt;
&lt;br /&gt;
=Going Live=&lt;br /&gt;
Next log onto your host's file manager (e.g. cPanel, Plesk, etc) or an FTP Client, however, preferably a file manager.&lt;br /&gt;
The general procedure is (it should take about 30 seconds if you review the steps before you start):&lt;br /&gt;
# Create a subfolder (e.g. myoldsite) for the Joomla 1.5 installation in your html root, e.g. public_html/myoldsite&lt;br /&gt;
# Select all the folders (***except the jupgrade folder***) and files in the html root and move them into the Joomla 1.5 subfolder (e.g. myoldsite)&lt;br /&gt;
# Select all the folders and files in the jupgrade folder and move them to the html root&lt;br /&gt;
# Double check the frontend and backend&lt;br /&gt;
&lt;br /&gt;
=How to Manually Migrate Joomla=&lt;br /&gt;
If Jupgrade did not work out for you like many of us, you might want to consider manual upgrade. '''Be warned, however, that this process is very tedious (especially see step 6 below), and the procedure is not well tested as of yet (if at all)'''. So just like the Jupgrade method, you will want to backup your database just in case. Before upgrading you should check to make sure every extension you want is joomla 1.6/1.7 compatible. Also back up your directory files just in case and keep a list of the extensions you used.&lt;br /&gt;
&lt;br /&gt;
Now onto the upgrade; please note that the following procedure should only be chosen if all else fails, and requires a good working knowledge of SQL! See the last paragraph of this section for a possibly less tedious alternative to doing steps 1, 2, 6 and 7) :&lt;br /&gt;
&lt;br /&gt;
'''Step 0:''' First of all, as always before big changes, backup all your data; that includes all files as well as exporting all database tables.&lt;br /&gt;
&lt;br /&gt;
'''Step 1:''' If you want, you can convert the prefixes of all the tables in your database. This is especially useful if you would like to keep your 1.5 database in parallel to your 1.6/1.7 installation, at least for the transition period. It is best done using a script, here is one that worked pretty well as seen on [http://www.nilpo.com/2009/01/web-development/mysql-table-prefix-changer-tool/ Nilop]. '''Beware''', however, that executing this script will stop your old site from working because after the prefix conversion, your old installation can't access the database anymore (it will still try to access the tables by their old prefix)! To enable it again, import the database export created in step 0 after the script has finished running. Joomla 1.5 usually has the prefix of &amp;quot;jos&amp;quot; which you can convert to the prefix &amp;quot;jml&amp;quot; or &amp;quot;j16&amp;quot;, for example. So using your ftp install the php converter script onto the root of your site. It should be at the url '''Mysite.com'''/prefix.php which all you need to do is fill in the database information. After this you have all the tables nicely converted to the new prefix.&lt;br /&gt;
&lt;br /&gt;
[[File:Changer.JPG|center]]&lt;br /&gt;
&lt;br /&gt;
Notice in the following screen shot that the sql data is &amp;quot;jos&amp;quot;:&lt;br /&gt;
[[File:Tables.JPG|thumb|center|500px]]&lt;br /&gt;
&lt;br /&gt;
You want it converted to &amp;quot;jml&amp;quot; as seen here:&lt;br /&gt;
[[File:Prefix.JPG|thumb|center|500px]]&lt;br /&gt;
&lt;br /&gt;
'''Step 2:''' Export all the database tables you would like to use on your joomla 1.6+ site. Usually this is things like content and components.&lt;br /&gt;
&lt;br /&gt;
[[File:Export.JPG|thumb|center|500px]]&lt;br /&gt;
&lt;br /&gt;
'''Step 3:''' Uninstall your old site including the database, files, and directories that are associated with joomla. Or if you would rather just test the upgrade, skip step this step and create a new directory for your joomla 1.6+ site.&lt;br /&gt;
&lt;br /&gt;
'''Step 4:''' Install the new joomla which is done through a ftp or a cpanel. If you have no database associated with it, install a new database and user.&lt;br /&gt;
&lt;br /&gt;
'''Step 5:''' Install the components and other extensions you would have used before onto your new joomla 1.6+ site. This is done first, in order for none of your old database tables to be overwritten later.&lt;br /&gt;
&lt;br /&gt;
'''Step 6: ''' Convert the .sql file with your 1.5 tables to an sql file compatible with the version you want to upgrade to. That is a very tedious step - you'll have to check the database schema changes between the 1.5 you're upgrading from and the 1.6.+ version you're upgrading to, and adapt the sql file accordingly. '''Note:''' This step could use a more detailed description, if you have ever done a manual Joomla migration, please help and share your experiences and knowledge here!&lt;br /&gt;
&lt;br /&gt;
'''Step 7:''' Import the .sql file from your computer onto your joomla 1.6+ database. It is also possible that some extensions may have the possibility of changes to the sql tables when they upgraded there extension to joomla 1.6+. If this is the case, it is recommended that you ask the developer of that extension for help with knowing what changes to the sql were made.&lt;br /&gt;
&lt;br /&gt;
'''Keep in mind!''' It is possible for settings to be lost based on how the component stored the settings. From personal experience it worked just fine, but you may want to review the settings of each component.&lt;br /&gt;
&lt;br /&gt;
For an easier way to migrate articles, categories/sections, contacts, images, and users, be sure to use [http://extensions.joomla.org/extensions/migration-a-conversion/data-import-a-export/12816 J2XML] for exporting and [http://extensions.joomla.org/extensions/migration-a-conversion/joomla-migration/15807 J2XML Importer] for importing the data.&lt;br /&gt;
&lt;br /&gt;
=Troubleshooting=&lt;br /&gt;
* first check, if you have php5 at least. (use phpinfo() or /usr/bin/php --version)&lt;br /&gt;
* '''jUpgrade cannot download Joomla 1.6 package?''' - When the download fails (timeouts, javascript issues, etc) you can download it manually here: http://anonymous:@joomlacode.org/svn/joomla/development/branches/jupgrade/pack/joomla16.zip and put this file into your ROOT/tmp directory. Then, in the preferences of jUpgrade, you must set 'Skip Download' to 'Yes'. After that, run the upgrade again.&lt;br /&gt;
* '''Are you getting errors with the progress bar in Internet Explorer (Windows XP)?''' - Use Firefox: http://www.mozilla.com/en-US/firefox/&lt;br /&gt;
* Go through the Requirements and Before You Get Started sections above and double check everything!&lt;br /&gt;
* '''Report Bugs:''' http://matware.com.ar/foros/jupgrade.html&lt;br /&gt;
* '''Support:''' http://matware.com.ar/foros/jupgrade.html&lt;br /&gt;
==How You can Contribute &amp;amp; Help==&lt;br /&gt;
Creating an extension as significant as jUpgrade requires an enormous amount of time and effort considering the major structural changes between Joomla 1.5 and 1.6. Add to this the fact that during each release of Joomla 1.6 betas, the extension would have to be modified to work with the new changes between releases, and all of a sudden it's too hard for any one person to complete in a short period of time (especially when you are not being paid).&lt;br /&gt;
With this being said, it's time to step up and make a difference, whether big or small. Have you profited from Joomla in the last year? Are you excited about the future of Joomla? Would you like to contribute back and show your gratitude? Now you can in this project!&lt;br /&gt;
We, as part of the Joomla community, are calling on the entire Joomla community to help out in whatever way you can. You don't have to be a master developer, just go through this tutorial on a test site and if you come across any bugs, report it. If you know how to fix it, create a patch for it. If you are a master developer, step up to the challenge.&lt;br /&gt;
* You can report bugs here: http://matware.com.ar/foros/jupgrade.html&lt;br /&gt;
* You can volunteer and ask questions about volunteering here: http://www.matware.com.ar/forum/projects/jupgrade/volunteer-information.html&lt;br /&gt;
[[Category:Joomla! 1.6]]&lt;br /&gt;
[[Category:Tutorials]]&lt;br /&gt;
[[Category:Migration]]&lt;br /&gt;
[[Category:Installation]]&lt;/div&gt;</summary>
		<author><name>CirTap</name></author>	</entry>

	<entry>
		<id>http://docs.joomla.org/Which_DocType_header_to_use</id>
		<title>Which DocType header to use</title>
		<link rel="alternate" type="text/html" href="http://docs.joomla.org/Which_DocType_header_to_use"/>
				<updated>2011-09-15T10:04:24Z</updated>
		
		<summary type="html">&lt;p&gt;CirTap: whitespace cleanup&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Current thinking is that XHTML 1.0 Transitional should be used for Joomla! templates.&lt;br /&gt;
===Recommended DocTypes===&lt;br /&gt;
{{:Recommended DocTypes|}}&lt;br /&gt;
===References about DocTypes===&lt;br /&gt;
{{:References about DocTypes|}}&lt;br /&gt;
&amp;lt;noinclude&amp;gt;[[Category:Beginners]][[Category:Templates]][[Category:Topics]][[Category:HTML|DocType]][[Category:Template FAQ]]&amp;lt;/noinclude&amp;gt;&lt;/div&gt;</summary>
		<author><name>CirTap</name></author>	</entry>

	<entry>
		<id>http://docs.joomla.org/Recommended_DocTypes</id>
		<title>Recommended DocTypes</title>
		<link rel="alternate" type="text/html" href="http://docs.joomla.org/Recommended_DocTypes"/>
				<updated>2011-09-15T10:04:09Z</updated>
		
		<summary type="html">&lt;p&gt;CirTap: whitespace cleanup&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;List of recommended [http://www.w3.org/QA/2002/04/valid-dtd-list.html DocTypes] for different circumstances:-&lt;br /&gt;
&lt;br /&gt;
* HTML 4.01 Strict: &amp;lt;nowiki&amp;gt;&amp;lt;!DOCTYPE HTML PUBLIC &amp;quot;-//W3C//DTD HTML 4.01//EN&amp;quot; &amp;quot;http://www.w3.org/TR/html4/strict.dtd&amp;quot;&amp;gt;&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
* HTML 4.01 Transitional: &amp;lt;nowiki&amp;gt;&amp;lt;!DOCTYPE HTML PUBLIC &amp;quot;-//W3C//DTD HTML 4.01 Transitional//EN&amp;quot; &amp;quot;http://www.w3.org/TR/html4/loose.dtd&amp;quot;&amp;gt;&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
* HTML 4.01 Frameset: &amp;lt;nowiki&amp;gt;&amp;lt;!DOCTYPE HTML PUBLIC &amp;quot;-//W3C//DTD HTML 4.01 Frameset//EN&amp;quot; &amp;quot;http://www.w3.org/TR/html4/frameset.dtd&amp;quot;&amp;gt;&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
* XHTML 1.0 Strict: &amp;lt;nowiki&amp;gt;&amp;lt;!DOCTYPE html PUBLIC &amp;quot;-//W3C//DTD XHTML 1.0 Strict//EN&amp;quot; &amp;quot;http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd&amp;quot;&amp;gt;&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
* XHTML 1.0 Transitional: &amp;lt;nowiki&amp;gt;&amp;lt;!DOCTYPE html PUBLIC &amp;quot;-//W3C//DTD XHTML 1.0 Transitional//EN&amp;quot; &amp;quot;http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd&amp;quot;&amp;gt;&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
* XHTML 1.0 Frameset: &amp;lt;nowiki&amp;gt;&amp;lt;!DOCTYPE html PUBLIC &amp;quot;-//W3C//DTD XHTML 1.0 Frameset//EN&amp;quot; &amp;quot;http://www.w3.org/TR/xhtml1/DTD/xhtml1-frameset.dtd&amp;quot;&amp;gt;&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
* XHTML 1.1 DTD: &amp;lt;nowiki&amp;gt;&amp;lt;!DOCTYPE html PUBLIC &amp;quot;-//W3C//DTD XHTML 1.1//EN&amp;quot; &amp;quot;http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd&amp;quot;&amp;gt;&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
* HTML5: &amp;lt;!DOCTYPE html&amp;gt;&lt;br /&gt;
&amp;lt;noinclude&amp;gt;[[Category:Reference]][[Category:Templates]][[Category:Itemised lists]]&amp;lt;/noinclude&amp;gt;&lt;/div&gt;</summary>
		<author><name>CirTap</name></author>	</entry>

	<entry>
		<id>http://docs.joomla.org/References_about_DocTypes</id>
		<title>References about DocTypes</title>
		<link rel="alternate" type="text/html" href="http://docs.joomla.org/References_about_DocTypes"/>
				<updated>2011-09-15T10:02:52Z</updated>
		
		<summary type="html">&lt;p&gt;CirTap: added W3C  article, whitespace cleanup&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;References about recommended DocTypes:&lt;br /&gt;
* http://www.w3.org/QA/2002/04/valid-dtd-list.html&lt;br /&gt;
* http://www.w3.org/QA/2002/04/Web-Quality&lt;br /&gt;
* http://www.alistapart.com/stories/doctype&lt;br /&gt;
* http://htmlhelp.com/tools/validator/doctype.html&lt;br /&gt;
* http://vivalaweb.info/blog/musing/2005/05/14/choosing-the-right-doctype-a-straight-forward-guide/&lt;br /&gt;
* http://hsivonen.iki.fi/doctype/&lt;br /&gt;
&amp;lt;noinclude&amp;gt;[[Category:Reference]][[Category:Templates]][[Category:Itemised lists]]&amp;lt;/noinclude&amp;gt;&lt;/div&gt;</summary>
		<author><name>CirTap</name></author>	</entry>

	<entry>
		<id>http://docs.joomla.org/Recommended_DocTypes</id>
		<title>Recommended DocTypes</title>
		<link rel="alternate" type="text/html" href="http://docs.joomla.org/Recommended_DocTypes"/>
				<updated>2011-09-15T10:00:34Z</updated>
		
		<summary type="html">&lt;p&gt;CirTap: added nowiki tags to prevent parsing od DTD urls, link to W3C article with DTD sources&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;List of recommended [http://www.w3.org/QA/2002/04/valid-dtd-list.html DocTypes] for different circumstances:-&lt;br /&gt;
&lt;br /&gt;
* HTML 4.01 Strict: &amp;lt;nowiki&amp;gt;&amp;lt;!DOCTYPE HTML PUBLIC &amp;quot;-//W3C//DTD HTML 4.01//EN&amp;quot; &amp;quot;http://www.w3.org/TR/html4/strict.dtd&amp;quot;&amp;gt;&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
* HTML 4.01 Transitional: &amp;lt;nowiki&amp;gt;&amp;lt;!DOCTYPE HTML PUBLIC &amp;quot;-//W3C//DTD HTML 4.01 Transitional//EN&amp;quot; &amp;quot;http://www.w3.org/TR/html4/loose.dtd&amp;quot;&amp;gt;&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
* HTML 4.01 Frameset: &amp;lt;nowiki&amp;gt;&amp;lt;!DOCTYPE HTML PUBLIC &amp;quot;-//W3C//DTD HTML 4.01 Frameset//EN&amp;quot; &amp;quot;http://www.w3.org/TR/html4/frameset.dtd&amp;quot;&amp;gt;&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
* XHTML 1.0 Strict: &amp;lt;nowiki&amp;gt;&amp;lt;!DOCTYPE html PUBLIC &amp;quot;-//W3C//DTD XHTML 1.0 Strict//EN&amp;quot; &amp;quot;http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd&amp;quot;&amp;gt;&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
* XHTML 1.0 Transitional: &amp;lt;nowiki&amp;gt;&amp;lt;!DOCTYPE html PUBLIC &amp;quot;-//W3C//DTD XHTML 1.0 Transitional//EN&amp;quot; &amp;quot;http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd&amp;quot;&amp;gt;&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
* XHTML 1.0 Frameset: &amp;lt;nowiki&amp;gt;&amp;lt;!DOCTYPE html PUBLIC &amp;quot;-//W3C//DTD XHTML 1.0 Frameset//EN&amp;quot; &amp;quot;http://www.w3.org/TR/xhtml1/DTD/xhtml1-frameset.dtd&amp;quot;&amp;gt;&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
* XHTML 1.1 DTD: &amp;lt;nowiki&amp;gt;&amp;lt;!DOCTYPE html PUBLIC &amp;quot;-//W3C//DTD XHTML 1.1//EN&amp;quot; &amp;quot;http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd&amp;quot;&amp;gt;&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
* HTML5: &amp;lt;!DOCTYPE html&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;noinclude&amp;gt;[[Category:Reference]]&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
&amp;lt;noinclude&amp;gt;[[Category:Templates]]&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
&amp;lt;noinclude&amp;gt;[[Category:Itemised lists]]&amp;lt;/noinclude&amp;gt;&lt;/div&gt;</summary>
		<author><name>CirTap</name></author>	</entry>

	<entry>
		<id>http://docs.joomla.org/Upgrade_1.6.5_to_1.6.6</id>
		<title>Upgrade 1.6.5 to 1.6.6</title>
		<link rel="alternate" type="text/html" href="http://docs.joomla.org/Upgrade_1.6.5_to_1.6.6"/>
				<updated>2011-08-02T11:31:24Z</updated>
		
		<summary type="html">&lt;p&gt;CirTap: removed SID from forum link&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Joomla! 1.6.6 was released yesterday (July 26, 2011) while Joomla! 1.7.0 was released a week prior (July 19th, 2011). Joomla 1.6.6 is a security release and is intended only for those users who are unable to use version 1.7.0.  Most users should update to 1.7.0 unless there are specific reasons why they cannot use 1.7.0 at this time. Version 1.6 will reach end of life on 19 August 2011. All users of version 1.6 should update to version 1.7.0 before that time. The update process is very simple, and complete instructions are available here. &lt;br /&gt;
&lt;br /&gt;
At the time of this writing (July 27, 2011), however, the automated backend Joomla installer only gives version Joomla! 1.7.0 as a possible upgrade route, so this tutorial will show how to you how to upgrade manually to 1.6.6 from any 1.6 version if there are specific reasons why 1.7.0 at this time can't be used. Alternatively you can also use a Joomla! extension to automate the process of loading version updates. See [http://extensions.joomla.org/extensions/access-a-security/site-security/site-protection/14087 Admin Tools for Joomla!] for more information. &lt;br /&gt;
&lt;br /&gt;
[http://www.joomla.org/announcements/release-news/5383-joomla-166-released.html Review the release notes for the new version.]&lt;br /&gt;
&lt;br /&gt;
{{upgrade-intro}}&lt;br /&gt;
&lt;br /&gt;
==Step 1: Download the upgrade file==&lt;br /&gt;
&lt;br /&gt;
To download 1.6.6:&lt;br /&gt;
&lt;br /&gt;
* Proceed to the [http://joomlacode.org/gf/project/joomla/frs/?action=FrsReleaseBrowse&amp;amp;frs_package_id=6007 Joomla 1.6.6 download area].&lt;br /&gt;
* Download Joomla_1.6.5_to_1.6.6-Stable-Patch_Package.zip if you're using 1.6.6 otherwise download Joomla_1.6.0_to_1.6.6-Stable-Patch_Package.zip for any other 1.6.x version.&lt;br /&gt;
&lt;br /&gt;
If you have questions about these instructions or want to use tar.gz or tar.bz2 instead (e.g. if the file is taking an extremely long time to download), read the ''Additional Information'' below this table.&lt;br /&gt;
&lt;br /&gt;
'''Additional information:'''&lt;br /&gt;
&lt;br /&gt;
{{Ambox|image=notice|text=[[Template:patch|What is a patch?]]|style=width:400px}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{Ambox|image=notice|text=[[Unpacking a package file|Which package format should I use?]]|style=width:400px}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Step 2: Backup your site==&lt;br /&gt;
Before you actually upgrade, you really should make a backup of your site. Backup your existing Joomla site files and store all the files and database in case something gets messed up, you wont have any problem reverting back.&lt;br /&gt;
&lt;br /&gt;
All upgrades should be first tested on a copy of your site before being applied to a live site.&lt;br /&gt;
&lt;br /&gt;
==Step 3: Install the upgrade file==&lt;br /&gt;
{{installing a package file}}&lt;br /&gt;
&lt;br /&gt;
==Step 4: Check your live site to make sure it is working correctly==&lt;br /&gt;
Don't assume that the upgrade will work flawlessly just because the test upgrade worked.  Check to make sure that nothing untoward has happened.  It could be that differences between the live site and test site platforms will bring out a problem that you did not notice during testing.  If you find a problem and it cannot be resolved quickly you might have to rollback the upgrade using the backup copy you created in step 2.&lt;br /&gt;
&lt;br /&gt;
Hopefully all will be well and you can relax.  If you have any questions before, during, or after the upgrade then please ask them on the [http://forum.joomla.org/viewforum.php?f=625 Joomla! 1.7 Migrating and Upgrading Forum].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Upgrading]]&lt;/div&gt;</summary>
		<author><name>CirTap</name></author>	</entry>

	<entry>
		<id>http://docs.joomla.org/Archived_vel</id>
		<title>Archived vel</title>
		<link rel="alternate" type="text/html" href="http://docs.joomla.org/Archived_vel"/>
				<updated>2011-07-15T13:31:27Z</updated>
		
		<summary type="html">&lt;p&gt;CirTap: Reverted edits by CirTap (talk) to last revision by Mandville&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{RightTOC}}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  '''Extension'''&lt;br /&gt;
! class=&amp;quot;unsortable&amp;quot;| '''Details'''&lt;br /&gt;
!  '''Reference Link'''&lt;br /&gt;
!  '''Extension Update Link'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''com_ajaxchat'''&lt;br /&gt;
|  Summary: PHP remote file inclusion vulnerability in Fiji Web Design Ajax Chat ('''com_ajaxchat''') component 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[mosConfig_absolute_path] parameter to tests/ajcuser.php.New version release December 22,2009&lt;br /&gt;
Published: october 28 2009&lt;br /&gt;
|  [[NIST:CVE-2009-3822|CVE-2009-3822]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | [http://extensions.joomla.org/extensions/communication/chat/10767 update v 1.1]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''com_booklibrary'''&lt;br /&gt;
|  PHP remote file inclusion vulnerability in doc/releasenote.php in the BookLibrary ('''com_booklibrary''') component 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter, a different vector than [[NIST:CVE-2009-2637|CVE-2009-2637]]. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 10/28/2009&lt;br /&gt;
CVSS Severity: 7.5 (HIGH)&lt;br /&gt;
|  [[NIST:CVE-2009-3817|CVE-2009-3817]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''[http://ordasoft.com/Download/Joomla1.0-extensions/Joomla1.0-components/View-category.html developer site updates]'''&lt;br /&gt;
|-&lt;br /&gt;
|   style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''com_foobla_suggestions'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the foobla Suggestions ('''com_foobla_suggestions''') component 1.5.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the idea_id parameter to index.php.&lt;br /&gt;
Published: 10/11/2009&lt;br /&gt;
CVSS Severity: 7.5 (HIGH)&lt;br /&gt;
|  [[NIST:CVE-2009-3669|CVE-2009-3669]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | [http://foobla.com/news/latest/fixed-foobla-suggestions-for-joomla-idea_id-sql-injection-vulnerability.html developer reported upgrade]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_djcatalog'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the DJ-Catalog ('''com_djcatalog''') component for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a showItem action and (2) cid parameter in a show action to index.php.&lt;br /&gt;
Published: 10/11/2009&lt;br /&gt;
CVSS Severity: 6.8 (MEDIUM)&lt;br /&gt;
|  [[NIST:CVE-2009-3661|CVE-2009-3661]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''com_cbresumebuilder'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the JoomlaCache CB Resume Builder (''''''com_cbresumebuilder''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the group_id parameter in a group_members action to index.php.&lt;br /&gt;
Published: 10/09/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3645|CVE-2009-3645]] &lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |'''[http://www.joomlacache.com/commercial-extensions/security-update.html Developer Update]'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  |  '''com_soundset'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Soundset ('''com_soundset''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter to index.php.&lt;br /&gt;
Published: 10/09/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3644|CVE-2009-3644]]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  |  '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  |'''com_sportfusion'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Kinfusion SportFusion ('''com_sportfusion''') component 0.2.2 through 0.2.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid[0] parameter in a teamdetail action to index.php.&lt;br /&gt;
Published: 09/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3491|CVE-2009-3491]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  |'''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_icrmbasic'''&lt;br /&gt;
|  Summary: A certain interface in the iCRM Basic ('''com_icrmbasic''') component 1.4.2.31 for Joomla! does not require administrative authentication, which has unspecified impact and remote attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 09/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3481|CVE-2009-3481]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_mytube'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the MyRemote Video Gallery ('''com_mytube''') component 1.0 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter in a videos action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3446|CVE-2009-3446]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_fastball'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Fastball ('''com_fastball''') component 1.1.0 through 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the league parameter to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3443|CVE-2009-3443]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | [http://www.fastballproductions.com   latest version] 1.2.1 &lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_facebook'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the JoomlaFacebook ('''com_facebook''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a student action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3438|CVE-2009-3438]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_tupinambis'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Tupinambis ('''com_tupinambis''') component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the proyecto parameter in a verproyecto action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3434|CVE-2009-3434]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''com_idoblog'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the IDoBlog ('''com_idoblog''') component 1.1 build 30 for Joomla! allows remote attackers to execute arbitrary SQL commands via the userid parameter in a profile action to index.php, a different vector than [[NIST:CVE-2008-2627|CVE-2008-2627]].&lt;br /&gt;
Published: 09/25/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3417|CVE-2009-3417]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot; |'''[http://idojoomla.com/download.html/ '''New Version v 1.1''' (build 32)]'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_hbssearch'''&lt;br /&gt;
|  Summary: Cross-site scripting ('''XSS''') vulnerability in the Hotel Booking Reservation System ('''aka HBS or com_hbssearch''') component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the adult parameter in a showhoteldetails action to index.php.&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 4.3 ('''MEDIUM''')&lt;br /&gt;
|  [[NIST:CVE-2009-3368|CVE-2009-3368]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_hbssearch'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System ('''aka HBS or com_hbssearch''') component for Joomla! allow remote attackers to execute arbitrary SQL commands via the ('''1''') h_id, ('''2''') id, and ('''3''') rid parameters to longDesc.php, and the h_id parameter to ('''4''') detail.php, ('''5''') detail1.php, ('''6''') detail2.php, ('''7''') detail3.php, ('''8''') detail4.php, ('''9''') detail5.php, ('''10''') detail6.php, ('''11''') detail7.php, and ('''12''') detail8.php, different vectors than [[NIST:CVE-2008-5865|CVE-2008-5865]], [[NIST:CVE-2008-5874|CVE-2008-5874]], and [[NIST:CVE-2008-5875|CVE-2008-5875]].&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3357|CVE-2009-3357]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''com_alphauserpoints'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in frontend/assets/ajax/checkusername.php in the AlphaUserPoints ('''com_alphauserpoints''') component 1.5.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the username2points parameter.&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3342|CVE-2009-3342]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |'''[http://www.alphaplug.com/index.php/news/142-alphauserpoints-153-released.html 1.5.3]'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''TurtuShout'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the TurtuShout component 0.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Name field.&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3335|CVE-2009-3335]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jinc'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Lhacky! Extensions Cave Joomla! Integrated Newsletters Component ('''aka JINC or com_jinc''') component 0.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a messages action to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3334|CVE-2009-3334]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''com_jbudgetsmagic'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the JBudgetsMagic ('''com_jbudgetsmagic''') component 0.3.2 through 0.4.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the bid parameter in a mybudget action to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3332|CVE-2009-3332]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | '''[http://sopinet.com/jbudgetsmagic/index.php?option=com_remository&amp;amp;Itemid=5&amp;amp;lang=en Update to 0.4.1]'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_surveymanager'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Focusplus Developments Survey Manager ('''com_surveymanager''') component 1.5.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the stype parameter in an editsurvey action to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3325|CVE-2009-3325]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_album'''&lt;br /&gt;
|  Summary: Directory traversal vulnerability in the Roland Breedveld Album ('''com_album''') component 1.14 for Joomla! allows remote attackers to access arbitrary directories and have unspecified other impact via a .. ('''dot dot''') in the target parameter to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3318|CVE-2009-3318]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;   | '''com_jreservation'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the [http://extensions.joomla.org/extensions/vertical-markets/booking-a-reservation/9798 JReservation] ('''com_jreservation''') component 1.0 and 1.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a propertycpanel action to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3316|CVE-2009-3316]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot; |  [http://www.jforjoomla.com Updated 28th] Jan fixed 13th Nov&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''IXXO Cart Standalone'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in IXXO Cart Standalone before 3.9.6.1, and the IXXO Cart component for Joomla! 1.0.x, allows remote attackers to execute arbitrary SQL commands via the parent parameter.&lt;br /&gt;
Published: 09/16/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3215|CVE-2009-3215]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_digifolio'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the DigiFolio ('''com_digifolio''') component 1.52 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a project action to index.php.&lt;br /&gt;
Published: 09/15/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3193|CVE-2009-3193]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_aclassf'''&lt;br /&gt;
|  Summary: Cross-site scripting ('''XSS''') vulnerability in '''gmap.php''' in the Almond Classifieds ('''com_aclassf''') component 7.5 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the addr parameter.&lt;br /&gt;
Published: 09/10/2009&lt;br /&gt;
CVSS Severity: 4.3 ('''MEDIUM''')&lt;br /&gt;
|  [[NIST:CVE-2009-3155|CVE-2009-3155]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;   | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''com_aclassf'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Almond Classifieds ('''com_aclassf''') component 7.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the replid parameter in a manw_repl add_form action to index.php, a different vector than [[NIST:CVE-2009-2567|CVE-2009-2567]].&lt;br /&gt;
Published: 09/10/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3154|CVE-2009-3154]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | [http://www.almondsoft.com/alcl.html Developer latest component]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jabode'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in Jabode horoscope extension ('''com_jabode''') for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a sign task to index.php.&lt;br /&gt;
Published: 09/08/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
&lt;br /&gt;
|  [[NIST:CVE-2008-7169|CVE-2008-7169]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_gameserver'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Game Server ('''com_gameserver''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a gamepanel action to index.php.&lt;br /&gt;
Published: 09/03/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3063|CVE-2009-3063]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_artportal'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Artetics.com Art Portal ('''com_artportal''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the portalid parameter to index.php.&lt;br /&gt;
Published: 09/03/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3054|CVE-2009-3054]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:#cef2e0; color:black&amp;quot; | '''com_agora'''&lt;br /&gt;
|  Summary: Directory traversal vulnerability in the Agora ('''com_agora''') component 3.0.0b for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the action parameter to the avatars page, reachable through index.php.&lt;br /&gt;
Published: 09/03/2009&lt;br /&gt;
CVSS Severity: 6.8 ('''MEDIUM''')&lt;br /&gt;
|  [[NIST:CVE-2009-3053|CVE-2009-3053]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot; |'''[http://jvitals.com/index.php?option=com_rokdownloads&amp;amp;view=file&amp;amp;Itemid=108&amp;amp;id=282:agora-3-0 3.0.7]'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_simpleshop'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Simple Shop Galore ('''com_simpleshop''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the section parameter in a section action to index.php, a different vulnerability than [[NIST:CVE-2008-2568|CVE-2008-2568]]. NOTE: this issue was disclosed by an unreliable researcher, so the details might be incorrect.&lt;br /&gt;
Published: 08/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-7033|CVE-2008-7033]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_groups'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Permis ('''com_groups''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a list action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 08/17/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-2789|CVE-2009-2789]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:#cef2e0; color:black&amp;quot; | '''com_content'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the content component ('''com_content''') 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a blogcategory action to index.php.&lt;br /&gt;
Published: 08/10/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6923|CVE-2008-6923]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |'''[http://developer.joomla.org/security/news/305-20091103-core-front-end-editor-issue-.html Resolution]'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Live Chat ('''com_livechat''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the last parameter to getChatRoom.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6883|CVE-2008-6883]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: Live Chat ('''com_livechat''') component 1.0 for Joomla! allows remote attackers to use the xmlhttp.php script as an open HTTP proxy to hide network scanning activities or scan internal networks via a GET request with a full URL in the query string.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6882|CVE-2008-6882]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the Live Chat ('''com_livechat''') component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the last parameter to ('''1''') getChat.php, ('''2''') getChatRoom.php, and ('''3''') getSavedChatRooms.php.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6881|CVE-2008-6881]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''JUMI'''&lt;br /&gt;
|  There is a backdoor in JUMI that installs itself when JUMI is installed on your web site. It sends your credentials to a website, and sets up a back door for remote code execution.&lt;br /&gt;
Please remove JUMI2.0.5 immediately. &lt;br /&gt;
It will be simple enough to remove the compromised code from this download, but you need to do &lt;br /&gt;
a full security audit on your site as well as you have been compromised. Added November 2009&lt;br /&gt;
|  [http://code.google.com/p/jumi/updates/list Report]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |[http://code.google.com/p/jumi/updates/list Jumi Update]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''com_photoblog'''&lt;br /&gt;
|  Input Validation Error Added November 2009&lt;br /&gt;
|  [http://www.securityfocus.com/bid/36809/ 36809]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |[http://webguerilla.net/downloads/3-components-for-joomla-1 webguerilla Photoblog alpha 3b]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jshop'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the JShop ('''com_jshop''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a product action to index.php.&lt;br /&gt;
Published: 11/02/2009&lt;br /&gt;
CVSS Severity: 7.5 '''(HIGH)''' &lt;br /&gt;
|  [[NIST:CVE-2009-3835|CVE-2009-3835]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot; |'''BF Survey Pro'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the '''BF Survey Pro''' v1.2.5 or lower  (fixed in version 1.2.6). '''BF Survey Basic v1.0''' (fixed in version 1.1). '''BF Quiz v1.1.1''' (fixed in version 1.2 or greater) Added November 2009&lt;br /&gt;
|  [http://www.tamlyncreative.com.au/software/forum/index.php?topic=357.0 tamlyncreative.com.au]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |[http://www.tamlyncreative.com.au/software/forum/index.php?topic=357.0 update]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot; |'''Joo!BB 0.9.1 '''&lt;br /&gt;
|  Summary: Persistent XSS/MySQL Injection vulnerabilities in Joo!BB 0.9.1 Added November 2009&lt;br /&gt;
|  [http://www.joobb.org/community/board/topic/700-MultipleXSSSQLInjectionVulnerabilities.html joob.org]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot; |[http://www.joobb.org/downloads/components.html update]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''sh404sef '''&lt;br /&gt;
|  Summary: sh404sef URI XSS Vulnerability  Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/sh404sef-uri-xss-vulnerability.html jeffchannell.com]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |[http://extensions.siliana.com/en/2009060876/sh404SEF-and-url-rewriting/Interim-release-of-sh404sef-for-Joomla-1.5.x.html update]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''AWD Wall 1.5''' &lt;br /&gt;
|  Summary '''AWD Wall 1.5''' Blind SQL Injection Vulnerability.The Joomla component AWD Wall 1.5 suffers from an SQL Injection vulnerability in its handling of the 'cbuser' parameter.Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/awd-wall-15-blind-sql-injection-vulnerability.html Notice]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | '''[http://www.awdsolution.com/template_demo/testsite/index.php?option=com_content&amp;amp;view=article&amp;amp;id=48&amp;amp;Itemid=72 developer update]'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''EasyBook 2.0.0rc4'''&lt;br /&gt;
|  Summary: The Joomla component '''EasyBook 2.0.0rc4''' suffers from multiple persistent XSS vulnerabilities. One seems fairly critical, while the others would take some incredible creativity to actively exploit. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/easybook-200rc4-multiple-xss-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''F!BB 1.5.96''' &lt;br /&gt;
|  Summary: The Joomla component '''F!BB 1.5.96 RC''' suffers from multiple persistent XSS vulnerabilities, as well SQL Injection in its user search feature. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/fbb-1596-rc-multiple-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Testimonial Ku 2.0 Admin Panel'''&lt;br /&gt;
|  Summary: The Joomla component '''Testimonial Ku 2.0''' is vulnerable to persistent XSS in the administrator panel. A malicious user can submit a testimonial containing &amp;lt;script&amp;gt; tags with absolutely no quotes and inject that script into the administrator panel through any of the available inputs except &amp;quot;email&amp;quot;. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/testimonial-ku-20-admin-panel-persistent-xss.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''MS Comment 0.8.0b'''&lt;br /&gt;
|  Summary '''MS Comment 0.8.0b for Joomla''', a commenting plugin, suffers from an multiple vulnerabilities. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/ms-comment-080b-multiple-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |  '''!JoomlaComment 4.0 beta1'''&lt;br /&gt;
|  Summary: '''!JoomlaComment 4.0 beta1''', a commenting plugin, suffers from multiple XSS vulnerabilities. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/joomlacomment-40-beta1-multiple-xss-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | '''  [http://compojoom.com/blog/8-news/121-joomlacomment-40-rc1-released Developer Notice 4.0 rc1]''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''WebAmoeba Ticket System 3.0.0'''&lt;br /&gt;
|  Summary:  '''WebAmoeba Ticket System 3.0.0''', a Joomla help desk component. The vulnerability is with the BBCode library used to parse BBCode tags, as it does not strip javascript: urls from [url] tags. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/webamoeba-ticket-system-300-bbcode-xss.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |'''Kunena 1.5.x''' &lt;br /&gt;
|Summary: This is an important security release and users are urged to update immediately. Five security issues and an Internet Explorer 8 table bug have been resolved in this release. This release also contains many other important bug fixes. Added 18 November 2009&lt;br /&gt;
|[http://www.kunena.com/blog/19-developer-blog/51-kunena-157-security-release-now-available Advisory]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |[http://www.kunena.com/blog/19-developer-blog/52-kunena-158-service-release-now-available Latest 1.5.8 Version]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_siirler'''&lt;br /&gt;
|  Summary:  SQL injection vulnerability in the '''Q-Proje Siirler Bileseni (com_siirler)''' component 1.2 RC for Joomla! allows remote attackers to execute arbitrary SQL commands via the sid parameter in an sdetay action to index.php. Added 18 November 2009&lt;br /&gt;
|  [[NIST:CVE-2009-3972 | CVE-2009-3972]]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''jTips (com_jtips)'''&lt;br /&gt;
|SUmmary:SQL injection vulnerability in the '''jTips (com_jtips)''' component 1.0.7 and 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the season parameter in a ladder action to index.php. Added 18 November 2009&lt;br /&gt;
| [[NIST:CVE-2009-3971 |CVE-2009-3971]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''NinjaMonials'''&lt;br /&gt;
| Summary: SQL injection vulnerability in the '''NinjaMonials (com_ninjacentral)''' component 1.1.0 for '''Joomla 1.0.x''' ! allows remote attackers to execute arbitrary SQL commands via the testimID parameter in a display action to index.php. Added 18 November 2009&lt;br /&gt;
|  [[NIST:CVE-2009-3964 | CVE-2009-3964]]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |'''  [http://ninjaforge.com/index.php?option=com_ninjacentral&amp;amp;page=show_package&amp;amp;id=14&amp;amp;Itemid=235 developer patch Ver 1.2]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   | '''webee 1.1.1 &amp;amp;1.2'''&lt;br /&gt;
|Summary: '''webee 1.1.1,''' a Joomla commenting plugin, suffers from multiple vulnerabilities. '''webee has been updated to 1.2''' as of 12 November 2009 and''' still suffers''' from SQL Injection. XSS was not tested in 1.2. Added 19 November 2009&lt;br /&gt;
| [http://jeffchannell.com/Joomla/webee-111-multiple-vulnerabilities.html jeffchannell.com]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | ''' [http://extensions.joomla.org/extensions/contacts-and-feedback/articles-comments/10155 developer update ver2.0]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''iF Portfolio Nexus'''&lt;br /&gt;
|Summary: The '''iF Portfolio Nexus component for Joomla!''' is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements using the id parameter, which could allow the attacker to view, add, modify or delete information in the back-end database. Nov 18, 2009&lt;br /&gt;
|[http://secunia.com/advisories/37408/ secunia.com 37408/]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; |[http://www.inertialfate.za.net/help/forums/topic?id=10&amp;amp;p=3#p172 iF Portfolio Nexus v1.1.1 released]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''JoomClip'''&lt;br /&gt;
|Summary: The '''JoomClip component for Joomla!''' is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements to the index.php script using the cat parameter, which could allow the attacker to view, add, modify or delete information in the back-end database.  Nov 18, 2009&lt;br /&gt;
|[http://secunia.com/advisories/37400/ secunia.com 37400/]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''Joomla XML'''&lt;br /&gt;
|Summary: Joomla! before 1.5.15 allows remote attackers to read an extension's XML file, and thereby obtain the extension's version number, via a direct request.&lt;br /&gt;
Published: 11/16/2009&lt;br /&gt;
|[[NIST:CVE-2009-3946 | CVE-2009-3946]] &lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |'''[http://developer.joomla.org/security/news/306-20091103-core-xml-file-read-issue.html Resolution]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Mygallery Remote SQL Injection Vulnerability''' &lt;br /&gt;
|Summary: Joomla Component mygallery ( farbinform_krell) Remote SQL Injection Vulnerability Added 27 Nov 2009 {{JVer|1.5}} NB: This could be an error in our database as the only one we could find was for wordpress.If anyone know of one for joomla please let us know..(poss joomlicious.com CM)&lt;br /&gt;
|[http://www.exploit-db.com] &lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Extreme Google Calendar'''&lt;br /&gt;
|Summary: '''com_gcalendar 1.1.2''' (gcid) Remote SQL Injection Vulnerability&lt;br /&gt;
Remote SQL Injection were identified in Google Calendar Component [http://extensions.joomla.org/extensions/calendars-a-events/calendars/4188 Extension Link] Added 27 Nov 2009 &lt;br /&gt;
|[http://www.exploit-db.com reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''LyftenBloggie'''&lt;br /&gt;
| Summary: [http://www.lyften.com/products/lyftenbloggie.html LyftenBloggie] Component &amp;quot;author&amp;quot; SQL Injection Vulnerability LyftenBloggie 1.x Added 27 Nov 2009&lt;br /&gt;
|[http://secunia.com/advisories/product/28005/	 SA37499]&lt;br /&gt;
| [http://jeffchannell.com/Joomla/lyften-bloggie-sql-injection-fix.html Un official fix]. Developer fix not release at 30 Nov 09 ''' [http://www.lyften.com/products/lyftenbloggie/extensions/download/id-20.html 1.0.4a (last update on Dec 28, 2009)]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''Sermon speaker'''&lt;br /&gt;
|Summary: [http://joomlacode.org/gf/project/sermon_speaker sermon speaker] sql vulnerability and password reset vulnerability version 3.2 and below&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |[http://joomlacode.org/gf/project/sermon_speaker/forum/?action=ForumBrowse&amp;amp;forum_id=7897&amp;amp;_forum_action=ForumMessageBrowse&amp;amp;thread_id=15219 Developer fix] 30 Nov 2009&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | [http://joomlacode.org/gf/project/musicgallery/ MusicGallery]&lt;br /&gt;
|Summary: [http://joomlacode.org/gf/project/musicgallery/ Component MusicGallery] SQL Injection Vulnerability 30 November {{JVer|1.5}}&lt;br /&gt;
|[[NIST:CVE-2009-4217 | CVE-2009-4217]]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; | [http://joomlacode.org/gf/project/musicgallery/ developer]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== December 2009 Compiled Reports ==&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  '''Extension'''&lt;br /&gt;
! class=&amp;quot;unsortable&amp;quot;| '''Details'''&lt;br /&gt;
!  '''Reference Link'''&lt;br /&gt;
!  '''Extension Update Link'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Omilen Photo Gallery'''&lt;br /&gt;
|Summary: Directory traversal vulnerability in the [http://extensions.joomla.org/extensions/photos-&amp;amp;-images/photo-flash-gallery/6373/details Omilen Photo Gallery] (com_omphotogallery) component Beta 0.5 for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the controller parameter to index.php.&lt;br /&gt;
Published: 12/04/2009&lt;br /&gt;
|[[NIST:CVE-2009-4202 | CVE-2009-4202]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Seminar'''&lt;br /&gt;
|Summary: SQL injection vulnerability in the [http://seminar.vollmar.ws/ Seminar] (com_seminar) component 1.28 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a View_seminar action to index.php.&lt;br /&gt;
Published: 12/04/2009&lt;br /&gt;
|[[NIST:CVE-2009-4200 | CVE-2009-4200]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''Mambo Resident'''&lt;br /&gt;
|Summary: Multiple SQL injection vulnerabilities in the Mambo Resident (aka Mos Res or com_mosres) component 1.0f for Mambo and Joomla!, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) property_uid parameter in a viewproperty action to index.php and the (2) regID parameter in a showregion action to index.php. Mambo Resident component for v4.5.2 '''may only be for 1.0.xx versions of J!'''&lt;br /&gt;
Published: 12/04/2009&lt;br /&gt;
|[[NIST:CVE-2009-4199 | CVE-2009-4199]]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; |[http://www.jomres.net/ Replacement Extension 08 dec 09]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''ProofReader''' &lt;br /&gt;
|Summary: Multiple cross-site scripting (XSS) vulnerabilities in index.php in the ProofReader (com_proofreader) component 1.0 RC9 and earlier for Joomla! allow remote attackers to inject arbitrary web script or HTML via the URI, which is not properly handled in (1) 404 or (2) error pages. Published: 12/02/2009 CVSS Severity: 4.3 (MEDIUM)&lt;br /&gt;
| [[NIST:CVE-2009-4157 | CVE-2009-4157]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''Laoneo Google Calendar GCalendar'''&lt;br /&gt;
|Summary: SQL injection vulnerability in the [http://g4j.laoneo.net/content/extensions/download/cat_view/20-joomla-15x/21-gcalendar.html Google Calendar GCalendar] (com_gcalendar) component 1.1.2, 2.1.4, and possibly earlier versions for Joomla! allows remote attackers to execute arbitrary SQL commands via the gcid parameter. NOTE: some of these details are obtained from third party information. Published: 11/29/2009 CVSS Severity: 7.5 (HIGH) Note: There is already a listing for GCalendar 1.1.2&lt;br /&gt;
|[[NIST:CVE-2009-4099 | CVE-2009-4099]]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;   | [http://g4j.laoneo.net/content/extensions/download/doc_details/28-gcalendar-suite-215.html Latest version GCalendar Suite 2.1.5]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''D4J eZine'''&lt;br /&gt;
|Summary: PHP remote file inclusion vulnerability in class/php/d4m_ajax_pagenav.php in the D4J eZine (com_ezine) component 2.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS mosConfig_absolute_path parameter. Published: 11/29/2009 CVSS Severity: 7.5 (HIGH)&lt;br /&gt;
|[[NIST:CVE-2009-4094 | CVE-2009-4094]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''Quick News'''&lt;br /&gt;
| Summary: The Joomla [http://joomlacode.org/gf/project/quicknews/ Quick News component] suffers from a remote SQL injection vulnerability. added 1st Dec 09&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''Joaktree component'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/miscellaneous/genealogy/9842 Joaktree] Vulnerability : SQL injection/ added 1st Dec 09&lt;br /&gt;
|[http://securityreason.com/exploitalert/7508 7508]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | '''  [http://naastniels.nl/index.php/en/joaktree/downloads version 1.1 update]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''mojoblog'''&lt;br /&gt;
|Summary [http://www.joomlify.com/files/mojoblog/ MojoBlog] Multiple Remote File Include Vulnerability added 1st Dec 09 {{JVer|1.5}}&lt;br /&gt;
|[http://securityreason.com/exploitalert/7509 7509]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''YJ Whois''' &lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/external-contents/domain-search/5774 YJ Whois] '''Low security risk''',and fixesMalicious users may inject JavaScript, VBScript, ActiveX, HTML or Flash into a vulnerable application to fool a user in order to gather data from them. An attacker can steal the session cookie and take over the account. Files affected is , modules/mod_yj_whois.php added 3 December 09&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; |[http://www.youjoomla.com/xss-security-patch-for-yj-whois.html Developer Notice and fix 03 dec 09]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; | '''yt_color YOOOtheme'''&lt;br /&gt;
|Summary: [http://www.yootheme.com/ YT_color yootheme] Malicious users may inject JavaScript, VBScript, ActiveX, HTML or Flash into a vulnerable application to fool a user in order to gather data from them. An attacker can steal the session cookie and take over the account. added 5 dec 09&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | '''  [http://www.yootheme.com/member-area/downloads/item/templates-15/xss-and-php-53-patches All members without an active membership can download the template patches here].'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''TP Whois''' &lt;br /&gt;
|summary: [http://www.templateplazza.com/view-details/tpwhois/183-component-tp-whois-for-joomla-1.5.x.html TP Whois ] Malicious users may inject JavaScript, VBScript, ActiveX, HTML or Flash into a vulnerable application to fool a user in order to gather data from them. An attacker can steal the session cookie and take over the account. Added 3 december {{JVer|1.5}}&lt;br /&gt;
|[http://www.exploit-db.com Refrence]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''com_job'''&lt;br /&gt;
|Summary: Component com_job ( showMoreUse) SQL injection vulnerability  Added 9th Dec&lt;br /&gt;
|[http://xforce.iss.net/xforce/xfdb/54626 Reference]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |  '''JQuarks''' &lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/contacts-and-feedback/quiz-a-surveys/10590 JQuarks] SQL injection vulnerability {{JVer|1.5}} added 8th dec 09&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | [http://www.iptechinside.com/labs/projects/list_files/jquarks Developer Update ]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''Mamboleto Component 2.0 RC3'''&lt;br /&gt;
|Summary: [http://www.fernandosoares.com.br/index.php?option=com_docman&amp;amp;task=cat_view&amp;amp;gid=28&amp;amp;Itemid=28 Mamboleto Component 2.0 RC3]SQL injection vulnerability {{JVer|1.5}} added 12 December&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |  ''' JS JOBS'''&lt;br /&gt;
|Summary [http://www.joomshark.com/index.php?option=com_content&amp;amp;view=article&amp;amp;id=4&amp;amp;Itemid=8 JS JOBS] Joomla Component com_jsjobs 1.0.5.6 SQL Injection Vulnerabilities {{JVer|1.5}} added 12 December&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | '''  [http://www.joomsky.com/index.php?option=com_rokdownloads&amp;amp;view=folder&amp;amp;Itemid=3&amp;amp;id=2:components Developer update 1.0.5.7]''' &lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |  '''corePHP JPhoto'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/photos-a-images/photo-gallery/10365 'corePHP' JPhoto]SQL injection vulnerability {{JVer|1.5}} added 12 December&lt;br /&gt;
|[http://secunia.com/advisories/37676/ Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | '''  [http://www.corephp.com/blog/uber-fast-jphoto-security-release/ Developer Upgrade]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;    | '''com_virtuemart'''&lt;br /&gt;
|Summary: &amp;quot;com_virtuemart&amp;quot; http://virtuemart.net/  '''Version : 1.0''' Vulnerability : SQL injection added Date : 07- dec -09 {{JVer|1.5}}&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |[http://virtuemart.net/ latest version]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | ''' Kide Shoutbox'''&lt;br /&gt;
&lt;br /&gt;
|Summary: The Kide Shoutbox (com_kide) component 0.4.6 for Joomla! does not properly perform authentication, which allows remote attackers to post messages with an arbitrary account name via an insertar action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Added: December 08&lt;br /&gt;
|[[NIST:CVE-2009-4232 | CVE-2009-4232]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | ''' JoomPortfolio Component'''&lt;br /&gt;
|Summary: [http://www.joomplace.com/joomportfolio/joomportfolio.html JoomPortfolio] Input passed via the &amp;quot;secid&amp;quot; parameter to index.php (when &amp;quot;option&amp;quot; is set to &amp;quot;com_joomportfolio&amp;quot; and &amp;quot;task&amp;quot; is set to &amp;quot;showcat&amp;quot;) is not properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.The vulnerability is reported in version 1.0.0. Other versions may also be affected. Added: December 18 {{JVer|1.5}}&lt;br /&gt;
|[http://secunia.com/advisories/37838/ Reporting Site]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''City Portal (templates?)'''&lt;br /&gt;
|Summary:   City Portal Blind SQL Injection Vulnerability added: 2009-12-18&lt;br /&gt;
|[http://www.exploit-db.com Reference] Possibly this [http://www.youjoomla.com/jclick-city-portal-joomla-template.html tempate]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''Event Manager'''&lt;br /&gt;
|Summary:  [http://www.jforjoomla.com/Joomla-Components/event-manager-15-component.html Event Manager] Blind SQL Injection Vulnerability EDB-ID: 10549&lt;br /&gt;
added: 2009-12-18&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | com_zcalendar&lt;br /&gt;
|Summary:  com_zcalendar Blind SQL-injection Vulnerability&lt;br /&gt;
EDB-ID: 10548 added: 2009-12-18&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''com_acmisc'''&lt;br /&gt;
|Summary:  com_acmisc SQL injection added: 2009-12-18&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''com_digistore'''&lt;br /&gt;
|Summary:  com_digistore SQL injection EDB-ID: 10546 added: 2009-12-18  {{JVer|1.5}}&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | '''  [http://www.ijoomla.com/ijoomla-digistore/ijoomla-digistore/ijoomla-digistore-change-log/ Update change log] '''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''com_jbook'''&lt;br /&gt;
|Summary:   com_jbook Blind SQL-injection EDB-ID: 10545 added: 2009-12-18 {{JVer|1.0}}&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |  '''com_personel'''&lt;br /&gt;
|Summary: com_personel component for Joomla! is vulnerable to SQL injection.&lt;br /&gt;
|[http://xforce.iss.net/xforce/xfdb/54903 iss.net reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |  '''JEEMA Article Collection'''&lt;br /&gt;
|Summary: [http://www.forum.jeema.net/component/content/article/4-jeema-article-collection-component/13-about-jeema-article-collection.html JEEMA Article Collection] Input passed via the &amp;quot;catid&amp;quot; parameter to index.php (when &amp;quot;option&amp;quot; is set to &amp;quot;com_jeemaarticlecollection&amp;quot; and &amp;quot;view&amp;quot; is set to &amp;quot;longlook&amp;quot;) is not properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. version 1.0.0.1 {{JVer|1.5}} added 22 dec 09&lt;br /&gt;
| [http://secunia.com/advisories/37865/ secunia]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;    | [http://www.jeema.net/downloads/free-joomla-extensions/joomla-components/12-jeema-joomla-article-collection.htm fixed the same in the version v102.]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |  '''HotBrackets Tournament Brackets '''&lt;br /&gt;
|Summary: The [http://extensions.joomla.org/extensions/sports-a-games/sports/10746 HotBrackets Tournament Brackets] component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. {{JVer|1.5}} added 22 dec &lt;br /&gt;
|[http://www.securityfocus.com/bid/37439/ Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''Car Manager'''&lt;br /&gt;
|Summary: http://webformatique.com/ com_carman Cross Site Scripting Vulnerability added 24 december 09{{JVer|1.5}}&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot; |'''Schools component'''&lt;br /&gt;
|Summary: The 'com_schools' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.&lt;br /&gt;
|[http://www.securityfocus.com/bid/37469 Reference] added 24 dec 09&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''webcamxp'''&lt;br /&gt;
|[http://extensions.joomla.org/extensions/communication/video-conference/4490 com_webcamxp] Cross Site Scripting Vulnerabilities  Last version 2008 {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''beeheard'''&lt;br /&gt;
|[http://extensions.joomla.org/extensions/contacts-and-feedback/testimonials-a-suggestions/10283 beeheard]  Blind SQL injection Vulnerability {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | '''  [http://beeheard.cmstactics.com/change-log Version 1.4.2] 04 Jan'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''jm-recommend'''&lt;br /&gt;
|jm-recommendCross Site Scripting Vulnerabilities. unable to locate on jed. {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | facileforms&lt;br /&gt;
| com_facileforms Cross Site Scripting Vulnerabilities. unable to locate on jed. Product considered retired.  {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''adagency'''&lt;br /&gt;
| [http://www.ijoomla.com/ijoomla-ad-agency/ijoomla-ad-agency/index/ adagency ]Vulnerabilities {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |  '''com_intuit'''&lt;br /&gt;
|[http://www.san-diego-web-designer.com/new-file-download/item/root/aboutimage-igateway-for-joomla.html com_intuit]Local File Inclusion Vulnerability {{JVer|1.5}} Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | '''  [http://www.securityfocus.com/bid/37494/discuss Retired]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''MemoryBook'''&lt;br /&gt;
|[http://extensions.joomla.org/extensions/calendars-a-events/birthdays-a-historic-events/10868 MemoryBook 1.2]  Multiple Vulnerabilities. requires: magic quotes OFF, user account {{JVer|1.5}} Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''qpersonel'''&lt;br /&gt;
|[http://extensions.joomla.org/extensions/directory-a-documentation/thematic-directory/7049 qpersonel ] Cross Site Scripting Vulnerabilities {{JVer|1.0}}[[Image:http://extensions.joomla.org/images/jed/compat_15_legacy.png]] Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''opryknings point''' &lt;br /&gt;
|com_oprykningspoint_mc Cross Site Scripting Vulnerabilities {{JVer|1.5}} Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''trabalhe conosco'''&lt;br /&gt;
|com_trabalhe_conosco Cross Site Scripting Vulnerabilities {{JVer|1.5}} Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''DhForum'''&lt;br /&gt;
|com_dhforum SQL Injection Vulnerability. considered retired/EOL Dec. 27 {{JVer|1.0}}1.5 legacy&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |'''com_morfeoshow'''&lt;br /&gt;
|[http://extensions.joomla.org/extensions/photos-a-images/photo-gallery-add-ons/9810 morfeoshow] this was a false report &lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''  false report'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''Run Digital Download rd-download''' &lt;br /&gt;
|[http://extensions.joomla.org/extensions/directory-a-documentation/downloads/7838 RD Download] Local File Disclosure Vulnerability  {{JVer|1.5}} Dec. 30 Version affected not disclosed.&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | [http://extensions.joomla.org/extensions/directory-a-documentation/downloads/7838 Version 0.9 relased] &lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|}&lt;br /&gt;
== November 2009 Compiled Vulnerability Reports. RESOLVED ONLY  ==&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
Items are not in any particular order.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  '''Extension'''&lt;br /&gt;
! class=&amp;quot;unsortable&amp;quot;| '''Details'''&lt;br /&gt;
!  '''Reference Link'''&lt;br /&gt;
!  '''Extension Update Link'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_djcatalog'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the DJ-Catalog ('''com_djcatalog''') component for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a showItem action and (2) cid parameter in a show action to index.php.&lt;br /&gt;
Published: 10/11/2009&lt;br /&gt;
CVSS Severity: 6.8 (MEDIUM)&lt;br /&gt;
|  [[NIST:CVE-2009-3661|CVE-2009-3661]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  |  '''com_soundset'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Soundset ('''com_soundset''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter to index.php.&lt;br /&gt;
Published: 10/09/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3644|CVE-2009-3644]]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  |  '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  |'''com_sportfusion'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Kinfusion SportFusion ('''com_sportfusion''') component 0.2.2 through 0.2.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid[0] parameter in a teamdetail action to index.php.&lt;br /&gt;
Published: 09/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3491|CVE-2009-3491]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  |'''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_icrmbasic'''&lt;br /&gt;
|  Summary: A certain interface in the iCRM Basic ('''com_icrmbasic''') component 1.4.2.31 for Joomla! does not require administrative authentication, which has unspecified impact and remote attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 09/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3481|CVE-2009-3481]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_mytube'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the MyRemote Video Gallery ('''com_mytube''') component 1.0 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter in a videos action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3446|CVE-2009-3446]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|   '''com_facebook'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the JoomlaFacebook ('''com_facebook''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a student action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3438|CVE-2009-3438]]&lt;br /&gt;
|   [http://extensions.joomla.org/extensions/4446/details JED entry.] [http://forge.joomla.org/gf/project/joomla-facebook/ Download site] Developer states reports not proven 24/07/10&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_tupinambis'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Tupinambis ('''com_tupinambis''') component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the proyecto parameter in a verproyecto action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3434|CVE-2009-3434]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_hbssearch'''&lt;br /&gt;
|  Summary: Cross-site scripting ('''XSS''') vulnerability in the Hotel Booking Reservation System ('''aka HBS or com_hbssearch''') component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the adult parameter in a showhoteldetails action to index.php.&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 4.3 ('''MEDIUM''')&lt;br /&gt;
|  [[NIST:CVE-2009-3368|CVE-2009-3368]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_hbssearch'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System ('''aka HBS or com_hbssearch''') component for Joomla! allow remote attackers to execute arbitrary SQL commands via the ('''1''') h_id, ('''2''') id, and ('''3''') rid parameters to longDesc.php, and the h_id parameter to ('''4''') detail.php, ('''5''') detail1.php, ('''6''') detail2.php, ('''7''') detail3.php, ('''8''') detail4.php, ('''9''') detail5.php, ('''10''') detail6.php, ('''11''') detail7.php, and ('''12''') detail8.php, different vectors than [[NIST:CVE-2008-5865|CVE-2008-5865]], [[NIST:CVE-2008-5874|CVE-2008-5874]], and [[NIST:CVE-2008-5875|CVE-2008-5875]].&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3357|CVE-2009-3357]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''TurtuShout'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the TurtuShout component 0.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Name field.&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3335|CVE-2009-3335]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jinc'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Lhacky! Extensions Cave Joomla! Integrated Newsletters Component ('''aka JINC or com_jinc''') component 0.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a messages action to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3334|CVE-2009-3334]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_surveymanager'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Focusplus Developments Survey Manager ('''com_surveymanager''') component 1.5.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the stype parameter in an editsurvey action to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3325|CVE-2009-3325]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_album'''&lt;br /&gt;
|  Summary: Directory traversal vulnerability in the Roland Breedveld Album ('''com_album''') component 1.14 for Joomla! allows remote attackers to access arbitrary directories and have unspecified other impact via a .. ('''dot dot''') in the target parameter to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3318|CVE-2009-3318]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''IXXO Cart Standalone'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in IXXO Cart Standalone before 3.9.6.1, and the IXXO Cart component for Joomla! 1.0.x, allows remote attackers to execute arbitrary SQL commands via the parent parameter.&lt;br /&gt;
Published: 09/16/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3215|CVE-2009-3215]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_digifolio'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the DigiFolio ('''com_digifolio''') component 1.52 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a project action to index.php.&lt;br /&gt;
Published: 09/15/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3193|CVE-2009-3193]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_aclassf'''&lt;br /&gt;
|  Summary: Cross-site scripting ('''XSS''') vulnerability in '''gmap.php''' in the Almond Classifieds ('''com_aclassf''') component 7.5 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the addr parameter.&lt;br /&gt;
Published: 09/10/2009&lt;br /&gt;
CVSS Severity: 4.3 ('''MEDIUM''')&lt;br /&gt;
|  [[NIST:CVE-2009-3155|CVE-2009-3155]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;   | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jabode'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in Jabode horoscope extension ('''com_jabode''') for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a sign task to index.php.&lt;br /&gt;
Published: 09/08/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
&lt;br /&gt;
|  [[NIST:CVE-2008-7169|CVE-2008-7169]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_gameserver'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Game Server ('''com_gameserver''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a gamepanel action to index.php.&lt;br /&gt;
Published: 09/03/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3063|CVE-2009-3063]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_artportal'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Artetics.com Art Portal ('''com_artportal''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the portalid parameter to index.php.&lt;br /&gt;
Published: 09/03/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3054|CVE-2009-3054]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_simpleshop'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Simple Shop Galore ('''com_simpleshop''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the section parameter in a section action to index.php, a different vulnerability than [[NIST:CVE-2008-2568|CVE-2008-2568]]. NOTE: this issue was disclosed by an unreliable researcher, so the details might be incorrect.&lt;br /&gt;
Published: 08/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-7033|CVE-2008-7033]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_groups'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Permis ('''com_groups''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a list action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 08/17/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-2789|CVE-2009-2789]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Live Chat ('''com_livechat''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the last parameter to getChatRoom.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6883|CVE-2008-6883]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: Live Chat ('''com_livechat''') component 1.0 for Joomla! allows remote attackers to use the xmlhttp.php script as an open HTTP proxy to hide network scanning activities or scan internal networks via a GET request with a full URL in the query string.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6882|CVE-2008-6882]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the Live Chat ('''com_livechat''') component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the last parameter to ('''1''') getChat.php, ('''2''') getChatRoom.php, and ('''3''') getSavedChatRooms.php.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6881|CVE-2008-6881]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jshop'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the JShop ('''com_jshop''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a product action to index.php.&lt;br /&gt;
Published: 11/02/2009&lt;br /&gt;
CVSS Severity: 7.5 '''(HIGH)''' &lt;br /&gt;
|  [[NIST:CVE-2009-3835|CVE-2009-3835]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;| '''EasyBook 2.0.0rc4'''&lt;br /&gt;
|  Summary: The Joomla component '''EasyBook 2.0.0rc4''' suffers from multiple persistent XSS vulnerabilities. One seems fairly critical, while the others would take some incredible creativity to actively exploit. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/easybook-200rc4-multiple-xss-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:#cef2e0; color:black&amp;quot;| '''  &lt;br /&gt;
[http://www.kubik-rubik.de/joomla-hilfe/komponente-easybook-reloaded-joomla easybook reloaded released]&lt;br /&gt;
'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''F!BB 1.5.96''' &lt;br /&gt;
|  Summary: The Joomla component '''F!BB 1.5.96 RC''' suffers from multiple persistent XSS vulnerabilities, as well SQL Injection in its user search feature. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/fbb-1596-rc-multiple-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Testimonial Ku 2.0 Admin Panel'''&lt;br /&gt;
|  Summary: The Joomla component '''Testimonial Ku 2.0''' is vulnerable to persistent XSS in the administrator panel. A malicious user can submit a testimonial containing &amp;lt;script&amp;gt; tags with absolutely no quotes and inject that script into the administrator panel through any of the available inputs except &amp;quot;email&amp;quot;. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/testimonial-ku-20-admin-panel-persistent-xss.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''MS Comment 0.8.0b'''&lt;br /&gt;
|  Summary '''MS Comment 0.8.0b for Joomla''', a commenting plugin, suffers from an multiple vulnerabilities. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/ms-comment-080b-multiple-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''WebAmoeba Ticket System 3.0.0'''&lt;br /&gt;
|  Summary:  '''WebAmoeba Ticket System 3.0.0''', a Joomla help desk component. The vulnerability is with the BBCode library used to parse BBCode tags, as it does not strip javascript: urls from [url] tags. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/webamoeba-ticket-system-300-bbcode-xss.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_siirler'''&lt;br /&gt;
|  Summary:  SQL injection vulnerability in the '''Q-Proje Siirler Bileseni (com_siirler)''' component 1.2 RC for Joomla! allows remote attackers to execute arbitrary SQL commands via the sid parameter in an sdetay action to index.php. Added 18 November 2009&lt;br /&gt;
|  [[NIST:CVE-2009-3972 | CVE-2009-3972]]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''jTips (com_jtips)'''&lt;br /&gt;
|SUmmary:SQL injection vulnerability in the '''jTips (com_jtips)''' component 1.0.7 and 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the season parameter in a ladder action to index.php. Added 18 November 2009&lt;br /&gt;
| [[NIST:CVE-2009-3971 |CVE-2009-3971]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''JoomClip'''&lt;br /&gt;
|Summary: The '''JoomClip component for Joomla!''' is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements to the index.php script using the cat parameter, which could allow the attacker to view, add, modify or delete information in the back-end database.  Nov 18, 2009&lt;br /&gt;
|[http://secunia.com/advisories/37400/ secunia.com 37400/]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Mygallery Remote SQL Injection Vulnerability''' &lt;br /&gt;
|Summary: Joomla Component mygallery ( farbinform_krell) Remote SQL Injection Vulnerability Added 27 Nov 2009 {{JVer|1.5}} NB: This could be an error in our database as the only one we could find was for wordpress.If anyone know of one for joomla please let us know..(poss joomlicious.com CM)&lt;br /&gt;
|[http://www.exploit-db.com] &lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Extreme Google Calendar'''&lt;br /&gt;
|Summary: '''com_gcalendar 1.1.2''' (gcid) Remote SQL Injection Vulnerability&lt;br /&gt;
Remote SQL Injection were identified in Google Calendar Component [http://extensions.joomla.org/extensions/calendars-a-events/calendars/4188 Extension Link] Added 27 Nov 2009 &lt;br /&gt;
|[http://www.exploit-db.com reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''LyftenBloggie'''&lt;br /&gt;
| Summary: [http://www.lyften.com/products/lyftenbloggie.html LyftenBloggie] Component &amp;quot;author&amp;quot; SQL Injection Vulnerability LyftenBloggie 1.x Added 27 Nov 2009&lt;br /&gt;
|[http://secunia.com/advisories/product/28005/	 SA37499]&lt;br /&gt;
| [http://jeffchannell.com/Joomla/lyften-bloggie-sql-injection-fix.html Un official fix]. Developer fix not release at 30 Nov 09 ''' [http://www.lyften.com/products/lyftenbloggie/extensions/download/id-20.html 1.0.4a (last update on Dec 28, 2009)]'''&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== November 2009 Compiled Vulnerability Reports. ==&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
Items are not in any particular order.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  '''Extension'''&lt;br /&gt;
! class=&amp;quot;unsortable&amp;quot;| '''Details'''&lt;br /&gt;
!  '''Reference Link'''&lt;br /&gt;
!  '''Extension Update Link'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_djcatalog'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the DJ-Catalog ('''com_djcatalog''') component for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a showItem action and (2) cid parameter in a show action to index.php.&lt;br /&gt;
Published: 10/11/2009&lt;br /&gt;
CVSS Severity: 6.8 (MEDIUM)&lt;br /&gt;
|  [[NIST:CVE-2009-3661|CVE-2009-3661]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  |  '''com_soundset'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Soundset ('''com_soundset''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter to index.php.&lt;br /&gt;
Published: 10/09/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3644|CVE-2009-3644]]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  |  '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  |'''com_sportfusion'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Kinfusion SportFusion ('''com_sportfusion''') component 0.2.2 through 0.2.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid[0] parameter in a teamdetail action to index.php.&lt;br /&gt;
Published: 09/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3491|CVE-2009-3491]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  |'''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_icrmbasic'''&lt;br /&gt;
|  Summary: A certain interface in the iCRM Basic ('''com_icrmbasic''') component 1.4.2.31 for Joomla! does not require administrative authentication, which has unspecified impact and remote attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 09/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3481|CVE-2009-3481]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_mytube'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the MyRemote Video Gallery ('''com_mytube''') component 1.0 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter in a videos action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3446|CVE-2009-3446]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|   '''com_facebook'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the JoomlaFacebook ('''com_facebook''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a student action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3438|CVE-2009-3438]]&lt;br /&gt;
|   [http://extensions.joomla.org/extensions/4446/details JED entry.] [http://forge.joomla.org/gf/project/joomla-facebook/ Download site] Developer states reports not proven 24/07/10&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_tupinambis'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Tupinambis ('''com_tupinambis''') component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the proyecto parameter in a verproyecto action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3434|CVE-2009-3434]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_hbssearch'''&lt;br /&gt;
|  Summary: Cross-site scripting ('''XSS''') vulnerability in the Hotel Booking Reservation System ('''aka HBS or com_hbssearch''') component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the adult parameter in a showhoteldetails action to index.php.&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 4.3 ('''MEDIUM''')&lt;br /&gt;
|  [[NIST:CVE-2009-3368|CVE-2009-3368]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_hbssearch'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System ('''aka HBS or com_hbssearch''') component for Joomla! allow remote attackers to execute arbitrary SQL commands via the ('''1''') h_id, ('''2''') id, and ('''3''') rid parameters to longDesc.php, and the h_id parameter to ('''4''') detail.php, ('''5''') detail1.php, ('''6''') detail2.php, ('''7''') detail3.php, ('''8''') detail4.php, ('''9''') detail5.php, ('''10''') detail6.php, ('''11''') detail7.php, and ('''12''') detail8.php, different vectors than [[NIST:CVE-2008-5865|CVE-2008-5865]], [[NIST:CVE-2008-5874|CVE-2008-5874]], and [[NIST:CVE-2008-5875|CVE-2008-5875]].&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3357|CVE-2009-3357]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''TurtuShout'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the TurtuShout component 0.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Name field.&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3335|CVE-2009-3335]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jinc'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Lhacky! Extensions Cave Joomla! Integrated Newsletters Component ('''aka JINC or com_jinc''') component 0.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a messages action to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3334|CVE-2009-3334]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_surveymanager'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Focusplus Developments Survey Manager ('''com_surveymanager''') component 1.5.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the stype parameter in an editsurvey action to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3325|CVE-2009-3325]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_album'''&lt;br /&gt;
|  Summary: Directory traversal vulnerability in the Roland Breedveld Album ('''com_album''') component 1.14 for Joomla! allows remote attackers to access arbitrary directories and have unspecified other impact via a .. ('''dot dot''') in the target parameter to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3318|CVE-2009-3318]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''IXXO Cart Standalone'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in IXXO Cart Standalone before 3.9.6.1, and the IXXO Cart component for Joomla! 1.0.x, allows remote attackers to execute arbitrary SQL commands via the parent parameter.&lt;br /&gt;
Published: 09/16/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3215|CVE-2009-3215]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_digifolio'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the DigiFolio ('''com_digifolio''') component 1.52 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a project action to index.php.&lt;br /&gt;
Published: 09/15/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3193|CVE-2009-3193]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_aclassf'''&lt;br /&gt;
|  Summary: Cross-site scripting ('''XSS''') vulnerability in '''gmap.php''' in the Almond Classifieds ('''com_aclassf''') component 7.5 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the addr parameter.&lt;br /&gt;
Published: 09/10/2009&lt;br /&gt;
CVSS Severity: 4.3 ('''MEDIUM''')&lt;br /&gt;
|  [[NIST:CVE-2009-3155|CVE-2009-3155]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;   | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jabode'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in Jabode horoscope extension ('''com_jabode''') for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a sign task to index.php.&lt;br /&gt;
Published: 09/08/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
&lt;br /&gt;
|  [[NIST:CVE-2008-7169|CVE-2008-7169]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_gameserver'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Game Server ('''com_gameserver''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a gamepanel action to index.php.&lt;br /&gt;
Published: 09/03/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3063|CVE-2009-3063]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_artportal'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Artetics.com Art Portal ('''com_artportal''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the portalid parameter to index.php.&lt;br /&gt;
Published: 09/03/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3054|CVE-2009-3054]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_simpleshop'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Simple Shop Galore ('''com_simpleshop''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the section parameter in a section action to index.php, a different vulnerability than [[NIST:CVE-2008-2568|CVE-2008-2568]]. NOTE: this issue was disclosed by an unreliable researcher, so the details might be incorrect.&lt;br /&gt;
Published: 08/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-7033|CVE-2008-7033]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_groups'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Permis ('''com_groups''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a list action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 08/17/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-2789|CVE-2009-2789]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Live Chat ('''com_livechat''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the last parameter to getChatRoom.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6883|CVE-2008-6883]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: Live Chat ('''com_livechat''') component 1.0 for Joomla! allows remote attackers to use the xmlhttp.php script as an open HTTP proxy to hide network scanning activities or scan internal networks via a GET request with a full URL in the query string.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6882|CVE-2008-6882]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the Live Chat ('''com_livechat''') component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the last parameter to ('''1''') getChat.php, ('''2''') getChatRoom.php, and ('''3''') getSavedChatRooms.php.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6881|CVE-2008-6881]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jshop'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the JShop ('''com_jshop''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a product action to index.php.&lt;br /&gt;
Published: 11/02/2009&lt;br /&gt;
CVSS Severity: 7.5 '''(HIGH)''' &lt;br /&gt;
|  [[NIST:CVE-2009-3835|CVE-2009-3835]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;| '''EasyBook 2.0.0rc4'''&lt;br /&gt;
|  Summary: The Joomla component '''EasyBook 2.0.0rc4''' suffers from multiple persistent XSS vulnerabilities. One seems fairly critical, while the others would take some incredible creativity to actively exploit. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/easybook-200rc4-multiple-xss-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:#cef2e0; color:black&amp;quot;| '''  &lt;br /&gt;
[http://www.kubik-rubik.de/joomla-hilfe/komponente-easybook-reloaded-joomla easybook reloaded released]&lt;br /&gt;
'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''F!BB 1.5.96''' &lt;br /&gt;
|  Summary: The Joomla component '''F!BB 1.5.96 RC''' suffers from multiple persistent XSS vulnerabilities, as well SQL Injection in its user search feature. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/fbb-1596-rc-multiple-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Testimonial Ku 2.0 Admin Panel'''&lt;br /&gt;
|  Summary: The Joomla component '''Testimonial Ku 2.0''' is vulnerable to persistent XSS in the administrator panel. A malicious user can submit a testimonial containing &amp;lt;script&amp;gt; tags with absolutely no quotes and inject that script into the administrator panel through any of the available inputs except &amp;quot;email&amp;quot;. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/testimonial-ku-20-admin-panel-persistent-xss.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''MS Comment 0.8.0b'''&lt;br /&gt;
|  Summary '''MS Comment 0.8.0b for Joomla''', a commenting plugin, suffers from an multiple vulnerabilities. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/ms-comment-080b-multiple-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''WebAmoeba Ticket System 3.0.0'''&lt;br /&gt;
|  Summary:  '''WebAmoeba Ticket System 3.0.0''', a Joomla help desk component. The vulnerability is with the BBCode library used to parse BBCode tags, as it does not strip javascript: urls from [url] tags. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/webamoeba-ticket-system-300-bbcode-xss.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_siirler'''&lt;br /&gt;
|  Summary:  SQL injection vulnerability in the '''Q-Proje Siirler Bileseni (com_siirler)''' component 1.2 RC for Joomla! allows remote attackers to execute arbitrary SQL commands via the sid parameter in an sdetay action to index.php. Added 18 November 2009&lt;br /&gt;
|  [[NIST:CVE-2009-3972 | CVE-2009-3972]]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''jTips (com_jtips)'''&lt;br /&gt;
|SUmmary:SQL injection vulnerability in the '''jTips (com_jtips)''' component 1.0.7 and 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the season parameter in a ladder action to index.php. Added 18 November 2009&lt;br /&gt;
| [[NIST:CVE-2009-3971 |CVE-2009-3971]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''JoomClip'''&lt;br /&gt;
|Summary: The '''JoomClip component for Joomla!''' is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements to the index.php script using the cat parameter, which could allow the attacker to view, add, modify or delete information in the back-end database.  Nov 18, 2009&lt;br /&gt;
|[http://secunia.com/advisories/37400/ secunia.com 37400/]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Mygallery Remote SQL Injection Vulnerability''' &lt;br /&gt;
|Summary: Joomla Component mygallery ( farbinform_krell) Remote SQL Injection Vulnerability Added 27 Nov 2009 {{JVer|1.5}} NB: This could be an error in our database as the only one we could find was for wordpress.If anyone know of one for joomla please let us know..(poss joomlicious.com CM)&lt;br /&gt;
|[http://www.exploit-db.com] &lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Extreme Google Calendar'''&lt;br /&gt;
|Summary: '''com_gcalendar 1.1.2''' (gcid) Remote SQL Injection Vulnerability&lt;br /&gt;
Remote SQL Injection were identified in Google Calendar Component [http://extensions.joomla.org/extensions/calendars-a-events/calendars/4188 Extension Link] Added 27 Nov 2009 &lt;br /&gt;
|[http://www.exploit-db.com reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''LyftenBloggie'''&lt;br /&gt;
| Summary: [http://www.lyften.com/products/lyftenbloggie.html LyftenBloggie] Component &amp;quot;author&amp;quot; SQL Injection Vulnerability LyftenBloggie 1.x Added 27 Nov 2009&lt;br /&gt;
|[http://secunia.com/advisories/product/28005/	 SA37499]&lt;br /&gt;
| [http://jeffchannell.com/Joomla/lyften-bloggie-sql-injection-fix.html Un official fix]. Developer fix not release at 30 Nov 09 ''' [http://www.lyften.com/products/lyftenbloggie/extensions/download/id-20.html 1.0.4a (last update on Dec 28, 2009)]'''&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== December 2009 Compiled Reports ==&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  '''Extension'''&lt;br /&gt;
! class=&amp;quot;unsortable&amp;quot;| '''Details'''&lt;br /&gt;
!  '''Reference Link'''&lt;br /&gt;
!  '''Extension Update Link'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Omilen Photo Gallery'''&lt;br /&gt;
|Summary: Directory traversal vulnerability in the [http://extensions.joomla.org/extensions/photos-&amp;amp;-images/photo-flash-gallery/6373/details Omilen Photo Gallery] (com_omphotogallery) component Beta 0.5 for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the controller parameter to index.php.&lt;br /&gt;
Published: 12/04/2009&lt;br /&gt;
|[[NIST:CVE-2009-4202 | CVE-2009-4202]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   | '''Seminar'''&lt;br /&gt;
|Summary: SQL injection vulnerability in the [http://seminar.vollmar.ws/ Seminar] (com_seminar) component 1.28 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a View_seminar action to index.php.&lt;br /&gt;
Published: 12/04/2009&lt;br /&gt;
|[[NIST:CVE-2009-4200 | CVE-2009-4200]]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   | '''  released V1.29, released'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''ProofReader''' &lt;br /&gt;
|Summary: Multiple cross-site scripting (XSS) vulnerabilities in index.php in the ProofReader (com_proofreader) component 1.0 RC9 and earlier for Joomla! allow remote attackers to inject arbitrary web script or HTML via the URI, which is not properly handled in (1) 404 or (2) error pages. Published: 12/02/2009 CVSS Severity: 4.3 (MEDIUM)&lt;br /&gt;
| [[NIST:CVE-2009-4157 | CVE-2009-4157]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''D4J eZine'''&lt;br /&gt;
|Summary: PHP remote file inclusion vulnerability in class/php/d4m_ajax_pagenav.php in the D4J eZine (com_ezine) component 2.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS mosConfig_absolute_path parameter. Published: 11/29/2009 CVSS Severity: 7.5 (HIGH)&lt;br /&gt;
|[[NIST:CVE-2009-4094 | CVE-2009-4094]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''Quick News'''&lt;br /&gt;
| Summary: The Joomla [http://joomlacode.org/gf/project/quicknews/ Quick News component] suffers from a remote SQL injection vulnerability. added 1st Dec 09&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''mojoblog'''&lt;br /&gt;
|Summary [http://www.joomlify.com/files/mojoblog/ MojoBlog] Multiple Remote File Include Vulnerability added 1st Dec 09 {{JVer|1.5}}&lt;br /&gt;
|[http://securityreason.com/exploitalert/7509 7509]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''TP Whois''' &lt;br /&gt;
|summary: [http://www.templateplazza.com/view-details/tpwhois/183-component-tp-whois-for-joomla-1.5.x.html TP Whois ] Malicious users may inject JavaScript, VBScript, ActiveX, HTML or Flash into a vulnerable application to fool a user in order to gather data from them. An attacker can steal the session cookie and take over the account. Added 3 december {{JVer|1.5}}&lt;br /&gt;
|[http://www.exploit-db.com Refrence]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''com_job'''&lt;br /&gt;
|Summary: Component com_job ( showMoreUse) SQL injection vulnerability  Added 9th Dec&lt;br /&gt;
|[http://xforce.iss.net/xforce/xfdb/54626 Reference]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''Mamboleto Component 2.0 RC3'''&lt;br /&gt;
|Summary: [http://www.fernandosoares.com.br/index.php?option=com_docman&amp;amp;task=cat_view&amp;amp;gid=28&amp;amp;Itemid=28 Mamboleto Component 2.0 RC3]SQL injection vulnerability {{JVer|1.5}} added 12 December&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | ''' Kide Shoutbox'''&lt;br /&gt;
|Summary: The Kide Shoutbox (com_kide) component 0.4.6 for Joomla! does not properly perform authentication, which allows remote attackers to post messages with an arbitrary account name via an insertar action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Added: December 08&lt;br /&gt;
|[[NIST:CVE-2009-4232 | CVE-2009-4232]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | ''' JoomPortfolio Component'''&lt;br /&gt;
|Summary: [http://www.joomplace.com/joomportfolio/joomportfolio.html JoomPortfolio] Input passed via the &amp;quot;secid&amp;quot; parameter to index.php (when &amp;quot;option&amp;quot; is set to &amp;quot;com_joomportfolio&amp;quot; and &amp;quot;task&amp;quot; is set to &amp;quot;showcat&amp;quot;) is not properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.The vulnerability is reported in version 1.0.0. Other versions may also be affected. Added: December 18 {{JVer|1.5}}&lt;br /&gt;
|[http://secunia.com/advisories/37838/ Reporting Site]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''City Portal (templates?)'''&lt;br /&gt;
|Summary:   City Portal Blind SQL Injection Vulnerability added: 2009-12-18&lt;br /&gt;
|[http://www.exploit-db.com Reference] Possibly this [http://www.youjoomla.com/jclick-city-portal-joomla-template.html tempate]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''Event Manager'''&lt;br /&gt;
|Summary:  [http://www.jforjoomla.com/Joomla-Components/event-manager-15-component.html Event Manager] Blind SQL Injection Vulnerability EDB-ID: 10549&lt;br /&gt;
added: 2009-12-18&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | com_zcalendar&lt;br /&gt;
|Summary:  com_zcalendar Blind SQL-injection Vulnerability&lt;br /&gt;
EDB-ID: 10548 added: 2009-12-18&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''com_acmisc'''&lt;br /&gt;
|Summary:  com_acmisc SQL injection added: 2009-12-18&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''com_jbook'''&lt;br /&gt;
|Summary:   com_jbook Blind SQL-injection EDB-ID: 10545 added: 2009-12-18 {{JVer|1.0}}&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |  '''com_personel'''&lt;br /&gt;
|Summary: com_personel component for Joomla! is vulnerable to SQL injection.&lt;br /&gt;
|[http://xforce.iss.net/xforce/xfdb/54903 iss.net reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |  '''HotBrackets Tournament Brackets '''&lt;br /&gt;
|Summary: The [http://extensions.joomla.org/extensions/sports-a-games/sports/10746 HotBrackets Tournament Brackets] component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. {{JVer|1.5}} added 22 dec &lt;br /&gt;
|[http://www.securityfocus.com/bid/37439/ Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''Car Manager'''&lt;br /&gt;
|Summary: http://webformatique.com/ com_carman Cross Site Scripting Vulnerability added 24 december 09{{JVer|1.5}}&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot; |'''Schools component'''&lt;br /&gt;
|Summary: The 'com_schools' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.&lt;br /&gt;
|[http://www.securityfocus.com/bid/37469 Reference] added 24 dec 09&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''webcamxp'''&lt;br /&gt;
|[http://extensions.joomla.org/extensions/communication/video-conference/4490 com_webcamxp] Cross Site Scripting Vulnerabilities  Last version 2008 {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''jm-recommend'''&lt;br /&gt;
|jm-recommendCross Site Scripting Vulnerabilities. unable to locate on jed. {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | facileforms&lt;br /&gt;
| com_facileforms Cross Site Scripting Vulnerabilities. unable to locate on jed. Product considered retired.  {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''adagency'''&lt;br /&gt;
| [http://www.ijoomla.com/ijoomla-ad-agency/ijoomla-ad-agency/index/ adagency ]Vulnerabilities {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |  '''com_intuit'''&lt;br /&gt;
|[http://www.san-diego-web-designer.com/new-file-download/item/root/aboutimage-igateway-for-joomla.html com_intuit]Local File Inclusion Vulnerability {{JVer|1.5}} Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | '''  [http://www.securityfocus.com/bid/37494/discuss Retired]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''MemoryBook'''&lt;br /&gt;
|[http://extensions.joomla.org/extensions/calendars-a-events/birthdays-a-historic-events/10868 MemoryBook 1.2]  Multiple Vulnerabilities. requires: magic quotes OFF, user account {{JVer|1.5}} Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''qpersonel'''&lt;br /&gt;
|[http://extensions.joomla.org/extensions/directory-a-documentation/thematic-directory/7049 qpersonel ] Cross Site Scripting Vulnerabilities {{JVer|1.0}}[[Image:http://extensions.joomla.org/images/jed/compat_15_legacy.png]] Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''opryknings point''' &lt;br /&gt;
|com_oprykningspoint_mc Cross Site Scripting Vulnerabilities {{JVer|1.5}} Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''trabalhe conosco'''&lt;br /&gt;
|com_trabalhe_conosco Cross Site Scripting Vulnerabilities {{JVer|1.5}} Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''DhForum'''&lt;br /&gt;
|com_dhforum SQL Injection Vulnerability. considered retired/EOL Dec. 27 {{JVer|1.0}}1.5 legacy&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== January 2010 Reported Vulnerable Extensions ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Please check with the extension publisher in case of any questions over the security of their product.'''&lt;br /&gt;
Report Vulnerable extensions either in the [[jforum:432]] security topic or the [http://forum.joomla.org/viewforum.php?f=470 extensions] topic clearly marked with the first word in the title being ''Vulnerable'' where the security moderators or JSST team will respond. &lt;br /&gt;
''This list is change protected, for updates or editing requests [http://forum.joomla.org/memberlist.php?mode=viewprofile&amp;amp;u=28000 Mandville] or [http://forum.joomla.org/memberlist.php?mode=viewprofile&amp;amp;u=87230 lafrance]&lt;br /&gt;
''&lt;br /&gt;
&lt;br /&gt;
[http://docs.joomla.org/Vulnerable_Extensions_List Back To Top]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  '''Extension'''&lt;br /&gt;
! class=&amp;quot;unsortable&amp;quot;| '''Details'''&lt;br /&gt;
!  '''Reference Link'''&lt;br /&gt;
!  '''Extension Update Link'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   |JvideoDirect&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/multimedia/video-players-a-gallery/9501 Jvideodirect] SQLi Jan 29&lt;br /&gt;
|&lt;br /&gt;
|[http://www.jvideodirect.com/ Update version 2.5]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   |'''JEvent search plugin'''&lt;br /&gt;
|Summary: JEvent search plugin for [http://extensions.joomla.org/extensions/calendars-a-events/events/95 JEvent] SQLi reported Jan 29&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | '''  [http://www.jevents.net/forum/viewtopic.php?f=17&amp;amp;t=3910#p15526 upgrade to 1.5.3b]'''&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   |'''Kunena'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/communication/forum/7256/details kunena] re reported suffering SQLi in version 1.5.9 Jan 29 Confirmation Required '''Now found to be malicious'''&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; | '''  [http://www.kunena.com/blog/19-developer-blog/51-kunena-157-security-release-now-available Versions 1.5.5 and below only]'''&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |'''JE Quiz'''&lt;br /&gt;
|Summary : http://extensions.joomla.org/extensions/contacts-and-feedback/quiz-a-surveys/11212 JeQuiz SQLi reported 29 Jan&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;&amp;quot;   |'''idoblog'''&lt;br /&gt;
|summary: exploitable due to open file permissions. 28 Jan&lt;br /&gt;
|Private Notification&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; | '''  [http://idojoomla.com/news.html build 35 released] '''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;    |'''ccnewsletter'''&lt;br /&gt;
|Summary [http://extensions.joomla.org/extensions/5112/details ccnewsletter Directory Traversal Vulnerability] Jan 28 &lt;br /&gt;
|Private Notification&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | ''' [http://www.chillcreations.com/en/blog/ccnewsletter-joomla-newsletter/ccnewsletter-106-security-release.html version 1.0.6 released 29 Jan]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;   |'''Virtuemart 1.1.4'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/e-commerce/shopping-cart/129 virtuemart] Input var order_status_id is vulnerable to SQLi NB Requires Higher Level access before exploiting. Jan 27&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; | '''  [http://forum.joomla.org/viewtopic.php?p=2027005#p2027005 developer patches]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   |'''JBDiary'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/calendars-a-events/events/11009 JBDiary] BLIND SQL Injection Vulnerabilities Jan 24 [http://www.jb-soft.nl/ http://www.jb-soft.nl/]&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;   | ''' [http://www.jb-soft.nl/index.php?option=com_content&amp;amp;view=article&amp;amp;id=64 Developer Update 27 Jan]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   |'''JbPublishDownFp'''&lt;br /&gt;
|Sumary: [http://extensions.joomla.org/extensions/news-production/timed-content/6496 JbPublishDownFp] SQL Injection Vulnerability Jan 24 [http://www.jb-soft.nl http://www.jb-soft.nl]&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |'''  [http://www.jb-soft.nl/index.php?option=com_content&amp;amp;view=article&amp;amp;id=64 Developer Update Jan 27]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''com_casino'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/sports-a-games/tips-a-betts com_casino]&lt;br /&gt;
SQL Injection Vulnerabilities Jan24&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   |'''Mochigames'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/search/mochigames com_Mochigames]&lt;br /&gt;
SQL Injection Vulnerabilities Jan24&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | ''' [http://www.yoflash.com/download.html mochigames_alpha052 Released]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |'''ContentBlogList'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/news-production/blog/10989 com_ContentBlogList] SQL Injection Vulnerability Jan 23&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |MailChimp for Joomla 1.5&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/bridges/mailing-a-newsletter-bridges/7836 MailChimp for Joomla 1.5]  jan 17&lt;br /&gt;
|Developer Statement&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |'''JoomlaXML'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/tools/design-tools/5020 JoomlaXML] malicious code insertion&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''JVClouds3D SWF module'''&lt;br /&gt;
|[http://joomlapro.ru/3djvclouds JVClouds3D SWF module] Cross Site Scripting . jan 14&lt;br /&gt;
|[http://xforce.iss.net/xforce/xfdb/55535 xforce]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''JVClouds3D'''&lt;br /&gt;
|[http://joomlapro.ru/3djvclouds JVClouds3D module] Cross Site Scripting . jan 14&lt;br /&gt;
|[http://xforce.iss.net/xforce/xfdb/55534 xforce]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |'''JA Showcase'''&lt;br /&gt;
|[http://www.joomlart.com/addons/components_and_modules/ja_showcase.html JA Showcase component] Directory Traversal jan 14&lt;br /&gt;
|[http://xforce.iss.net/xforce/xfdb/55512 xforce]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |'''jprojects'''&lt;br /&gt;
|Summary:   Unknown Author com_j-projects Blind SQL Injection Vulnerability. Jan 10 detail update&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |'''jEmbed-Embed Anything'''&lt;br /&gt;
|[http://www.joshprakash.com/index.php?option=com_docman&amp;amp;task=doc_details&amp;amp;gid=70 jEmbed-Embed Anything] A vulnerability has been discovered in the jEmbed-Embed Anything component for Joomla, which can be exploited by malicious people to conduct SQL injection attacks. Jan 10&lt;br /&gt;
|[http://secunia.com/advisories/38112 Secunia Advisory: SA38112] &lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | [http://extensions.joomla.org/extensions/3699/details Product considered retired]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;    |'''perchagallery '''&lt;br /&gt;
|Summary: perchagallery  [http://extensions.joomla.org/extensions/photos-a-images/photo-gallery/10350 com_perchagallery] SQL Injection Vulnerability  Jan 7&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | '''  [http://www.percha.com/index.php?option=com_phocadownload&amp;amp;view=file&amp;amp;id=22:1.5&amp;amp;Itemid=20 Developer Update 1.5b]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0;  color:black&amp;quot;   |  '''CARTwebERP'''&lt;br /&gt;
|Summary:  [http://extensions.joomla.org/extensions/bridges/e-commerce-bridges/8753 CARTwebERP] Local File Inclusion Vulnerability  Jan. 3&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | '''  [http://extensions.joomla.org/extensions/bridges/e-commerce-bridges/8753 1.56.76 (last update on Jan 11, 2010)]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |   '''JoomlaBibleStudy'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/miscellaneous/religion/3461 JoomlaBibleStudy] LFI Vulnerability  Jan. 3&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;   | '''[http://joomlabiblestudy.org/invisible-downloads/category/3-component.html Developer reported update]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |  '''com_bfsurvey_basic and pro'''&lt;br /&gt;
|Summary: [http://www.tamlyncreative.com.au/software/ BFsurvey] SQL Injection Vulnerability ,LFI Vulnerability   Jan. 3&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | '''  [http://www.tamlyncreative.com.au/software/forum/index.php?topic=641.0 Developer Update announcement]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''Alfresco'''&lt;br /&gt;
|Summary:  SQL Injection Vulnerability. Not believed to be Joomlatools extension Jan. 3&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''abbrev'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/directory-a-documentation/glossary-a-dictionary/4965 abbrev] Local File Inclusion Vulnerability Jan. 3&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''countries'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/miscellaneous/development/6553 countries] SQL Injection Vulnerability  Jan. 3&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   |  '''Dedicated Component com_tpjobs'''&lt;br /&gt;
|Summary: [http://www.templateplazza.com/ tpjobs] SQL Injection Vulnerability unable to locate files probably template plaza  Jan. 3&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;     | '''  [http://www.templateplazza.com/extensions-updates/tpjobs-component-update-v-1.1.html Developer Update] '''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''Component com_doqment'''&lt;br /&gt;
|SQL Injection Vulnerability Jan. 3&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''Component com_otzivi''' &lt;br /&gt;
|Blind SQL Injection Vulnerability  Jan. 3&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''aprice'''&lt;br /&gt;
|Summary: [http://adeptweb.info/component/option,com_aprice/Itemid,109/ com_aprice] Component 'analog' Parameter SQL Injection Vulnerability&lt;br /&gt;
|[http://www.securityfocus.com/bid/37575 Report]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |'''cartikads'''&lt;br /&gt;
|Summary: [http://www.cartikahosting.com com_cartikads] Remote File Upload Vulnerability &lt;br /&gt;
'''Mambo''' Open Source ads management component&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   | '''Docman seller''' &lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/e-commerce/subscriptions/5000 Document seller]  Input passed via the &amp;quot;id&amp;quot; parameter to index.php (when &amp;quot;option&amp;quot; is set to &amp;quot;com_dm_orders&amp;quot;, &amp;quot;task&amp;quot; is set to &amp;quot;order_form&amp;quot;, and &amp;quot;payment_method&amp;quot; is set to &amp;quot;Paypal&amp;quot;) is not properly sanitised before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.&lt;br /&gt;
|[http://secunia.com/advisories/38024/ secunia]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;   | [http://extensions.joomla.org/extensions/e-commerce/subscriptions/5000 Updated 10th Jan]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |  '''ozio gallery''' &lt;br /&gt;
|summary: [http://extensions.joomla.org/extensions/photos-a-images/photo-flash-gallery/4883 Ozio Gallery2] SQLi eploit &lt;br /&gt;
|[http://www.viruslist.com/en/advisories/37974 Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;   |[http://oziogallery.joomla.it/index.php?option=com_content&amp;amp;view=article&amp;amp;id=62%3Anuova-ozio-gallery-23-aggiornamento-di-sicurezza&amp;amp;catid=2%3Anotizie&amp;amp;Itemid=13&amp;amp;lang=en developer update Jan 11]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   | '''RD-Autos Free''' &lt;br /&gt;
|[http://extensions.joomla.org/extensions/vertical-markets/vehicles/5458 RD-Autos Free ] This version is now commercial not free&lt;br /&gt;
|Private advisory to JED Jan 11&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | ''' Product Retired and replaced'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''DailyMeals'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/vertical-markets/food-a-beverage/4764 dailymeals] Local File Inclusion  Vulnerability  Jan 02&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''RD-Autos Pro''' &lt;br /&gt;
|[http://extensions.joomla.org/extensions/vertical-markets/vehicles/6357 RD Autos Pro]&lt;br /&gt;
|Private advisory to JED Jan 11&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   | '''  Upgrade to  Latest version  be 2.0.2'''&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
[[Category:Security]]&lt;br /&gt;
[[Category:Component Management]]&lt;/div&gt;</summary>
		<author><name>CirTap</name></author>	</entry>

	<entry>
		<id>http://docs.joomla.org/Vulnerable_Extensions_List</id>
		<title>Vulnerable Extensions List</title>
		<link rel="alternate" type="text/html" href="http://docs.joomla.org/Vulnerable_Extensions_List"/>
				<updated>2011-07-15T13:03:37Z</updated>
		
		<summary type="html">&lt;p&gt;CirTap: Reverted edits by CirTap (talk) to last revision by Mandville&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{RightTOC}}&lt;br /&gt;
'''List prior to Jnuary 2010 ([[Archived vel|now archived]])''' Please check here also. &lt;br /&gt;
&lt;br /&gt;
Please also check the [[Investigation of exploits|Extension Investigation List]].&lt;br /&gt;
 &lt;br /&gt;
== Check and Report.  ==&lt;br /&gt;
'''Please check with the extension publisher in case of any questions over the security of their product.'''&lt;br /&gt;
Report Vulnerable extensions in the [[jforum:432|security forum]]  clearly marked with the first word in the title being ''Vulnerable'' where the security moderators or JSST team will respond. &lt;br /&gt;
This list is change protected,''' for additions or updates email''' ''vel @ joomla.org'' [http://forum.joomla.org/memberlist.php?mode=viewprofile&amp;amp;u=28000 Mandville] or [http://forum.joomla.org/memberlist.php?mode=viewprofile&amp;amp;u=87230 lafrance] are the main editors&lt;br /&gt;
*If you are seeing this page on any site other than [http://docs.joomla.org/Vulnerable_Extensions_List the Offical Joomla Documentation] you may be seeing an out of date version or experiencing [http://en.wikipedia.org/wiki/Plagiarism plagiary] and the links may not work properly&lt;br /&gt;
&lt;br /&gt;
== How to use this list ==&lt;br /&gt;
'''Items will be removed after a suitable period and not on resolution'''&lt;br /&gt;
All known vulnerable extensions are the listed in the first column. Any in &amp;lt;span style=&amp;quot;background:red; color:white&amp;quot;&amp;gt;a red box &amp;lt;/span&amp;gt;are where we have not been given a fix for. Alert Advisory details in the centre column . &lt;br /&gt;
Finally a link to the notice about any &amp;lt;span style=&amp;quot;background:#cef2e0; color:black&amp;quot;&amp;gt;update with link&amp;lt;/span&amp;gt; or &amp;lt;span style=&amp;quot;background:red; color:white&amp;quot;&amp;gt;'''Not Known''' &amp;lt;/span&amp;gt; where none is known.&lt;br /&gt;
&lt;br /&gt;
'''This list is compiled from found information and may not be an up to date accurate list''' ''We do '''NOT''' promise to test or validate these reports. We do '''NOT''' guarantee the quality or effectiveness of any updates reported to us or listed here.''&lt;br /&gt;
To sign up for the feed please [http://feeds.joomla.org/JoomlaSecurityVulnerableExtensions follow this link]&lt;br /&gt;
* We do not list BETA products, or extensions for J1.0.x&lt;br /&gt;
&lt;br /&gt;
== Developers - How to get yourself removed from the VEL ==&lt;br /&gt;
&lt;br /&gt;
Resolved items will be removed after a suitable period and not on resolution&lt;br /&gt;
&lt;br /&gt;
Please solve the issues and:&lt;br /&gt;
&lt;br /&gt;
* '''If JED listed''' &lt;br /&gt;
&lt;br /&gt;
To have your extension republished, please follow these steps:&lt;br /&gt;
&lt;br /&gt;
1- Solve the issues.&lt;br /&gt;
&lt;br /&gt;
2- Attach the new zip file at your actual JED listing.&lt;br /&gt;
&lt;br /&gt;
3- Change the extension version at JED listing.&lt;br /&gt;
&lt;br /&gt;
4- Make sure to include a notice in the JED description to the fact that the new release is a &amp;quot;Security Release&amp;quot; and those who use the extension should upgrade immediately.&lt;br /&gt;
&lt;br /&gt;
5- Create a [http://bit.ly/velunlist JED listing owner ticket] to the JED with a notice and ask that your listing be republished. Include the full details of yournew version number and security notice page&lt;br /&gt;
&lt;br /&gt;
6- Email the VEL team with a notice of resolution, the latest version number '''and''' a link to the security release statement on your website&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
VEL email can be found above and the JED support link is in your notice of &amp;quot;unpublication&amp;quot; [http://extensions.joomla.org/component/maqmahelpdesk/ and here] &lt;br /&gt;
&lt;br /&gt;
* '''If not JED listed.''' &lt;br /&gt;
Inform us by '''email''' with a notice of resolution, the latest version number '''and''' a link to the security release statement on your website.&lt;br /&gt;
&lt;br /&gt;
== February 2010 and onwards Reported Vulnerable Extensions ==&lt;br /&gt;
&amp;lt;startFeed /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Please check with the extension publisher in case of any questions over the security of their product.'''&lt;br /&gt;
Report Vulnerable extensions either in the [[jforum:432]] security topic clearly marked with the first word in the title being ''Vulnerable Report'' where the security moderators or JSST team will respond or via email to the VEL team. For a guide to the [http://docs.joomla.org/Vulnerable_Extensions_List_0210#Codes_used codes]&lt;br /&gt;
*If you are seeing this page on any site other than [http://docs.joomla.org/Vulnerable_Extensions_List the Offical Joomla Documentation] you may be seeing an out of date version or experiencing [http://en.wikipedia.org/wiki/Plagiarism plagiary] and the links may not work properly&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  '''Extension'''&lt;br /&gt;
! class=&amp;quot;unsortable&amp;quot;| '''Details'''&lt;br /&gt;
!  '''Date Added'''&lt;br /&gt;
! class=&amp;quot;unsortable&amp;quot; |'''Extension Update Link &amp;amp; Date'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  Sobi   ==&lt;br /&gt;
|SQLI - &lt;br /&gt;
|130711&lt;br /&gt;
|[http://www.sigsiu.net/changelog developer fix and update statement]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  fabrik   ==&lt;br /&gt;
|sqli &lt;br /&gt;
|120711&lt;br /&gt;
|[http://fabrikar.com/downloads/details/36/89 Developers Update statement 2.1]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
==  xmap   ==&lt;br /&gt;
|sqli 1.2.11 &lt;br /&gt;
|120711&lt;br /&gt;
|upgrade to 1.2.12&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
== Atomic Gallery     ==&lt;br /&gt;
|Creates 777 folders [http://www.atomicon.nl/atomicongallery Atomic gallery] &lt;br /&gt;
|110711&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
==  myApi   ==&lt;br /&gt;
|ID [http://extensions.joomla.org/component/mtree/social-web/facebook-integration/11624 Contains &amp;quot;Call-Home&amp;quot; function. Sends private user information to developer.] &lt;br /&gt;
|020711&lt;br /&gt;
|[http://www.myapi.co.uk/ Developer states Use version 1.3.4.1]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  mdigg   ==&lt;br /&gt;
|SQL I (not listed in JED)&lt;br /&gt;
|020711&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  Calc Builder   ==&lt;br /&gt;
|sqli + ID&lt;br /&gt;
|180611&lt;br /&gt;
| [http://components.moonsoft.es/downloadcalcbuilder  dev security release 0.0.2]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
== Cool Debate    ==&lt;br /&gt;
|Cool Debate 1.03 LFI&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==     ==&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  Scriptegrator Plugin 1.5.5==&lt;br /&gt;
|LFI&lt;br /&gt;
|140611&lt;br /&gt;
| [http://www.greatjoomla.com/news/index.html  Update - Core Design Scriptegrator plugin 2.0.9 &amp;amp;] 1.5.6&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  Joomnik Gallery   ==&lt;br /&gt;
|SQLi&lt;br /&gt;
|&lt;br /&gt;
|[http://joomlacode.org/gf/project/joomnik/ developer update to 0.9.1]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  JMS fileseller   ==&lt;br /&gt;
|LFI &lt;br /&gt;
|0611&lt;br /&gt;
|[http://joommasters.com/commercial-extensions/components/jms-fileseller.html developer upgrade announcement to v1.1]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  sh404SEF   ==&lt;br /&gt;
|low-level XSS security issue&lt;br /&gt;
|300511&lt;br /&gt;
|[http://dev.anything-digital.com/Forum/Announcements/11147-sh404SEF-2.2.6-now-available-for-Joomla-1.5/ Dev upgrade statement to 2.2.6]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  JE Story submit    ==&lt;br /&gt;
|LFI/RFI &lt;br /&gt;
|&lt;br /&gt;
|[http://joomlaextensions.co.in/extensions/modules/je-content-menu.html?page=shop.product_details&amp;amp;flypage=flypage.tpl&amp;amp;product_id=77&amp;amp;category_id=13&amp;amp;vmcchk=1 developer states Version 1.8]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==   FCKeditor   ==&lt;br /&gt;
|File Upload Vulnerability&lt;br /&gt;
|230511&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
== KeyCaptcha    ==&lt;br /&gt;
|Private report under investigation&lt;br /&gt;
|190511&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  Ask A Question AddOn v1.1   ==&lt;br /&gt;
|SQLi&lt;br /&gt;
|160511&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Global Flash Gallery     ==&lt;br /&gt;
|flash-gallery.com xss &lt;br /&gt;
|130511&lt;br /&gt;
|[http://flash-gallery.com/help/joomla-extension/faq/security-update-0.5.0/ dev release 0.5.0 statement]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== com_google     ==&lt;br /&gt;
|LFI [http://freejoomlacomponent.appspot.com/ com_google]&lt;br /&gt;
|080511&lt;br /&gt;
|[http://freejoomlacomponent.appspot.com/securityrelease.html devs update to 1.5.1]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  docman   ==&lt;br /&gt;
|com-docman Input Validation Error &lt;br /&gt;
|160511&lt;br /&gt;
|[http://forum.joomla.org/viewtopic.php?p=2502904#p2502904 devs resolution statement, report for old version]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  Newsletter Subscriber    ==&lt;br /&gt;
|XSS &lt;br /&gt;
|120511&lt;br /&gt;
|[http://mavrosxristoforos.com/joomla-extensions/free/newsletter-subscriber Deveopler update]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  Akeeba   ==&lt;br /&gt;
|akkeba backup and joomlapack&lt;br /&gt;
|170411&lt;br /&gt;
|[https://www.akeebabackup.com/home/item/1091-akeeba-backup-3-2-7.html dev update to 3.2.7]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  Facebook Graph Connect   ==&lt;br /&gt;
|SID. call home device with user credentials&lt;br /&gt;
|120411&lt;br /&gt;
|[http://www.sikkimonline.info/security-notice dev update notice]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== booklibrary    ==&lt;br /&gt;
|SQLi ordasoft booklibrary&lt;br /&gt;
|180311&lt;br /&gt;
|[http://ordasoft.com/Book-Library/security-upgrade-instructions-for-book-library.html developer upgrade instructions]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
== semantic    ==&lt;br /&gt;
|com semantic http://www.scms.es/joomla creates hidden admin users &lt;br /&gt;
|150311&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
==  JOMSOCIAL 2.0.x 2.1.x   ==&lt;br /&gt;
|SID, open folders&lt;br /&gt;
|120311&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  flexicontent   ==&lt;br /&gt;
|forced 777, malicious files &lt;br /&gt;
|250311&lt;br /&gt;
|[http://www.flexicontent.org/home/item/192-flexicontent-154-is-finally-out.html devs resolve statement], [http://www.flexicontent.org/downloads/latest-version.html Changelog]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
== jLabs Google Analytics Counter     ==&lt;br /&gt;
|jLabs Google Analytics Counter  SID&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
==  xcloner   ==&lt;br /&gt;
|Unspecified&lt;br /&gt;
|260211&lt;br /&gt;
|[http://www.xcloner.com/xcloner-news/important-security-upgrade/ dev announcement of security release]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== smartformer    ==&lt;br /&gt;
|RFI&lt;br /&gt;
|230211 (repeat of 041110)&lt;br /&gt;
|[http://www.itoris.com/joomla-form-builder-smartformer.html v2.4.1 security fix for Joomla 1.5.x]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== xmap 1.2.10    ==&lt;br /&gt;
|Malicious payload in zip&lt;br /&gt;
|230211&lt;br /&gt;
|[http://joomla.vargas.co.cr/en/news/4-xmap/95-security-notice developer resolution notic]e Clean version available from [http://joomlacode.org/gf/project/xmap/frs/ joomlacode] &lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==   Frontend-User-Access 3.4.1  ==&lt;br /&gt;
|Frontend-User-Access 3.4.1 from http://www.pages-and-items.com LFI&lt;br /&gt;
|030211&lt;br /&gt;
|update to [http://extensions.joomla.org/extensions/access-a-security/frontend-access-control/6874 Frontend-User-Access 3.4.2]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  com properties 7134   ==&lt;br /&gt;
| http://com-property.com/ malicious files in script&lt;br /&gt;
|&lt;br /&gt;
|[http://joomlacode.org/gf/project/property/frs/?action=FrsReleaseBrowse&amp;amp;frs_package_id=5815 Dev update statement]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  B2 Portfolio ==&lt;br /&gt;
|B2 portfolio 1.0 SQLi pulseextensions.com&lt;br /&gt;
|250111&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  allcinevid   ==&lt;br /&gt;
|SQLI http://extensions.joomla.org/extensions/multimedia/multimedia-players/video-players-a-gallery/15367&lt;br /&gt;
|220111&lt;br /&gt;
|[http://www.joomtraders.com/our-blog/allcinevid-1.0-sql-injection.html Developers resolution notice]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
== People Component    ==&lt;br /&gt;
|People component http://www.ptt-solution.com/vmchk/people-component.html sqli&lt;br /&gt;
|150111&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==   J!Dump v1.1.2  ==&lt;br /&gt;
| LFI in J!Dump v1.1.2 and before&lt;br /&gt;
|060111&lt;br /&gt;
|The extension is fixed in &lt;br /&gt;
[http://joomlacode.org/gf/project/jdump/frs  version 1.1.3]  070111&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==   xmovie 1.0  ==&lt;br /&gt;
|xmovie 1.0 LFi&lt;br /&gt;
|010111&lt;br /&gt;
|[http://www.optikool.com/news/xmovie-news/45-xmovie-11-udpate v1.1 is a security release.] &lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  Easy File Uploader    ==&lt;br /&gt;
|LFI - http://extensions.joomla.org/extensions/core-enhancements/file-management/11909&lt;br /&gt;
|090111&lt;br /&gt;
| Fixed MIME type tamper vulnerability http://michaelgilkes.info/joomla-plugin-easy-file-uploader 2011-01-10&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  akeebabackup admin tools   ==&lt;br /&gt;
|xss&lt;br /&gt;
|181210&lt;br /&gt;
|http://www.akeebabackup.com/home/item/929-security-release-admin-tools-1-1.html devs update statement&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== aicontactsafe    ==&lt;br /&gt;
|XSS for versions 2.0.13 and below&lt;br /&gt;
|161210&lt;br /&gt;
|[http://www.algisinfo.com/joomla/aicontactsafe-change-log.html dev release 2.0.14]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  JRadio    ==&lt;br /&gt;
|JRadio LFI/SID&lt;br /&gt;
|161210&lt;br /&gt;
|http://www.fxwebdesign.nl/index.php?option=com_content&amp;amp;view=article&amp;amp;id=20&amp;amp;Itemid=56 developer fix statement&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  JE Auto   ==&lt;br /&gt;
|JE Auto 1.0 SQL I&lt;br /&gt;
|091210&lt;br /&gt;
|[http://www.joomlaextensions.co.in/extensions/components/je-auto.html developers bug fix statement]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  jxtended comments   ==&lt;br /&gt;
|xss &lt;br /&gt;
|081210&lt;br /&gt;
|[http://jxtended.com/blog/releases/375-jxtended-comments-131-stable-released.html dev notice] update to 1.3.1&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  sh404SEF   ==&lt;br /&gt;
|sqlI&lt;br /&gt;
|301110&lt;br /&gt;
|[http://dev.anything-digital.com/Blog/sh404SEF/Urgent-security-releases-now-available-for-all-version-of-sh404SEF.html dev post of resolution] &lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  JE Ajax Event Calendar   ==&lt;br /&gt;
|SQL I (relist)&lt;br /&gt;
|251110&lt;br /&gt;
|[http://joomlaextensions.co.in/extensions/components/je-ajax-event-calender.html Dev states resolved,] &lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  Jimtawl    ==&lt;br /&gt;
|Jimtawl LFI &lt;br /&gt;
|251110&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  mosets tree    ==&lt;br /&gt;
|mosets tree various &lt;br /&gt;
|181110&lt;br /&gt;
|dev release 2.1.8 http://forum.mosets.com/showthread.php?t=17064&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==   Maian Media SILVER  ==&lt;br /&gt;
|Maian Media SQLi&lt;br /&gt;
|151110&lt;br /&gt;
|Developer states unproven in free edition, paid/SILVER version is being upgraded. [http://www.aretimes.com/index.php?option=com_content&amp;amp;view=category&amp;amp;layout=blog&amp;amp;id=40&amp;amp;Itemid=113 dev article]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  alfurqan  ==&lt;br /&gt;
|alfurqan 1.5 sqli&lt;br /&gt;
|151110&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  ccboard   ==&lt;br /&gt;
|[http://extensions.joomla.org/extensions/communication/forum/6823 ccboard XSS and SQLi]&lt;br /&gt;
|131110&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==   ProDesk v 1.5  ==&lt;br /&gt;
|LFI &lt;br /&gt;
|091110&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  JQuarks 4 survey 1.0.0   ==&lt;br /&gt;
|SQLi&lt;br /&gt;
|091110&lt;br /&gt;
| [http://www.iptechinside.com/labs/projects/list_files/jquarks-for-surveys developer statement updated to version 1.0.1] 101110&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== RSform! 1.0.5    ==&lt;br /&gt;
|Multiple vulnerabilities - LFI, SQLi&lt;br /&gt;
|061110&lt;br /&gt;
| [http://www.rsjoomla.com/customer-support/documentations/12-general-overview-of-the-component/46-rsform-changelog.html developer announcement of security release]to 1.0.6 091110&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== ccinvoices    ==&lt;br /&gt;
|SQLi for [http://www.chillcreations.com/ ccinvoices]&lt;br /&gt;
|051110&lt;br /&gt;
|Developer Upgrade release to ccInvoices_110RC3 061110&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  sponsorwall   ==&lt;br /&gt;
|SQL injection pulseextensions.com&lt;br /&gt;
|011110&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==  Flip wall   ==&lt;br /&gt;
|SQL injection pulseextensions.com&lt;br /&gt;
|011110&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== K2 joomlaworks    ==&lt;br /&gt;
| http://getk2.org/ k2 xss&lt;br /&gt;
|&lt;br /&gt;
|[http://getk2.org/ version 2.4.1]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Mosets Tree 2.1.5     ==&lt;br /&gt;
|Mosets Tree http://www.mosets.com/tree/  2.1.5 LFI&lt;br /&gt;
|&lt;br /&gt;
|[http://forum.mosets.com/forumdisplay.php?f=2 developer relase statement and change log]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
== Freestyle FAQ 1.5.6     ==&lt;br /&gt;
|http://freestyle-joomla.com/fssdownloads/viewcategory/2 Freestyle FAQ 1.5.6 ‎SQL Injection&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==   JE FAQ Pro  ==&lt;br /&gt;
|[http://www.jextn.com/ Je faq pro] various reports&lt;br /&gt;
|090910&lt;br /&gt;
|[http://www.jextn.com/joomla-faq-component-extensions-downloads Developer update notice]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==   iJoomla Magazine 3.0.1  ==&lt;br /&gt;
|iJoomla Magazine 3.0.1 RFI&lt;br /&gt;
|090910&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  Clantools   ==&lt;br /&gt;
| &lt;br /&gt;
|http://www.joomla-clantools.de/downloads/doc_download/7-clantools-123.html clantool sqli&lt;br /&gt;
|090910&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  jphone   ==&lt;br /&gt;
|jphone LFI&lt;br /&gt;
|090910&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
== Gantry Framework    ==&lt;br /&gt;
|SQli injection&lt;br /&gt;
|050910&lt;br /&gt;
|[http://www.gantry-framework.org/news Update to 3.0.11]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  PicSell    ==&lt;br /&gt;
|[http://vm.xmlswf.com/index.php?option=com_content&amp;amp;view=article&amp;amp;id=104&amp;amp;Itemid=131Picsell LFD, 777]&lt;br /&gt;
|020910&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  JE FAQ Pro   ==&lt;br /&gt;
|[http://www.jextn.com/joomla-faq-component-extensions-downloads/ SID]&lt;br /&gt;
|020910&lt;br /&gt;
|[http://www.jextn.com/joomla-faq-component-extensions-downloads Developer update notice]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==   Zoom Portfolio   ==&lt;br /&gt;
|SID&lt;br /&gt;
|020910&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==   zina   ==&lt;br /&gt;
|[http://www.pancake.org/zina/ SQL Injection]&lt;br /&gt;
|020910&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  Team's   ==&lt;br /&gt;
|[http://www.joomlamo.com Teams extension] SQL Injection &lt;br /&gt;
|120810&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  Amblog    ==&lt;br /&gt;
|[http://robitbt.hu/jm/index.php?option=com_amdownloader&amp;amp;task=showfiles&amp;amp;pathid=8 Amblog] SQLi&lt;br /&gt;
|120810&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==     ==&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  Graffiti Wall   ==&lt;br /&gt;
|[http://extensions.joomla.org/extensions/extension-specific/jomsocial-extensions/13263 Graffiti Wall] for [http://www.joomplace.com/forum/jomsocial-plugins/jomsocial-plugins/graffiti-wall-permissions-777.html jomsocial silent 777]&lt;br /&gt;
|310710&lt;br /&gt;
|[http://extensions.joomla.org/extensions/extension-specific/jomsocial-extensions/13263 Dev statement 1.1 - is security release]. Folder permission was set by default as 777 that is unsecure.&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  Spielothek   ==&lt;br /&gt;
|http://extensions.joomla.org/extensions/sports-a-games/games/11017 http://www.spielban.de/ silent 0777, unknown folder creation&lt;br /&gt;
|290710&lt;br /&gt;
|Dev states version 1.7.1 resolves issues 020810&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==   Aardvertiser  ==&lt;br /&gt;
|http://extensions.joomla.org/extensions/ads-a-affiliates/classified-ads/9454 silent 0777&lt;br /&gt;
|290710&lt;br /&gt;
|[http://sourceforge.net/projects/aardvertiser/forums/forum/989030/topic/3788365 dev announces silent 0777 fixed in Version 2.1 290710]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  FW Real Estate Light    ==&lt;br /&gt;
|http://extensions.joomla.org/extensions/vertical-markets/real-estate/13376 http://www.fastw3b.net/fw-real-estate-light.html silent 777&lt;br /&gt;
|290710&lt;br /&gt;
|[http://www.fastw3b.net/fw-real-estate-light.html version 1.1 reported as fixed 777 issue]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
==     ==&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
== jDownloads    ==&lt;br /&gt;
|http://www.jdownloads.com/ and http://extensions.joomla.org/extensions/directory-a-documentation/downloads/2849 silent 0777 setting&lt;br /&gt;
|2807110&lt;br /&gt;
|1.7.4 RC3 Build 771 update on Jul 29 to remove 0777&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  TTVideo   ==&lt;br /&gt;
|[http://www.toughtomato.com TTVideo 1.0 Joomla] SQL Injection Vulnerability&lt;br /&gt;
|270710&lt;br /&gt;
|[http://www.toughtomato.com/resources/downloads/joomla-1.5/components/ttvideo/ dev updated the component to prevent this]. 280710&lt;br /&gt;
Users are no longer able to download the previous version.&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  frei-chat2.0   ==&lt;br /&gt;
|http://code.google.com/p/frei-chat/downloads/list xss vulnerability &lt;br /&gt;
|230710&lt;br /&gt;
|[http://code.google.com/p/frei-chat/downloads/list Dev announcement to fix] 2.1.2 for FreiChat [Those having CB installed]AND 1.2.2 for FreiChatPure [Extension Independent] 240710&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  QContacts    ==&lt;br /&gt;
|http://extensions.joomla.org/extensions/contacts-and-feedback/contact-details/4811 '''Version: 1.0.4 reported, current version 1.0.6'''&lt;br /&gt;
|220710&lt;br /&gt;
|Devleoper states [http://www.latenight-coding.com/news/joomla/supposed-vulnerability-qcontacts-104.html unproven report and no POC]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
== Jomtube    ==&lt;br /&gt;
|http://www.jomtube.com/ SID&lt;br /&gt;
|220710&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  mysms   ==&lt;br /&gt;
|http://www.willcodejoomlaforfood.de/ Upload Vulnerability &lt;br /&gt;
|july 10,2010&lt;br /&gt;
|290710 [http://www.willcodejoomlaforfood.de/ released the version 1.5.12.] &lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
== Rapid Recipe    ==&lt;br /&gt;
|http://www.rapid-source.com Persistent XSS Vulnerability last known fix version 1.7.2 &lt;br /&gt;
|july 10,2010&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==   Health &amp;amp; Fitness Stats   ==&lt;br /&gt;
|http://joomla-extensions.instantiate.co.uk/jcomponents/healthstats Persistent XSS Vulnerability july 10,2010 &lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==  staticxt   ==&lt;br /&gt;
|http://extensions.joomla.org/extensions/edition/custom-code-in-content/2184  no version number provided&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
==   EasyBlog  ==&lt;br /&gt;
|http://stackideas.com/products/easyblog.html xss (new report) july 10,2010&lt;br /&gt;
|&lt;br /&gt;
|[http://extensions.joomla.org/extensions/news-production/blog/12630 developer reported fix available on site ]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==   redshop light   ==&lt;br /&gt;
|http://redcomponent.com/redshop http://extensions.joomla.org/extensions/e-commerce/shopping-cart/13184 silent 777 and sqli&lt;br /&gt;
|110710&lt;br /&gt;
|[http://redcomponent.com/forum/72-redshop-light/11261-redshop-light-rc2-released-security-release Developer reported fix and upgrade to RC2]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==   quickfaq  ==&lt;br /&gt;
|http://www.schlu.net sqli&lt;br /&gt;
|090710&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==    Minify4Joomla  ==&lt;br /&gt;
|http://waltercedric.com/ LFI and xss&lt;br /&gt;
|090710&lt;br /&gt;
|No longer available to download&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==   IXXO Cart   ==&lt;br /&gt;
|http://www.php-shop-system.com/ SQLi LFI XSS Vulnerability&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
== Music Manager    ==&lt;br /&gt;
|LFI [http://danieljamesscott.org/software/4-joomla-extensions/4-music-manager.html music manager]&lt;br /&gt;
|090710&lt;br /&gt;
|[http://danieljamesscott.org/software/4-joomla-extensions/4-music-manager.html Version 0.13 released]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  PaymentsPlus   ==&lt;br /&gt;
|http://paymentsplus.com.au/ 2.1.5 Blind SQL Injection Vulnerability&lt;br /&gt;
|090710 &lt;br /&gt;
|current version 2.20, 2.1.5 not listed on dev site&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  ArtForms   ==&lt;br /&gt;
|http://joomlacode.org/gf/project/jartforms/ ArtForms 2.1b7.2 RC2 Multiple Remote Vulnerabilities&lt;br /&gt;
|090710&lt;br /&gt;
| Old beta extension &lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==    NeoRecruit  ==&lt;br /&gt;
|neojoomla.com SQL Injection &lt;br /&gt;
| neorecruit vers 1.4 060710&lt;br /&gt;
|[http://www.neojoomla.com/index.php?lang=en dev statement of fix in 1.4.1 and safe 2.0.5] &lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  autartimonial   ==&lt;br /&gt;
|autartica.be Sqli Vulnerability&lt;br /&gt;
|060710&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==   Jobs Pro  ==&lt;br /&gt;
|instantphp.com/ Sqli&lt;br /&gt;
|060710&lt;br /&gt;
|[http://www.instantphp.com/news/40-new-releases/153-jobs-133-is-published.html devs] announcement of fix 130710&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
==  JPodium   ==&lt;br /&gt;
|http://www.jpodium.de/ SQL Injection &lt;br /&gt;
|060710&lt;br /&gt;
|[http://www.jpodium.de/index.php?option=com_content&amp;amp;view=article&amp;amp;id=135:jpodium-not-vulnerable-to-sql-injection&amp;amp;catid=2:newsrotator Devs statement as to not proven]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  Front-End Article Manager System   ==&lt;br /&gt;
|http://b-elektro.no/ Upload Vulnerability&lt;br /&gt;
|040710&lt;br /&gt;
|[http://b-elektro.no/index.php dev states resolved]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
== addressbook    ==&lt;br /&gt;
|http://b-elektro.no/ Upload Vulnerability&lt;br /&gt;
|040710&lt;br /&gt;
|[http://b-elektro.no/index.php dev states resolved] &lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
==   NijnaMonials  ==&lt;br /&gt;
|http://ninjaforge.com/ Sqli Vulnerability&lt;br /&gt;
|040710&lt;br /&gt;
|070410 Discovered to be malicious/false report see [http://nekkidninjas.com/index.php/2010/07/05/there-is-no-sql-injection-vulnerability- devs notice]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
== Phoca Gallery    ==&lt;br /&gt;
|SQL I  (wrong download location in report)&lt;br /&gt;
|040710&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;| deemed malicious report&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
== socialads    ==&lt;br /&gt;
|techjoomla.com/ Xss Vulnerability &lt;br /&gt;
|040710&lt;br /&gt;
|[http://techjoomla.com/joomla-extension-news/socialads-v101-security-update-to-fix-xss-vulnerability-out.html Developers resolved statement]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
== eventcal 1.6.4    ==&lt;br /&gt;
|http://joomlacode.org/gf/project/eventcal/frs/ SQL I  last update 2006-12-31 on joomlacode&lt;br /&gt;
|040710&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
== myblog controller    ==&lt;br /&gt;
|LFI  &lt;br /&gt;
http://www.azrul.com/ &lt;br /&gt;
|010710&lt;br /&gt;
|[http://www.azrul.com/  MyBlog 3.0.332] &lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  joomanager    ==&lt;br /&gt;
|SQli Vulnerability&lt;br /&gt;
http://www.joomanager.com&lt;br /&gt;
|010710&lt;br /&gt;
|[http://www.joomanager.com/component/content/article/3-newsflash/60-joomanager-v13-stable-and-sef-plugins-released.html developer release statement] 260311&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  gamesbox   ==&lt;br /&gt;
|SQL Injection Vulnerability&lt;br /&gt;
http://www.jooforge.com/en/download/commercial/extensions/39-gamesbox&lt;br /&gt;
|010710&lt;br /&gt;
|upgrade to     1.0.10&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==   wmtpic  ==&lt;br /&gt;
|www.webmaster-tips.net various&lt;br /&gt;
|010710&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
== date converter    ==&lt;br /&gt;
|http://sourceforge.net/projects/date-converter/ sqli&lt;br /&gt;
|010710&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
== Remository    ==&lt;br /&gt;
|http://remository.com/ LFI (proc)&lt;br /&gt;
|010710&lt;br /&gt;
|Developer states not proven and possibly malicious. Unable to reproduce without proc/environ security. 260710&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==   RokBridge 1.0rc12   ==&lt;br /&gt;
|http://extensions.joomla.org/extensions/communication/forum-bridges/9012 SDI&lt;br /&gt;
|090810&lt;br /&gt;
|[http://www.rockettheme.com/extensions-updates/834-rokbridge-10rc13-released RokBridge has been updated to version 1.0rc13.] 120810&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
== real estate    ==&lt;br /&gt;
|http://www.opensourcetechnologies.com/demos/real-estate.html RFI&lt;br /&gt;
|210610&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  jomsocial   ==&lt;br /&gt;
|Version: 1.6.288 Multiple XSS&lt;br /&gt;
|210610&lt;br /&gt;
|[http://www.jomsocial.com/blog/security-patch-for-jomsocial-16x.html 1.6.291 released] 220610&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  DOCman    ==&lt;br /&gt;
|DOCman 1.5.7 DOCman 1.4.0 none specific exploit&lt;br /&gt;
|210610&lt;br /&gt;
|[http://blog.joomlatools.eu/2010/06/docman-security-announcement.html developer announcement]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
== eportfolio    ==&lt;br /&gt;
|http://www.joomplace.com/e-portfolio/e-portfolio-description.html Upload  Vulnerability&lt;br /&gt;
|200610&lt;br /&gt;
|Developer [http://www.joomplace.com/e-portfolio/e-portfolio-description.html announcement ] 270810&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  cinema   ==&lt;br /&gt;
|SQL injection&lt;br /&gt;
|190610&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==   Jreservation  ==&lt;br /&gt;
|http://jforjoomla.com/ SQLi Vulnerability&lt;br /&gt;
|190610&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  Super Messenger   ==&lt;br /&gt;
|axxis.gr xss &lt;br /&gt;
|190610&lt;br /&gt;
|[http://axxis.gr/forum/viewtopic.php?f=6&amp;amp;t=641 developer release statement 1.4.6]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==   joomdocs  ==&lt;br /&gt;
|http://joomclan.com/index.php/JoomDocs/ xss vulnerability&lt;br /&gt;
|190610&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  RSComments 1.0.0   ==&lt;br /&gt;
|Persistent XSS NOTE: ONLY executes in backend!&lt;br /&gt;
|190610&lt;br /&gt;
|[http://www.rsjoomla.com/customer-support/documentations/96--general-overview-of-the-component/393-changelog.html Developer update announcement] 210610&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==   Live Chat    ==&lt;br /&gt;
|http://www.joompolitan.com/livechat.html Multiple Remote Vulnerabilities &lt;br /&gt;
|190610&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
== Turtushout 0.11    ==&lt;br /&gt;
| http://www.turtus.org.ua/files?func=fileinfo&amp;amp;id=13 SQL Injection (again)&lt;br /&gt;
|190610&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  BF Survey Pro Free   ==&lt;br /&gt;
|BF Survey Pro Free SQL Injection Exploit &lt;br /&gt;
|190610&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  MisterEstate   ==&lt;br /&gt;
|http://www.misterestate.com/ Blind SQL Injection Exploit &lt;br /&gt;
|190610&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  RSMonials    ==&lt;br /&gt;
|http://www.rswebsols.com/downloads/category/14-download-rsmonials-all?download=23%3Adownload-rsmonials-component XSS Exploit&lt;br /&gt;
|190610&lt;br /&gt;
|Believed to be 1.5.1 version&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==  RSComments 1.0.0   ==&lt;br /&gt;
|RS Comments 1.0.0 Multiple XSS Vulnerabilities http://www.rsjoomla.com (relisted)&lt;br /&gt;
|180610&lt;br /&gt;
|[http://www.rsjoomla.com/customer-support/documentations/96--general-overview-of-the-component/393-changelog.html Developer update announcement] 210610&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  Answers v2.3beta   ==&lt;br /&gt;
|Multiple Vulnerabilities http://extensions.joomla.org/extensions/communication/forum/12652&lt;br /&gt;
|180610&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  Gallery XML 1.1   ==&lt;br /&gt;
|Multiple Vulnerabilities&lt;br /&gt;
http://extensions.joomla.org/extensions/photos-a-images/photo-gallery/12504&lt;br /&gt;
|180610&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  JFaq 1.2   ==&lt;br /&gt;
|JFaq 1.2 Multiple Vulnerabilities&lt;br /&gt;
|180610&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  Listbingo 1.3   ==&lt;br /&gt;
|Multiple Vulnerabilities&lt;br /&gt;
http://extensions.joomla.org/extensions/ads-a-affiliates/classified-ads/12062&lt;br /&gt;
|180610&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
== PowerMail Pro    ==&lt;br /&gt;
| PowerMail Pro Local File Inclusion Vulnerability&lt;br /&gt;
|&lt;br /&gt;
|[http://powermail4joomla.com/forum/showthread.php?tid=163 Dev upadte statement] 151010&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
== Alpha User Points    ==&lt;br /&gt;
|www.alphaplug.com LFI&lt;br /&gt;
|180610&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  Magic Updater   ==&lt;br /&gt;
|http://software.realtyna.com/ RFI&lt;br /&gt;
|170610&lt;br /&gt;
|[http://software.realtyna.com/component/content/article/64-security-patch-for-magic-updater-and-translator.html] developer update statement&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==   recruitmentmanager  ==&lt;br /&gt;
|http://recruitment.focusdev.co.uk Upload Vulnerability&lt;br /&gt;
|130610&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  Info Line (MT_ILine)    ==&lt;br /&gt;
|http://extensions.joomla.org/extensions/news-display/news-tickers-a-scrollers/8425 reports of shell scripts in download file&lt;br /&gt;
|120610&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  Search Log   ==&lt;br /&gt;
|http://www.kanich.net/radio/site/searchlog/searchlog-download SQLi&lt;br /&gt;
|080610&lt;br /&gt;
|[http://www.kanich.net/radio/site/searchlog/searchlog-download Developer cited update to version 3.1.1 100710]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
==  iJoobi   ==&lt;br /&gt;
|jtickets, jsubscription SQL Injection Vulnerability, &lt;br /&gt;
jstore SQL Injection Vulnerability, jnewsletter SQL Injection, jmarket SQL Injection Vulnerability, jcommunity SQL Injection, jsubscription SQL Injection,   &lt;br /&gt;
|090610&lt;br /&gt;
|developer states unproven&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  Ads manager  Annonce   ==&lt;br /&gt;
|http://joomla.clubnautiquemarine.fr/ &lt;br /&gt;
Upload Vulnerability&lt;br /&gt;
| 05/06/10&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  lead article    ==&lt;br /&gt;
|http://www.leadya.co.il/ SQLi&lt;br /&gt;
|050610&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  djartgallery   ==&lt;br /&gt;
|http://www.design-joomla.eu Multiple Vul&lt;br /&gt;
|05/06/10&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
== Gallery 2 Bridge    ==&lt;br /&gt;
|[http://trac.4theweb.nl/g2bridge g2bridge] LFI vulnerability&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  jsjobs   ==&lt;br /&gt;
|[http://www.joomsky.com jsjobs] SQL Injection Vulnerability&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
==     ==&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==   JE Poll  ==&lt;br /&gt;
|http://slideshow.joomlaextensions.co.in/ SQL Injection Vulnerability&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  MyCar   ==&lt;br /&gt;
|http://www.unisoft.me/extensions/ sqli ID&lt;br /&gt;
|&lt;br /&gt;
|[http://www.unisoft.me/mycar/index.php?option=com_smallchat&amp;amp;Itemid=5 Dev announcement update to 1.1]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  MediQnA   ==&lt;br /&gt;
|MediQnA LFI vulnerability version : v1.1&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==   JE Job  ==&lt;br /&gt;
|http://joomlaextensions.co.in/ LFI SQLi&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  BF Quiz   ==&lt;br /&gt;
|SQL Injection Exploit Version(s) = 1.3.0&lt;br /&gt;
|&lt;br /&gt;
|[http://www.tamlyncreative.com.au/software/forum/index.php?topic=729.0 Developer update to BF Quiz v1.3.1]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
==     ==&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==   Ozio Gallery 2  ==&lt;br /&gt;
|DT and open email relay&lt;br /&gt;
|280510&lt;br /&gt;
|[http://oziogallery.joomla.it/index.php?option=com_content&amp;amp;view=article&amp;amp;id=65:rilasciata-la-versione-ozio-gallery-25&amp;amp;catid=2:notizie&amp;amp;Itemid=13&amp;amp;lang=en Developer update and security release] 010610&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  SectionEx   ==&lt;br /&gt;
|Stack Ideas section Ex LFI&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  ActiveHelper LiveHelp    ==&lt;br /&gt;
|XSS in [http://extensions.joomla.org/extensions/communication/chat/12492 LiveHelp] &lt;br /&gt;
|200510&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
==  RS Comments   ==&lt;br /&gt;
|XSS Vulnerability &lt;br /&gt;
|&lt;br /&gt;
|[http://www.rsjoomla.com/customer-support/documentations/96--general-overview-of-the-component/393-changelog.html - fix posted 210510]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
==  BCA RSS Feed   ==&lt;br /&gt;
|LFI and other vulnerabilities&lt;br /&gt;
|&lt;br /&gt;
|Upgrade to [http://ninjaforge.com/index.php?option=com_ninjacentral&amp;amp;page=show_package&amp;amp;id=74&amp;amp;Itemid=236 Ninja RSS Syndicator 1.0.9 or later]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
== SimpleDownload    ==&lt;br /&gt;
|http://extensions.joomla.org/extensions/directory-a-documentation/downloads/10717 various exploits&lt;br /&gt;
|160510&lt;br /&gt;
|updated version (version 0.9.6)&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
==  JE Quotation Form   ==&lt;br /&gt;
|http://joomlaextensions.co.in/free-download/doc_download/11-je-quotation-form.html  LFI&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  konsultasi   ==&lt;br /&gt;
|SQL Injection Vulnerability&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
== Aardvertiser    ==&lt;br /&gt;
|Local File Inclusion Vulnerability	&lt;br /&gt;
http://extensions.joomla.org/extensions/ads-a-affiliates/classified-ads/9454&lt;br /&gt;
|&lt;br /&gt;
|see [http://docs.joomla.org/Vulnerable_Extensions_List#Aardvertiser resolved notice 040810]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  Seber Cart    ==&lt;br /&gt;
|Local File Disclosure Vulnerability&lt;br /&gt;
|&lt;br /&gt;
|[http://www.sebercart.com/index.php?option=com_content&amp;amp;view=article&amp;amp;id=158 Developer Update 140510]&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  FDione Form Wizard   ==&lt;br /&gt;
|lfi vulnerability	&lt;br /&gt;
|140510 200510&lt;br /&gt;
|[http://dionesoft.com Update to Dione Form Wizard (v. 1.0.4)].&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==   Custom PHP Pages  ==&lt;br /&gt;
|http://extensions.joomla.org/extensions/edition/custom-code-in-content/5057 LFI Vulnerability		&lt;br /&gt;
|&lt;br /&gt;
|[http://fijiwebdesign.com Developer declares not vulnerable 140510]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |&lt;br /&gt;
&lt;br /&gt;
==  Camp26 Visitor    ==&lt;br /&gt;
|RFI www.camp26.biz&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==    iJoomla News Portal  ==&lt;br /&gt;
|RFI SID&lt;br /&gt;
|&lt;br /&gt;
|[http://www.ijoomla.com/forum/index.php/topic,4480.0.html Update to 1.5.10]&lt;br /&gt;
|-&lt;br /&gt;
|  &lt;br /&gt;
==  article Factory Manager   ==&lt;br /&gt;
|RFI &amp;amp; Input Validation Error http://www.thefactory.ro/shop/joomla-components/article-manager.html&lt;br /&gt;
|may 2010&lt;br /&gt;
|can not reproduce and unproven, http://www.thefactory.ro&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  Table JX Component    ==&lt;br /&gt;
|http://www.toolsjx.com/ Table JX Component XSS&lt;br /&gt;
|060510 - update 130510&lt;br /&gt;
|Version: 1.5.5 considered unsafe, [http://www.toolsjx.com update to 1.5.7]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |&lt;br /&gt;
&lt;br /&gt;
==   JE Property  ==&lt;br /&gt;
|JE Property Finder Upload Vulnerability&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |&lt;br /&gt;
&lt;br /&gt;
==   Noticeboard  ==&lt;br /&gt;
|Noticeboard for Joomla &amp;quot;controller&amp;quot; Local File Inclusion Vulnerability&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |&lt;br /&gt;
&lt;br /&gt;
==SmartSite     ==&lt;br /&gt;
|SmartSite com_smartsite Local File Inclusion Vulnerability &lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   |&lt;br /&gt;
&lt;br /&gt;
==  ABC    ==&lt;br /&gt;
|ABC SQL Injection Vulnerability&lt;br /&gt;
|&lt;br /&gt;
|reported as updated to JED 290410&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |&lt;br /&gt;
&lt;br /&gt;
==  htmlcoderhelper graphics   ==&lt;br /&gt;
|htmlcoderhelper graphics v1.0.6 LFI Vulnerability&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |&lt;br /&gt;
&lt;br /&gt;
== Ultimate Portfolio    ==&lt;br /&gt;
|Ultimate Portfolio  Local File Inclusion Vulnerability&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   |&lt;br /&gt;
&lt;br /&gt;
==  huruhelpdesk   ==&lt;br /&gt;
|http://www.huruhelpdesk.net sqli injection &lt;br /&gt;
|&lt;br /&gt;
|[http://www.huruhelpdesk.net/forums/8-announcements/392--sql-injection-reveals-user-md5-password-hash Reported fix]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |&lt;br /&gt;
&lt;br /&gt;
==  Archery Scores   ==&lt;br /&gt;
| [http://lispeltuut.org/ Archery Scores (com_archeryscores) v1.0.6 LFI Vulnerability]&lt;br /&gt;
&lt;br /&gt;
|210410&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |&lt;br /&gt;
&lt;br /&gt;
==  ZiMB Manager   ==&lt;br /&gt;
|Joomla Component ZiMB Manager Local File Inclusion Vulnerability&lt;br /&gt;
|210410&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |&lt;br /&gt;
&lt;br /&gt;
==  Matamko   ==&lt;br /&gt;
|Matamko Local File Inclusion Vulnerability&lt;br /&gt;
|210410&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |&lt;br /&gt;
&lt;br /&gt;
==  Multiple Root   ==&lt;br /&gt;
|Multiple Root Local File Inclusion Vulnerability http://joomlacomponent.inetlanka.com/&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |&lt;br /&gt;
&lt;br /&gt;
==  Multiple Map   ==&lt;br /&gt;
|Multiple Map Local File Inclusion Vulnerability joomlacomponent.inetlanka.com&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |&lt;br /&gt;
&lt;br /&gt;
==   Contact Us Draw Root Map  ==&lt;br /&gt;
|Draw Root Map Local File Inclusion Vulnerability joomlacomponent.inetlanka.com&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |&lt;br /&gt;
&lt;br /&gt;
==  iF surfALERT   ==&lt;br /&gt;
|[http://www.inertialfate.za.net/ iF surfALERT] Local File Inclusion Vulnerability&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |&lt;br /&gt;
&lt;br /&gt;
==   GBU FACEBOOK  ==&lt;br /&gt;
|GBU FACEBOOK SQL injection vulnerability http://www.gbugrafici.nl/gbufacebook/&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |&lt;br /&gt;
&lt;br /&gt;
==   jnewspaper  ==&lt;br /&gt;
|jnewspaper (cid) SQL Injection Vulnerability&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  JTM Reseller   ==&lt;br /&gt;
|TM Reseller SQL injection vulnerability&lt;br /&gt;
|&lt;br /&gt;
|[http://jtmreseller.com/ Developer Update] &lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   |&lt;br /&gt;
&lt;br /&gt;
==  media Mall Factory   ==&lt;br /&gt;
|SQLi&lt;br /&gt;
|200410&lt;br /&gt;
| [http://www.thefactory.ro/contact-us/product-update-request.html Solution: update to 1.0.5] &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==   Gadget Factory  ==&lt;br /&gt;
|LFi&lt;br /&gt;
|200410&lt;br /&gt;
|[http://www.thefactory.ro/contact-us/product-update-request.html Solution: update to 1.5.1]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  Deluxe Blog Factory   ==&lt;br /&gt;
|SQLi&lt;br /&gt;
|200410&lt;br /&gt;
|[http://www.thefactory.ro/contact-us/product-update-request.html update to 1.1.2]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
==     ==&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |&lt;br /&gt;
== MT Fire Eagle ==&lt;br /&gt;
&lt;br /&gt;
|LFI http://joomlacode.org/gf/project/jfireeagle/frs/ http://www.moto-treks.com&lt;br /&gt;
| 190410&lt;br /&gt;
| product considered retired and to be replaced by dev&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
==  com properties   ==&lt;br /&gt;
| http://com-property.com/ SQL I&lt;br /&gt;
|&lt;br /&gt;
|[http://www.com-property.com/images/fbfiles/files/properties-20100413.txt developer announced fix]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  Sweetykeeper   ==&lt;br /&gt;
|Sweetykeeper Local File Inclusion Vulnerability  http://www.joomlacorner.com/&lt;br /&gt;
|120410&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  jvehicles   ==&lt;br /&gt;
|SQL Injection http://jvehicles.com&lt;br /&gt;
|120410&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  worldrates   ==&lt;br /&gt;
|http://dev.pucit.edu.pk/&lt;br /&gt;
|120410&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  cvmaker   ==&lt;br /&gt;
|http://dev.pucit.edu.pk/&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  advertising   ==&lt;br /&gt;
|http://dev.pucit.edu.pk/&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==   horoscope  ==&lt;br /&gt;
|http://dev.pucit.edu.pk/&lt;br /&gt;
|120410&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==   webtv  ==&lt;br /&gt;
|http://dev.pucit.edu.pk/&lt;br /&gt;
|120410&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  diary   ==&lt;br /&gt;
|http://dev.pucit.edu.pk/&lt;br /&gt;
|120410&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==   Multi-Venue Restaurant Menu Manager (MVRMM)  ==&lt;br /&gt;
|http://www.focusdev.co.uk/ &lt;br /&gt;
|120410 &lt;br /&gt;
||[http://extensions.joomla.org/extensions/vertical-markets/food-a-beverage/10015 Version 1.5.2 Stable Update 4]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  Memory Book   ==&lt;br /&gt;
|http://dev.pucit.edu.pk/&lt;br /&gt;
|120410&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==   TRAVELbook  ==&lt;br /&gt;
| http://www.demo-page.de/&lt;br /&gt;
|120410&lt;br /&gt;
|[http://www.demo-page.de/de/erweiterungen-mehr-inhalte/travelbook/download.html developers resolution notice 1.0.2]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
== AlphaUserPoints    ==&lt;br /&gt;
|&lt;br /&gt;
|[http://www.alphaplug.com/index.php/downloads.html?func=fileinfo&amp;amp;id=31 developer upgrade]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  JprojectMan   ==&lt;br /&gt;
|LFI http://extensions.joomla.org/extensions/communities-a-groupware/project-a-task-management/5676&lt;br /&gt;
|110410&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==   CKForms  ==&lt;br /&gt;
|1.3.4 release - Important LFI security fix [http://joomlacode.org/gf/project/ckforms/news/?action=NewsThreadView&amp;amp;id=2814 ]&lt;br /&gt;
|07-04-10 &lt;br /&gt;
|[http://ckforms.cookex.eu/download/download.php upgrade]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==   econtentsite  ==&lt;br /&gt;
|LFI&lt;br /&gt;
|040410&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==    Jvehicles ==&lt;br /&gt;
|ID&lt;br /&gt;
|040410&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
==     ==&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  smestorage   ==&lt;br /&gt;
|[http://www.smestorage.com SMEStorage] LFI&lt;br /&gt;
&lt;br /&gt;
|Updated 29 March 10&lt;br /&gt;
|[http://gelembjuk.com/index.php?option=com_content&amp;amp;view=section&amp;amp;layout=blog&amp;amp;id=1&amp;amp;Itemid=55 developer fix] to 1.1&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  JE Tooltip   ==&lt;br /&gt;
|[http://joomlaextensions.co.in/formcreator/ JE Tooltip] LFI&lt;br /&gt;
|Updated 23 March &lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  Gift Exchange Beta   ==&lt;br /&gt;
|[http://extensions.joomla.org/extensions/communities-a-groupware/membership/11680 Gift exchange] SQLi&lt;br /&gt;
|Updated 23 March &lt;br /&gt;
|[http://socialables.com/28-Jomsocial/Gift-Exchange/flypage.tpl.html upgrade beta 1.0.1]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  RokDownloads  ==&lt;br /&gt;
|[[http://extensions.joomla.org/extensions/directory-a-documentation/downloads/7967 LFI]] &lt;br /&gt;
|15 march 2010&lt;br /&gt;
||upgrade to [http://www.rockettheme.com/extensions-updates/638-rokdownloads-10-released version 1.0]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==    gigcalender   ==&lt;br /&gt;
&lt;br /&gt;
|SQLi [http://extensions.joomla.org/extensions/calendars-a-events/events/97)http://extensions.joomla.org/extensions/calendars-a-events/events/97 gigcalender]&lt;br /&gt;
|13 march 2010&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==    heza content   ==&lt;br /&gt;
|SQLi [http://extensions.joomla.org/extensions/structure-a-navigation/sections-a-categories/10427)http://extensions.joomla.org/extensions/structure-a-navigation/sections-a-categories/10427  heza content]&lt;br /&gt;
|13 march 2010&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==   juliaportfolio   ==&lt;br /&gt;
|LFI [http://extensions.joomla.org/extensions/directory-&amp;amp;-documentation/portfolio/8519/details juliaportfolio]&lt;br /&gt;
|13 march 2010&lt;br /&gt;
|[http://www.treidorinte.ro/joomla-extensions/19-joomla-components/467-juliaportfolio-security-upgrade-required withdrawal and update notice]&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  Flash Magazine Deluxe   ==&lt;br /&gt;
|SQL Injection Vulnerability.&lt;br /&gt;
|Feb 25&lt;br /&gt;
|'''[http://www.joomplace.com/flash-magazine-deluxe/flash-magazine-deluxe-description.html Developer Update Version 2.0.11 09/03/10]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  SqlReport   ==&lt;br /&gt;
|Sqlreport has a sql/RFI exploit. awaiting confirmation on exact developer.&lt;br /&gt;
|Feb 20&lt;br /&gt;
|'''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  Scriptegrator   ==&lt;br /&gt;
|Core Design [http://www.greatjoomla.com/extensions/plugins/core-design-scriptegrator-plugin.html Scriptegrator] RFI exploit&lt;br /&gt;
|Feb 20&lt;br /&gt;
|[http://www.greatjoomla.com/extensions/plugins/core-design-scriptegrator-plugin.html Dev Upgrade announcement]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  AllVideos 3.1  ==&lt;br /&gt;
|&lt;br /&gt;
A vulnerability discovered in versions 3.0. and 3.1 of the plugin can be exploited by malicious people to disclose potentially sensitive information. For security reasons we will not be providing further details to safeguard users of affected versions. http://www.joomlaworks.gr/content/view/77/34/]|&lt;br /&gt;
|17 Feb&lt;br /&gt;
| [http://joomlaworks.googlecode.com/files/plg_jw_allvideos-v3.3_j1.5.zip Version 3.3 release 18th]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  RW Cards   ==&lt;br /&gt;
| [http://extensions.joomla.org/extensions/3430/details RW Card] LFI and ID exploit [http://www.weberr.de/ Dev Site]&lt;br /&gt;
|180210&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |'''  [http://www.weberr.de/index.php/forum.html?func=view&amp;amp;catid=5&amp;amp;id=1939&amp;amp;limit=6 developer update]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Yelp ==&lt;br /&gt;
| SQLi - Unable to locate developer. Possibly a custom extension.&lt;br /&gt;
|Feb 01 &lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  '''Autartitarot'''   ==&lt;br /&gt;
|Directory Traversal. Back end access required&lt;br /&gt;
| Feb 05&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; | ''' Please upgrade to [http://www.autartica.be/en/autartitarot version 1.0.4]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  communitypolls   ==&lt;br /&gt;
|LFI - [http://www.corejoomla.com/ community polls] &lt;br /&gt;
|Feb 17&lt;br /&gt;
||upgrade to [http://www.corejoomla.com/ version 1.5.3]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
==     ==&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;endFeed /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''This list is change protected, for updates or additions [http://forum.joomla.org/memberlist.php?mode=viewprofile&amp;amp;u=28000 Mandville] or [http://forum.joomla.org/memberlist.php?mode=viewprofile&amp;amp;u=87230 lafrance]&lt;br /&gt;
''&lt;br /&gt;
&lt;br /&gt;
== Codes used ==&lt;br /&gt;
SQLi - SQL injection [http://en.wikipedia.org/wiki/Code_injection#SQL_injection wikipedia]&lt;br /&gt;
&lt;br /&gt;
LFI - Local File Inclusion [http://www.scribd.com/doc/6498408/Remote-and-Local-File-Inclusion-Explained scribd]&lt;br /&gt;
&lt;br /&gt;
RFI - Remote file inclusion [http://en.wikipedia.org/wiki/Remote_File_Inclusion wikipedia]&lt;br /&gt;
&lt;br /&gt;
DT - Directory Traversal [http://en.wikipedia.org/wiki/Directory_traversal wikipedia]&lt;br /&gt;
&lt;br /&gt;
ID = Information Disclosure: account information or sensitive information publicly viewable&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Future Actions &amp;amp; WIP ==&lt;br /&gt;
&lt;br /&gt;
[http://feeds.joomla.org/JoomlaSecurityVulnerableExtensions RSS feed] completed&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
to feed VEL direct to twitter&lt;br /&gt;
&lt;br /&gt;
== Notes ==&lt;br /&gt;
The RSS feed is currently fed by item entry order and not by date fixed. &lt;br /&gt;
List as discussed in  [[jtopic:455746]] by [http://forum.joomla.org/memberlist.php?mode=viewprofile&amp;amp;u=67439 PhilD] editing by [http://forum.joomla.org/memberlist.php?mode=viewprofile&amp;amp;u=28000 Mandville]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
[[Category:Security]]&lt;br /&gt;
[[Category:Security_FAQ]]&lt;br /&gt;
[[Category:Component Management]]&lt;br /&gt;
----&lt;/div&gt;</summary>
		<author><name>CirTap</name></author>	</entry>

	<entry>
		<id>http://docs.joomla.org/Vulnerable_Extensions_List/Archive/2009-10</id>
		<title>Vulnerable Extensions List/Archive/2009-10</title>
		<link rel="alternate" type="text/html" href="http://docs.joomla.org/Vulnerable_Extensions_List/Archive/2009-10"/>
				<updated>2011-07-15T12:32:52Z</updated>
		
		<summary type="html">&lt;p&gt;CirTap: moved Vulnerable Extensions List/Archive/2009-10 to Archived vel over redirect&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;#REDIRECT [[Archived vel]]&lt;/div&gt;</summary>
		<author><name>CirTap</name></author>	</entry>

	<entry>
		<id>http://docs.joomla.org/Archived_vel</id>
		<title>Archived vel</title>
		<link rel="alternate" type="text/html" href="http://docs.joomla.org/Archived_vel"/>
				<updated>2011-07-15T12:32:52Z</updated>
		
		<summary type="html">&lt;p&gt;CirTap: moved Vulnerable Extensions List/Archive/2009-10 to Archived vel over redirect&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{RightTOC}}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  '''Extension'''&lt;br /&gt;
! class=&amp;quot;unsortable&amp;quot;| '''Details'''&lt;br /&gt;
!  '''Reference Link'''&lt;br /&gt;
!  '''Extension Update Link'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''com_ajaxchat'''&lt;br /&gt;
|  Summary: PHP remote file inclusion vulnerability in Fiji Web Design Ajax Chat ('''com_ajaxchat''') component 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[mosConfig_absolute_path] parameter to tests/ajcuser.php.New version release December 22,2009&lt;br /&gt;
Published: october 28 2009&lt;br /&gt;
|  [[NIST:CVE-2009-3822|CVE-2009-3822]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | [http://extensions.joomla.org/extensions/communication/chat/10767 update v 1.1]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''com_booklibrary'''&lt;br /&gt;
|  PHP remote file inclusion vulnerability in doc/releasenote.php in the BookLibrary ('''com_booklibrary''') component 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter, a different vector than [[NIST:CVE-2009-2637|CVE-2009-2637]]. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 10/28/2009&lt;br /&gt;
CVSS Severity: 7.5 (HIGH)&lt;br /&gt;
|  [[NIST:CVE-2009-3817|CVE-2009-3817]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''[http://ordasoft.com/Download/Joomla1.0-extensions/Joomla1.0-components/View-category.html developer site updates]'''&lt;br /&gt;
|-&lt;br /&gt;
|   style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''com_foobla_suggestions'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the foobla Suggestions ('''com_foobla_suggestions''') component 1.5.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the idea_id parameter to index.php.&lt;br /&gt;
Published: 10/11/2009&lt;br /&gt;
CVSS Severity: 7.5 (HIGH)&lt;br /&gt;
|  [[NIST:CVE-2009-3669|CVE-2009-3669]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | [http://foobla.com/news/latest/fixed-foobla-suggestions-for-joomla-idea_id-sql-injection-vulnerability.html developer reported upgrade]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_djcatalog'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the DJ-Catalog ('''com_djcatalog''') component for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a showItem action and (2) cid parameter in a show action to index.php.&lt;br /&gt;
Published: 10/11/2009&lt;br /&gt;
CVSS Severity: 6.8 (MEDIUM)&lt;br /&gt;
|  [[NIST:CVE-2009-3661|CVE-2009-3661]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''com_cbresumebuilder'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the JoomlaCache CB Resume Builder (''''''com_cbresumebuilder''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the group_id parameter in a group_members action to index.php.&lt;br /&gt;
Published: 10/09/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3645|CVE-2009-3645]] &lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |'''[http://www.joomlacache.com/commercial-extensions/security-update.html Developer Update]'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  |  '''com_soundset'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Soundset ('''com_soundset''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter to index.php.&lt;br /&gt;
Published: 10/09/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3644|CVE-2009-3644]]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  |  '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  |'''com_sportfusion'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Kinfusion SportFusion ('''com_sportfusion''') component 0.2.2 through 0.2.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid[0] parameter in a teamdetail action to index.php.&lt;br /&gt;
Published: 09/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3491|CVE-2009-3491]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  |'''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_icrmbasic'''&lt;br /&gt;
|  Summary: A certain interface in the iCRM Basic ('''com_icrmbasic''') component 1.4.2.31 for Joomla! does not require administrative authentication, which has unspecified impact and remote attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 09/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3481|CVE-2009-3481]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_mytube'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the MyRemote Video Gallery ('''com_mytube''') component 1.0 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter in a videos action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3446|CVE-2009-3446]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_fastball'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Fastball ('''com_fastball''') component 1.1.0 through 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the league parameter to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3443|CVE-2009-3443]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | [http://www.fastballproductions.com   latest version] 1.2.1 &lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_facebook'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the JoomlaFacebook ('''com_facebook''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a student action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3438|CVE-2009-3438]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_tupinambis'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Tupinambis ('''com_tupinambis''') component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the proyecto parameter in a verproyecto action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3434|CVE-2009-3434]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''com_idoblog'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the IDoBlog ('''com_idoblog''') component 1.1 build 30 for Joomla! allows remote attackers to execute arbitrary SQL commands via the userid parameter in a profile action to index.php, a different vector than [[NIST:CVE-2008-2627|CVE-2008-2627]].&lt;br /&gt;
Published: 09/25/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3417|CVE-2009-3417]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot; |'''[http://idojoomla.com/download.html/ '''New Version v 1.1''' (build 32)]'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_hbssearch'''&lt;br /&gt;
|  Summary: Cross-site scripting ('''XSS''') vulnerability in the Hotel Booking Reservation System ('''aka HBS or com_hbssearch''') component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the adult parameter in a showhoteldetails action to index.php.&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 4.3 ('''MEDIUM''')&lt;br /&gt;
|  [[NIST:CVE-2009-3368|CVE-2009-3368]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_hbssearch'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System ('''aka HBS or com_hbssearch''') component for Joomla! allow remote attackers to execute arbitrary SQL commands via the ('''1''') h_id, ('''2''') id, and ('''3''') rid parameters to longDesc.php, and the h_id parameter to ('''4''') detail.php, ('''5''') detail1.php, ('''6''') detail2.php, ('''7''') detail3.php, ('''8''') detail4.php, ('''9''') detail5.php, ('''10''') detail6.php, ('''11''') detail7.php, and ('''12''') detail8.php, different vectors than [[NIST:CVE-2008-5865|CVE-2008-5865]], [[NIST:CVE-2008-5874|CVE-2008-5874]], and [[NIST:CVE-2008-5875|CVE-2008-5875]].&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3357|CVE-2009-3357]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''com_alphauserpoints'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in frontend/assets/ajax/checkusername.php in the AlphaUserPoints ('''com_alphauserpoints''') component 1.5.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the username2points parameter.&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3342|CVE-2009-3342]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |'''[http://www.alphaplug.com/index.php/news/142-alphauserpoints-153-released.html 1.5.3]'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''TurtuShout'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the TurtuShout component 0.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Name field.&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3335|CVE-2009-3335]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jinc'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Lhacky! Extensions Cave Joomla! Integrated Newsletters Component ('''aka JINC or com_jinc''') component 0.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a messages action to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3334|CVE-2009-3334]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''com_jbudgetsmagic'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the JBudgetsMagic ('''com_jbudgetsmagic''') component 0.3.2 through 0.4.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the bid parameter in a mybudget action to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3332|CVE-2009-3332]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | '''[http://sopinet.com/jbudgetsmagic/index.php?option=com_remository&amp;amp;Itemid=5&amp;amp;lang=en Update to 0.4.1]'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_surveymanager'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Focusplus Developments Survey Manager ('''com_surveymanager''') component 1.5.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the stype parameter in an editsurvey action to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3325|CVE-2009-3325]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_album'''&lt;br /&gt;
|  Summary: Directory traversal vulnerability in the Roland Breedveld Album ('''com_album''') component 1.14 for Joomla! allows remote attackers to access arbitrary directories and have unspecified other impact via a .. ('''dot dot''') in the target parameter to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3318|CVE-2009-3318]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;   | '''com_jreservation'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the [http://extensions.joomla.org/extensions/vertical-markets/booking-a-reservation/9798 JReservation] ('''com_jreservation''') component 1.0 and 1.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a propertycpanel action to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3316|CVE-2009-3316]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot; |  [http://www.jforjoomla.com Updated 28th] Jan fixed 13th Nov&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''IXXO Cart Standalone'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in IXXO Cart Standalone before 3.9.6.1, and the IXXO Cart component for Joomla! 1.0.x, allows remote attackers to execute arbitrary SQL commands via the parent parameter.&lt;br /&gt;
Published: 09/16/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3215|CVE-2009-3215]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_digifolio'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the DigiFolio ('''com_digifolio''') component 1.52 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a project action to index.php.&lt;br /&gt;
Published: 09/15/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3193|CVE-2009-3193]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_aclassf'''&lt;br /&gt;
|  Summary: Cross-site scripting ('''XSS''') vulnerability in '''gmap.php''' in the Almond Classifieds ('''com_aclassf''') component 7.5 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the addr parameter.&lt;br /&gt;
Published: 09/10/2009&lt;br /&gt;
CVSS Severity: 4.3 ('''MEDIUM''')&lt;br /&gt;
|  [[NIST:CVE-2009-3155|CVE-2009-3155]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;   | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''com_aclassf'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Almond Classifieds ('''com_aclassf''') component 7.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the replid parameter in a manw_repl add_form action to index.php, a different vector than [[NIST:CVE-2009-2567|CVE-2009-2567]].&lt;br /&gt;
Published: 09/10/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3154|CVE-2009-3154]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | [http://www.almondsoft.com/alcl.html Developer latest component]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jabode'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in Jabode horoscope extension ('''com_jabode''') for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a sign task to index.php.&lt;br /&gt;
Published: 09/08/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
&lt;br /&gt;
|  [[NIST:CVE-2008-7169|CVE-2008-7169]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_gameserver'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Game Server ('''com_gameserver''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a gamepanel action to index.php.&lt;br /&gt;
Published: 09/03/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3063|CVE-2009-3063]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_artportal'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Artetics.com Art Portal ('''com_artportal''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the portalid parameter to index.php.&lt;br /&gt;
Published: 09/03/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3054|CVE-2009-3054]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:#cef2e0; color:black&amp;quot; | '''com_agora'''&lt;br /&gt;
|  Summary: Directory traversal vulnerability in the Agora ('''com_agora''') component 3.0.0b for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the action parameter to the avatars page, reachable through index.php.&lt;br /&gt;
Published: 09/03/2009&lt;br /&gt;
CVSS Severity: 6.8 ('''MEDIUM''')&lt;br /&gt;
|  [[NIST:CVE-2009-3053|CVE-2009-3053]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot; |'''[http://jvitals.com/index.php?option=com_rokdownloads&amp;amp;view=file&amp;amp;Itemid=108&amp;amp;id=282:agora-3-0 3.0.7]'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_simpleshop'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Simple Shop Galore ('''com_simpleshop''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the section parameter in a section action to index.php, a different vulnerability than [[NIST:CVE-2008-2568|CVE-2008-2568]]. NOTE: this issue was disclosed by an unreliable researcher, so the details might be incorrect.&lt;br /&gt;
Published: 08/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-7033|CVE-2008-7033]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_groups'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Permis ('''com_groups''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a list action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 08/17/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-2789|CVE-2009-2789]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:#cef2e0; color:black&amp;quot; | '''com_content'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the content component ('''com_content''') 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a blogcategory action to index.php.&lt;br /&gt;
Published: 08/10/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6923|CVE-2008-6923]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |'''[http://developer.joomla.org/security/news/305-20091103-core-front-end-editor-issue-.html Resolution]'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Live Chat ('''com_livechat''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the last parameter to getChatRoom.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6883|CVE-2008-6883]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: Live Chat ('''com_livechat''') component 1.0 for Joomla! allows remote attackers to use the xmlhttp.php script as an open HTTP proxy to hide network scanning activities or scan internal networks via a GET request with a full URL in the query string.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6882|CVE-2008-6882]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the Live Chat ('''com_livechat''') component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the last parameter to ('''1''') getChat.php, ('''2''') getChatRoom.php, and ('''3''') getSavedChatRooms.php.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6881|CVE-2008-6881]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''JUMI'''&lt;br /&gt;
|  There is a backdoor in JUMI that installs itself when JUMI is installed on your web site. It sends your credentials to a website, and sets up a back door for remote code execution.&lt;br /&gt;
Please remove JUMI2.0.5 immediately. &lt;br /&gt;
It will be simple enough to remove the compromised code from this download, but you need to do &lt;br /&gt;
a full security audit on your site as well as you have been compromised. Added November 2009&lt;br /&gt;
|  [http://code.google.com/p/jumi/updates/list Report]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |[http://code.google.com/p/jumi/updates/list Jumi Update]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''com_photoblog'''&lt;br /&gt;
|  Input Validation Error Added November 2009&lt;br /&gt;
|  [http://www.securityfocus.com/bid/36809/ 36809]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |[http://webguerilla.net/downloads/3-components-for-joomla-1 webguerilla Photoblog alpha 3b]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jshop'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the JShop ('''com_jshop''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a product action to index.php.&lt;br /&gt;
Published: 11/02/2009&lt;br /&gt;
CVSS Severity: 7.5 '''(HIGH)''' &lt;br /&gt;
|  [[NIST:CVE-2009-3835|CVE-2009-3835]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot; |'''BF Survey Pro'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the '''BF Survey Pro''' v1.2.5 or lower  (fixed in version 1.2.6). '''BF Survey Basic v1.0''' (fixed in version 1.1). '''BF Quiz v1.1.1''' (fixed in version 1.2 or greater) Added November 2009&lt;br /&gt;
|  [http://www.tamlyncreative.com.au/software/forum/index.php?topic=357.0 tamlyncreative.com.au]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |[http://www.tamlyncreative.com.au/software/forum/index.php?topic=357.0 update]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot; |'''Joo!BB 0.9.1 '''&lt;br /&gt;
|  Summary: Persistent XSS/MySQL Injection vulnerabilities in Joo!BB 0.9.1 Added November 2009&lt;br /&gt;
|  [http://www.joobb.org/community/board/topic/700-MultipleXSSSQLInjectionVulnerabilities.html joob.org]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot; |[http://www.joobb.org/downloads/components.html update]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''sh404sef '''&lt;br /&gt;
|  Summary: sh404sef URI XSS Vulnerability  Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/sh404sef-uri-xss-vulnerability.html jeffchannell.com]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |[http://extensions.siliana.com/en/2009060876/sh404SEF-and-url-rewriting/Interim-release-of-sh404sef-for-Joomla-1.5.x.html update]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''AWD Wall 1.5''' &lt;br /&gt;
|  Summary '''AWD Wall 1.5''' Blind SQL Injection Vulnerability.The Joomla component AWD Wall 1.5 suffers from an SQL Injection vulnerability in its handling of the 'cbuser' parameter.Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/awd-wall-15-blind-sql-injection-vulnerability.html Notice]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | '''[http://www.awdsolution.com/template_demo/testsite/index.php?option=com_content&amp;amp;view=article&amp;amp;id=48&amp;amp;Itemid=72 developer update]'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''EasyBook 2.0.0rc4'''&lt;br /&gt;
|  Summary: The Joomla component '''EasyBook 2.0.0rc4''' suffers from multiple persistent XSS vulnerabilities. One seems fairly critical, while the others would take some incredible creativity to actively exploit. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/easybook-200rc4-multiple-xss-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''F!BB 1.5.96''' &lt;br /&gt;
|  Summary: The Joomla component '''F!BB 1.5.96 RC''' suffers from multiple persistent XSS vulnerabilities, as well SQL Injection in its user search feature. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/fbb-1596-rc-multiple-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Testimonial Ku 2.0 Admin Panel'''&lt;br /&gt;
|  Summary: The Joomla component '''Testimonial Ku 2.0''' is vulnerable to persistent XSS in the administrator panel. A malicious user can submit a testimonial containing &amp;lt;script&amp;gt; tags with absolutely no quotes and inject that script into the administrator panel through any of the available inputs except &amp;quot;email&amp;quot;. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/testimonial-ku-20-admin-panel-persistent-xss.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''MS Comment 0.8.0b'''&lt;br /&gt;
|  Summary '''MS Comment 0.8.0b for Joomla''', a commenting plugin, suffers from an multiple vulnerabilities. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/ms-comment-080b-multiple-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |  '''!JoomlaComment 4.0 beta1'''&lt;br /&gt;
|  Summary: '''!JoomlaComment 4.0 beta1''', a commenting plugin, suffers from multiple XSS vulnerabilities. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/joomlacomment-40-beta1-multiple-xss-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | '''  [http://compojoom.com/blog/8-news/121-joomlacomment-40-rc1-released Developer Notice 4.0 rc1]''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''WebAmoeba Ticket System 3.0.0'''&lt;br /&gt;
|  Summary:  '''WebAmoeba Ticket System 3.0.0''', a Joomla help desk component. The vulnerability is with the BBCode library used to parse BBCode tags, as it does not strip javascript: urls from [url] tags. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/webamoeba-ticket-system-300-bbcode-xss.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |'''Kunena 1.5.x''' &lt;br /&gt;
|Summary: This is an important security release and users are urged to update immediately. Five security issues and an Internet Explorer 8 table bug have been resolved in this release. This release also contains many other important bug fixes. Added 18 November 2009&lt;br /&gt;
|[http://www.kunena.com/blog/19-developer-blog/51-kunena-157-security-release-now-available Advisory]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |[http://www.kunena.com/blog/19-developer-blog/52-kunena-158-service-release-now-available Latest 1.5.8 Version]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_siirler'''&lt;br /&gt;
|  Summary:  SQL injection vulnerability in the '''Q-Proje Siirler Bileseni (com_siirler)''' component 1.2 RC for Joomla! allows remote attackers to execute arbitrary SQL commands via the sid parameter in an sdetay action to index.php. Added 18 November 2009&lt;br /&gt;
|  [[NIST:CVE-2009-3972 | CVE-2009-3972]]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''jTips (com_jtips)'''&lt;br /&gt;
|SUmmary:SQL injection vulnerability in the '''jTips (com_jtips)''' component 1.0.7 and 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the season parameter in a ladder action to index.php. Added 18 November 2009&lt;br /&gt;
| [[NIST:CVE-2009-3971 |CVE-2009-3971]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''NinjaMonials'''&lt;br /&gt;
| Summary: SQL injection vulnerability in the '''NinjaMonials (com_ninjacentral)''' component 1.1.0 for '''Joomla 1.0.x''' ! allows remote attackers to execute arbitrary SQL commands via the testimID parameter in a display action to index.php. Added 18 November 2009&lt;br /&gt;
|  [[NIST:CVE-2009-3964 | CVE-2009-3964]]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |'''  [http://ninjaforge.com/index.php?option=com_ninjacentral&amp;amp;page=show_package&amp;amp;id=14&amp;amp;Itemid=235 developer patch Ver 1.2]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   | '''webee 1.1.1 &amp;amp;1.2'''&lt;br /&gt;
|Summary: '''webee 1.1.1,''' a Joomla commenting plugin, suffers from multiple vulnerabilities. '''webee has been updated to 1.2''' as of 12 November 2009 and''' still suffers''' from SQL Injection. XSS was not tested in 1.2. Added 19 November 2009&lt;br /&gt;
| [http://jeffchannell.com/Joomla/webee-111-multiple-vulnerabilities.html jeffchannell.com]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | ''' [http://extensions.joomla.org/extensions/contacts-and-feedback/articles-comments/10155 developer update ver2.0]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''iF Portfolio Nexus'''&lt;br /&gt;
|Summary: The '''iF Portfolio Nexus component for Joomla!''' is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements using the id parameter, which could allow the attacker to view, add, modify or delete information in the back-end database. Nov 18, 2009&lt;br /&gt;
|[http://secunia.com/advisories/37408/ secunia.com 37408/]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; |[http://www.inertialfate.za.net/help/forums/topic?id=10&amp;amp;p=3#p172 iF Portfolio Nexus v1.1.1 released]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''JoomClip'''&lt;br /&gt;
|Summary: The '''JoomClip component for Joomla!''' is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements to the index.php script using the cat parameter, which could allow the attacker to view, add, modify or delete information in the back-end database.  Nov 18, 2009&lt;br /&gt;
|[http://secunia.com/advisories/37400/ secunia.com 37400/]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''Joomla XML'''&lt;br /&gt;
|Summary: Joomla! before 1.5.15 allows remote attackers to read an extension's XML file, and thereby obtain the extension's version number, via a direct request.&lt;br /&gt;
Published: 11/16/2009&lt;br /&gt;
|[[NIST:CVE-2009-3946 | CVE-2009-3946]] &lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |'''[http://developer.joomla.org/security/news/306-20091103-core-xml-file-read-issue.html Resolution]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Mygallery Remote SQL Injection Vulnerability''' &lt;br /&gt;
|Summary: Joomla Component mygallery ( farbinform_krell) Remote SQL Injection Vulnerability Added 27 Nov 2009 {{JVer|1.5}} NB: This could be an error in our database as the only one we could find was for wordpress.If anyone know of one for joomla please let us know..(poss joomlicious.com CM)&lt;br /&gt;
|[http://www.exploit-db.com] &lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Extreme Google Calendar'''&lt;br /&gt;
|Summary: '''com_gcalendar 1.1.2''' (gcid) Remote SQL Injection Vulnerability&lt;br /&gt;
Remote SQL Injection were identified in Google Calendar Component [http://extensions.joomla.org/extensions/calendars-a-events/calendars/4188 Extension Link] Added 27 Nov 2009 &lt;br /&gt;
|[http://www.exploit-db.com reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''LyftenBloggie'''&lt;br /&gt;
| Summary: [http://www.lyften.com/products/lyftenbloggie.html LyftenBloggie] Component &amp;quot;author&amp;quot; SQL Injection Vulnerability LyftenBloggie 1.x Added 27 Nov 2009&lt;br /&gt;
|[http://secunia.com/advisories/product/28005/	 SA37499]&lt;br /&gt;
| [http://jeffchannell.com/Joomla/lyften-bloggie-sql-injection-fix.html Un official fix]. Developer fix not release at 30 Nov 09 ''' [http://www.lyften.com/products/lyftenbloggie/extensions/download/id-20.html 1.0.4a (last update on Dec 28, 2009)]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''Sermon speaker'''&lt;br /&gt;
|Summary: [http://joomlacode.org/gf/project/sermon_speaker sermon speaker] sql vulnerability and password reset vulnerability version 3.2 and below&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |[http://joomlacode.org/gf/project/sermon_speaker/forum/?action=ForumBrowse&amp;amp;forum_id=7897&amp;amp;_forum_action=ForumMessageBrowse&amp;amp;thread_id=15219 Developer fix] 30 Nov 2009&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | [http://joomlacode.org/gf/project/musicgallery/ MusicGallery]&lt;br /&gt;
|Summary: [http://joomlacode.org/gf/project/musicgallery/ Component MusicGallery] SQL Injection Vulnerability 30 November {{JVer|1.5}}&lt;br /&gt;
|[[NIST:CVE-2009-4217 | CVE-2009-4217]]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; | [http://joomlacode.org/gf/project/musicgallery/ developer]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== December 2009 Compiled Reports ==&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  '''Extension'''&lt;br /&gt;
! class=&amp;quot;unsortable&amp;quot;| '''Details'''&lt;br /&gt;
!  '''Reference Link'''&lt;br /&gt;
!  '''Extension Update Link'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Omilen Photo Gallery'''&lt;br /&gt;
|Summary: Directory traversal vulnerability in the [http://extensions.joomla.org/extensions/photos-&amp;amp;-images/photo-flash-gallery/6373/details Omilen Photo Gallery] (com_omphotogallery) component Beta 0.5 for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the controller parameter to index.php.&lt;br /&gt;
Published: 12/04/2009&lt;br /&gt;
|[[NIST:CVE-2009-4202 | CVE-2009-4202]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Seminar'''&lt;br /&gt;
|Summary: SQL injection vulnerability in the [http://seminar.vollmar.ws/ Seminar] (com_seminar) component 1.28 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a View_seminar action to index.php.&lt;br /&gt;
Published: 12/04/2009&lt;br /&gt;
|[[NIST:CVE-2009-4200 | CVE-2009-4200]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''Mambo Resident'''&lt;br /&gt;
|Summary: Multiple SQL injection vulnerabilities in the Mambo Resident (aka Mos Res or com_mosres) component 1.0f for Mambo and Joomla!, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) property_uid parameter in a viewproperty action to index.php and the (2) regID parameter in a showregion action to index.php. Mambo Resident component for v4.5.2 '''may only be for 1.0.xx versions of J!'''&lt;br /&gt;
Published: 12/04/2009&lt;br /&gt;
|[[NIST:CVE-2009-4199 | CVE-2009-4199]]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; |[http://www.jomres.net/ Replacement Extension 08 dec 09]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''ProofReader''' &lt;br /&gt;
|Summary: Multiple cross-site scripting (XSS) vulnerabilities in index.php in the ProofReader (com_proofreader) component 1.0 RC9 and earlier for Joomla! allow remote attackers to inject arbitrary web script or HTML via the URI, which is not properly handled in (1) 404 or (2) error pages. Published: 12/02/2009 CVSS Severity: 4.3 (MEDIUM)&lt;br /&gt;
| [[NIST:CVE-2009-4157 | CVE-2009-4157]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''Laoneo Google Calendar GCalendar'''&lt;br /&gt;
|Summary: SQL injection vulnerability in the [http://g4j.laoneo.net/content/extensions/download/cat_view/20-joomla-15x/21-gcalendar.html Google Calendar GCalendar] (com_gcalendar) component 1.1.2, 2.1.4, and possibly earlier versions for Joomla! allows remote attackers to execute arbitrary SQL commands via the gcid parameter. NOTE: some of these details are obtained from third party information. Published: 11/29/2009 CVSS Severity: 7.5 (HIGH) Note: There is already a listing for GCalendar 1.1.2&lt;br /&gt;
|[[NIST:CVE-2009-4099 | CVE-2009-4099]]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;   | [http://g4j.laoneo.net/content/extensions/download/doc_details/28-gcalendar-suite-215.html Latest version GCalendar Suite 2.1.5]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''D4J eZine'''&lt;br /&gt;
|Summary: PHP remote file inclusion vulnerability in class/php/d4m_ajax_pagenav.php in the D4J eZine (com_ezine) component 2.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS mosConfig_absolute_path parameter. Published: 11/29/2009 CVSS Severity: 7.5 (HIGH)&lt;br /&gt;
|[[NIST:CVE-2009-4094 | CVE-2009-4094]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''Quick News'''&lt;br /&gt;
| Summary: The Joomla [http://joomlacode.org/gf/project/quicknews/ Quick News component] suffers from a remote SQL injection vulnerability. added 1st Dec 09&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''Joaktree component'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/miscellaneous/genealogy/9842 Joaktree] Vulnerability : SQL injection/ added 1st Dec 09&lt;br /&gt;
|[http://securityreason.com/exploitalert/7508 7508]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | '''  [http://naastniels.nl/index.php/en/joaktree/downloads version 1.1 update]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''mojoblog'''&lt;br /&gt;
|Summary [http://www.joomlify.com/files/mojoblog/ MojoBlog] Multiple Remote File Include Vulnerability added 1st Dec 09 {{JVer|1.5}}&lt;br /&gt;
|[http://securityreason.com/exploitalert/7509 7509]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''YJ Whois''' &lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/external-contents/domain-search/5774 YJ Whois] '''Low security risk''',and fixesMalicious users may inject JavaScript, VBScript, ActiveX, HTML or Flash into a vulnerable application to fool a user in order to gather data from them. An attacker can steal the session cookie and take over the account. Files affected is , modules/mod_yj_whois.php added 3 December 09&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; |[http://www.youjoomla.com/xss-security-patch-for-yj-whois.html Developer Notice and fix 03 dec 09]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; | '''yt_color YOOOtheme'''&lt;br /&gt;
|Summary: [http://www.yootheme.com/ YT_color yootheme] Malicious users may inject JavaScript, VBScript, ActiveX, HTML or Flash into a vulnerable application to fool a user in order to gather data from them. An attacker can steal the session cookie and take over the account. added 5 dec 09&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | '''  [http://www.yootheme.com/member-area/downloads/item/templates-15/xss-and-php-53-patches All members without an active membership can download the template patches here].'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''TP Whois''' &lt;br /&gt;
|summary: [http://www.templateplazza.com/view-details/tpwhois/183-component-tp-whois-for-joomla-1.5.x.html TP Whois ] Malicious users may inject JavaScript, VBScript, ActiveX, HTML or Flash into a vulnerable application to fool a user in order to gather data from them. An attacker can steal the session cookie and take over the account. Added 3 december {{JVer|1.5}}&lt;br /&gt;
|[http://www.exploit-db.com Refrence]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''com_job'''&lt;br /&gt;
|Summary: Component com_job ( showMoreUse) SQL injection vulnerability  Added 9th Dec&lt;br /&gt;
|[http://xforce.iss.net/xforce/xfdb/54626 Reference]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |  '''JQuarks''' &lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/contacts-and-feedback/quiz-a-surveys/10590 JQuarks] SQL injection vulnerability {{JVer|1.5}} added 8th dec 09&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | [http://www.iptechinside.com/labs/projects/list_files/jquarks Developer Update ]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''Mamboleto Component 2.0 RC3'''&lt;br /&gt;
|Summary: [http://www.fernandosoares.com.br/index.php?option=com_docman&amp;amp;task=cat_view&amp;amp;gid=28&amp;amp;Itemid=28 Mamboleto Component 2.0 RC3]SQL injection vulnerability {{JVer|1.5}} added 12 December&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |  ''' JS JOBS'''&lt;br /&gt;
|Summary [http://www.joomshark.com/index.php?option=com_content&amp;amp;view=article&amp;amp;id=4&amp;amp;Itemid=8 JS JOBS] Joomla Component com_jsjobs 1.0.5.6 SQL Injection Vulnerabilities {{JVer|1.5}} added 12 December&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | '''  [http://www.joomsky.com/index.php?option=com_rokdownloads&amp;amp;view=folder&amp;amp;Itemid=3&amp;amp;id=2:components Developer update 1.0.5.7]''' &lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |  '''corePHP JPhoto'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/photos-a-images/photo-gallery/10365 'corePHP' JPhoto]SQL injection vulnerability {{JVer|1.5}} added 12 December&lt;br /&gt;
|[http://secunia.com/advisories/37676/ Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | '''  [http://www.corephp.com/blog/uber-fast-jphoto-security-release/ Developer Upgrade]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;    | '''com_virtuemart'''&lt;br /&gt;
|Summary: &amp;quot;com_virtuemart&amp;quot; http://virtuemart.net/  '''Version : 1.0''' Vulnerability : SQL injection added Date : 07- dec -09 {{JVer|1.5}}&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |[http://virtuemart.net/ latest version]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | ''' Kide Shoutbox'''&lt;br /&gt;
&lt;br /&gt;
|Summary: The Kide Shoutbox (com_kide) component 0.4.6 for Joomla! does not properly perform authentication, which allows remote attackers to post messages with an arbitrary account name via an insertar action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Added: December 08&lt;br /&gt;
|[[NIST:CVE-2009-4232 | CVE-2009-4232]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | ''' JoomPortfolio Component'''&lt;br /&gt;
|Summary: [http://www.joomplace.com/joomportfolio/joomportfolio.html JoomPortfolio] Input passed via the &amp;quot;secid&amp;quot; parameter to index.php (when &amp;quot;option&amp;quot; is set to &amp;quot;com_joomportfolio&amp;quot; and &amp;quot;task&amp;quot; is set to &amp;quot;showcat&amp;quot;) is not properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.The vulnerability is reported in version 1.0.0. Other versions may also be affected. Added: December 18 {{JVer|1.5}}&lt;br /&gt;
|[http://secunia.com/advisories/37838/ Reporting Site]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''City Portal (templates?)'''&lt;br /&gt;
|Summary:   City Portal Blind SQL Injection Vulnerability added: 2009-12-18&lt;br /&gt;
|[http://www.exploit-db.com Reference] Possibly this [http://www.youjoomla.com/jclick-city-portal-joomla-template.html tempate]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''Event Manager'''&lt;br /&gt;
|Summary:  [http://www.jforjoomla.com/Joomla-Components/event-manager-15-component.html Event Manager] Blind SQL Injection Vulnerability EDB-ID: 10549&lt;br /&gt;
added: 2009-12-18&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | com_zcalendar&lt;br /&gt;
|Summary:  com_zcalendar Blind SQL-injection Vulnerability&lt;br /&gt;
EDB-ID: 10548 added: 2009-12-18&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''com_acmisc'''&lt;br /&gt;
|Summary:  com_acmisc SQL injection added: 2009-12-18&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''com_digistore'''&lt;br /&gt;
|Summary:  com_digistore SQL injection EDB-ID: 10546 added: 2009-12-18  {{JVer|1.5}}&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | '''  [http://www.ijoomla.com/ijoomla-digistore/ijoomla-digistore/ijoomla-digistore-change-log/ Update change log] '''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''com_jbook'''&lt;br /&gt;
|Summary:   com_jbook Blind SQL-injection EDB-ID: 10545 added: 2009-12-18 {{JVer|1.0}}&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |  '''com_personel'''&lt;br /&gt;
|Summary: com_personel component for Joomla! is vulnerable to SQL injection.&lt;br /&gt;
|[http://xforce.iss.net/xforce/xfdb/54903 iss.net reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |  '''JEEMA Article Collection'''&lt;br /&gt;
|Summary: [http://www.forum.jeema.net/component/content/article/4-jeema-article-collection-component/13-about-jeema-article-collection.html JEEMA Article Collection] Input passed via the &amp;quot;catid&amp;quot; parameter to index.php (when &amp;quot;option&amp;quot; is set to &amp;quot;com_jeemaarticlecollection&amp;quot; and &amp;quot;view&amp;quot; is set to &amp;quot;longlook&amp;quot;) is not properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. version 1.0.0.1 {{JVer|1.5}} added 22 dec 09&lt;br /&gt;
| [http://secunia.com/advisories/37865/ secunia]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;    | [http://www.jeema.net/downloads/free-joomla-extensions/joomla-components/12-jeema-joomla-article-collection.htm fixed the same in the version v102.]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |  '''HotBrackets Tournament Brackets '''&lt;br /&gt;
|Summary: The [http://extensions.joomla.org/extensions/sports-a-games/sports/10746 HotBrackets Tournament Brackets] component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. {{JVer|1.5}} added 22 dec &lt;br /&gt;
|[http://www.securityfocus.com/bid/37439/ Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''Car Manager'''&lt;br /&gt;
|Summary: http://webformatique.com/ com_carman Cross Site Scripting Vulnerability added 24 december 09{{JVer|1.5}}&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot; |'''Schools component'''&lt;br /&gt;
|Summary: The 'com_schools' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.&lt;br /&gt;
|[http://www.securityfocus.com/bid/37469 Reference] added 24 dec 09&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''webcamxp'''&lt;br /&gt;
|[http://extensions.joomla.org/extensions/communication/video-conference/4490 com_webcamxp] Cross Site Scripting Vulnerabilities  Last version 2008 {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''beeheard'''&lt;br /&gt;
|[http://extensions.joomla.org/extensions/contacts-and-feedback/testimonials-a-suggestions/10283 beeheard]  Blind SQL injection Vulnerability {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | '''  [http://beeheard.cmstactics.com/change-log Version 1.4.2] 04 Jan'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''jm-recommend'''&lt;br /&gt;
|jm-recommendCross Site Scripting Vulnerabilities. unable to locate on jed. {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | facileforms&lt;br /&gt;
| com_facileforms Cross Site Scripting Vulnerabilities. unable to locate on jed. Product considered retired.  {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''adagency'''&lt;br /&gt;
| [http://www.ijoomla.com/ijoomla-ad-agency/ijoomla-ad-agency/index/ adagency ]Vulnerabilities {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |  '''com_intuit'''&lt;br /&gt;
|[http://www.san-diego-web-designer.com/new-file-download/item/root/aboutimage-igateway-for-joomla.html com_intuit]Local File Inclusion Vulnerability {{JVer|1.5}} Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | '''  [http://www.securityfocus.com/bid/37494/discuss Retired]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''MemoryBook'''&lt;br /&gt;
|[http://extensions.joomla.org/extensions/calendars-a-events/birthdays-a-historic-events/10868 MemoryBook 1.2]  Multiple Vulnerabilities. requires: magic quotes OFF, user account {{JVer|1.5}} Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''qpersonel'''&lt;br /&gt;
|[http://extensions.joomla.org/extensions/directory-a-documentation/thematic-directory/7049 qpersonel ] Cross Site Scripting Vulnerabilities {{JVer|1.0}}[[Image:http://extensions.joomla.org/images/jed/compat_15_legacy.png]] Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''opryknings point''' &lt;br /&gt;
|com_oprykningspoint_mc Cross Site Scripting Vulnerabilities {{JVer|1.5}} Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''trabalhe conosco'''&lt;br /&gt;
|com_trabalhe_conosco Cross Site Scripting Vulnerabilities {{JVer|1.5}} Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''DhForum'''&lt;br /&gt;
|com_dhforum SQL Injection Vulnerability. considered retired/EOL Dec. 27 {{JVer|1.0}}1.5 legacy&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |'''com_morfeoshow'''&lt;br /&gt;
|[http://extensions.joomla.org/extensions/photos-a-images/photo-gallery-add-ons/9810 morfeoshow] this was a false report &lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''  false report'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''Run Digital Download rd-download''' &lt;br /&gt;
|[http://extensions.joomla.org/extensions/directory-a-documentation/downloads/7838 RD Download] Local File Disclosure Vulnerability  {{JVer|1.5}} Dec. 30 Version affected not disclosed.&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | [http://extensions.joomla.org/extensions/directory-a-documentation/downloads/7838 Version 0.9 relased] &lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|}&lt;br /&gt;
== November 2009 Compiled Vulnerability Reports. RESOLVED ONLY  ==&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
Items are not in any particular order.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  '''Extension'''&lt;br /&gt;
! class=&amp;quot;unsortable&amp;quot;| '''Details'''&lt;br /&gt;
!  '''Reference Link'''&lt;br /&gt;
!  '''Extension Update Link'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_djcatalog'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the DJ-Catalog ('''com_djcatalog''') component for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a showItem action and (2) cid parameter in a show action to index.php.&lt;br /&gt;
Published: 10/11/2009&lt;br /&gt;
CVSS Severity: 6.8 (MEDIUM)&lt;br /&gt;
|  [[NIST:CVE-2009-3661|CVE-2009-3661]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  |  '''com_soundset'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Soundset ('''com_soundset''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter to index.php.&lt;br /&gt;
Published: 10/09/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3644|CVE-2009-3644]]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  |  '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  |'''com_sportfusion'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Kinfusion SportFusion ('''com_sportfusion''') component 0.2.2 through 0.2.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid[0] parameter in a teamdetail action to index.php.&lt;br /&gt;
Published: 09/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3491|CVE-2009-3491]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  |'''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_icrmbasic'''&lt;br /&gt;
|  Summary: A certain interface in the iCRM Basic ('''com_icrmbasic''') component 1.4.2.31 for Joomla! does not require administrative authentication, which has unspecified impact and remote attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 09/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3481|CVE-2009-3481]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_mytube'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the MyRemote Video Gallery ('''com_mytube''') component 1.0 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter in a videos action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3446|CVE-2009-3446]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|   '''com_facebook'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the JoomlaFacebook ('''com_facebook''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a student action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3438|CVE-2009-3438]]&lt;br /&gt;
|   [http://extensions.joomla.org/extensions/4446/details JED entry.] [http://forge.joomla.org/gf/project/joomla-facebook/ Download site] Developer states reports not proven 24/07/10&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_tupinambis'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Tupinambis ('''com_tupinambis''') component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the proyecto parameter in a verproyecto action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3434|CVE-2009-3434]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_hbssearch'''&lt;br /&gt;
|  Summary: Cross-site scripting ('''XSS''') vulnerability in the Hotel Booking Reservation System ('''aka HBS or com_hbssearch''') component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the adult parameter in a showhoteldetails action to index.php.&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 4.3 ('''MEDIUM''')&lt;br /&gt;
|  [[NIST:CVE-2009-3368|CVE-2009-3368]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_hbssearch'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System ('''aka HBS or com_hbssearch''') component for Joomla! allow remote attackers to execute arbitrary SQL commands via the ('''1''') h_id, ('''2''') id, and ('''3''') rid parameters to longDesc.php, and the h_id parameter to ('''4''') detail.php, ('''5''') detail1.php, ('''6''') detail2.php, ('''7''') detail3.php, ('''8''') detail4.php, ('''9''') detail5.php, ('''10''') detail6.php, ('''11''') detail7.php, and ('''12''') detail8.php, different vectors than [[NIST:CVE-2008-5865|CVE-2008-5865]], [[NIST:CVE-2008-5874|CVE-2008-5874]], and [[NIST:CVE-2008-5875|CVE-2008-5875]].&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3357|CVE-2009-3357]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''TurtuShout'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the TurtuShout component 0.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Name field.&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3335|CVE-2009-3335]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jinc'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Lhacky! Extensions Cave Joomla! Integrated Newsletters Component ('''aka JINC or com_jinc''') component 0.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a messages action to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3334|CVE-2009-3334]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_surveymanager'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Focusplus Developments Survey Manager ('''com_surveymanager''') component 1.5.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the stype parameter in an editsurvey action to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3325|CVE-2009-3325]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_album'''&lt;br /&gt;
|  Summary: Directory traversal vulnerability in the Roland Breedveld Album ('''com_album''') component 1.14 for Joomla! allows remote attackers to access arbitrary directories and have unspecified other impact via a .. ('''dot dot''') in the target parameter to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3318|CVE-2009-3318]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''IXXO Cart Standalone'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in IXXO Cart Standalone before 3.9.6.1, and the IXXO Cart component for Joomla! 1.0.x, allows remote attackers to execute arbitrary SQL commands via the parent parameter.&lt;br /&gt;
Published: 09/16/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3215|CVE-2009-3215]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_digifolio'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the DigiFolio ('''com_digifolio''') component 1.52 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a project action to index.php.&lt;br /&gt;
Published: 09/15/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3193|CVE-2009-3193]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_aclassf'''&lt;br /&gt;
|  Summary: Cross-site scripting ('''XSS''') vulnerability in '''gmap.php''' in the Almond Classifieds ('''com_aclassf''') component 7.5 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the addr parameter.&lt;br /&gt;
Published: 09/10/2009&lt;br /&gt;
CVSS Severity: 4.3 ('''MEDIUM''')&lt;br /&gt;
|  [[NIST:CVE-2009-3155|CVE-2009-3155]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;   | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jabode'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in Jabode horoscope extension ('''com_jabode''') for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a sign task to index.php.&lt;br /&gt;
Published: 09/08/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
&lt;br /&gt;
|  [[NIST:CVE-2008-7169|CVE-2008-7169]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_gameserver'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Game Server ('''com_gameserver''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a gamepanel action to index.php.&lt;br /&gt;
Published: 09/03/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3063|CVE-2009-3063]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_artportal'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Artetics.com Art Portal ('''com_artportal''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the portalid parameter to index.php.&lt;br /&gt;
Published: 09/03/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3054|CVE-2009-3054]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_simpleshop'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Simple Shop Galore ('''com_simpleshop''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the section parameter in a section action to index.php, a different vulnerability than [[NIST:CVE-2008-2568|CVE-2008-2568]]. NOTE: this issue was disclosed by an unreliable researcher, so the details might be incorrect.&lt;br /&gt;
Published: 08/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-7033|CVE-2008-7033]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_groups'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Permis ('''com_groups''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a list action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 08/17/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-2789|CVE-2009-2789]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Live Chat ('''com_livechat''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the last parameter to getChatRoom.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6883|CVE-2008-6883]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: Live Chat ('''com_livechat''') component 1.0 for Joomla! allows remote attackers to use the xmlhttp.php script as an open HTTP proxy to hide network scanning activities or scan internal networks via a GET request with a full URL in the query string.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6882|CVE-2008-6882]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the Live Chat ('''com_livechat''') component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the last parameter to ('''1''') getChat.php, ('''2''') getChatRoom.php, and ('''3''') getSavedChatRooms.php.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6881|CVE-2008-6881]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jshop'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the JShop ('''com_jshop''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a product action to index.php.&lt;br /&gt;
Published: 11/02/2009&lt;br /&gt;
CVSS Severity: 7.5 '''(HIGH)''' &lt;br /&gt;
|  [[NIST:CVE-2009-3835|CVE-2009-3835]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;| '''EasyBook 2.0.0rc4'''&lt;br /&gt;
|  Summary: The Joomla component '''EasyBook 2.0.0rc4''' suffers from multiple persistent XSS vulnerabilities. One seems fairly critical, while the others would take some incredible creativity to actively exploit. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/easybook-200rc4-multiple-xss-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:#cef2e0; color:black&amp;quot;| '''  &lt;br /&gt;
[http://www.kubik-rubik.de/joomla-hilfe/komponente-easybook-reloaded-joomla easybook reloaded released]&lt;br /&gt;
'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''F!BB 1.5.96''' &lt;br /&gt;
|  Summary: The Joomla component '''F!BB 1.5.96 RC''' suffers from multiple persistent XSS vulnerabilities, as well SQL Injection in its user search feature. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/fbb-1596-rc-multiple-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Testimonial Ku 2.0 Admin Panel'''&lt;br /&gt;
|  Summary: The Joomla component '''Testimonial Ku 2.0''' is vulnerable to persistent XSS in the administrator panel. A malicious user can submit a testimonial containing &amp;lt;script&amp;gt; tags with absolutely no quotes and inject that script into the administrator panel through any of the available inputs except &amp;quot;email&amp;quot;. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/testimonial-ku-20-admin-panel-persistent-xss.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''MS Comment 0.8.0b'''&lt;br /&gt;
|  Summary '''MS Comment 0.8.0b for Joomla''', a commenting plugin, suffers from an multiple vulnerabilities. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/ms-comment-080b-multiple-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''WebAmoeba Ticket System 3.0.0'''&lt;br /&gt;
|  Summary:  '''WebAmoeba Ticket System 3.0.0''', a Joomla help desk component. The vulnerability is with the BBCode library used to parse BBCode tags, as it does not strip javascript: urls from [url] tags. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/webamoeba-ticket-system-300-bbcode-xss.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_siirler'''&lt;br /&gt;
|  Summary:  SQL injection vulnerability in the '''Q-Proje Siirler Bileseni (com_siirler)''' component 1.2 RC for Joomla! allows remote attackers to execute arbitrary SQL commands via the sid parameter in an sdetay action to index.php. Added 18 November 2009&lt;br /&gt;
|  [[NIST:CVE-2009-3972 | CVE-2009-3972]]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''jTips (com_jtips)'''&lt;br /&gt;
|SUmmary:SQL injection vulnerability in the '''jTips (com_jtips)''' component 1.0.7 and 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the season parameter in a ladder action to index.php. Added 18 November 2009&lt;br /&gt;
| [[NIST:CVE-2009-3971 |CVE-2009-3971]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''JoomClip'''&lt;br /&gt;
|Summary: The '''JoomClip component for Joomla!''' is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements to the index.php script using the cat parameter, which could allow the attacker to view, add, modify or delete information in the back-end database.  Nov 18, 2009&lt;br /&gt;
|[http://secunia.com/advisories/37400/ secunia.com 37400/]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Mygallery Remote SQL Injection Vulnerability''' &lt;br /&gt;
|Summary: Joomla Component mygallery ( farbinform_krell) Remote SQL Injection Vulnerability Added 27 Nov 2009 {{JVer|1.5}} NB: This could be an error in our database as the only one we could find was for wordpress.If anyone know of one for joomla please let us know..(poss joomlicious.com CM)&lt;br /&gt;
|[http://www.exploit-db.com] &lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Extreme Google Calendar'''&lt;br /&gt;
|Summary: '''com_gcalendar 1.1.2''' (gcid) Remote SQL Injection Vulnerability&lt;br /&gt;
Remote SQL Injection were identified in Google Calendar Component [http://extensions.joomla.org/extensions/calendars-a-events/calendars/4188 Extension Link] Added 27 Nov 2009 &lt;br /&gt;
|[http://www.exploit-db.com reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''LyftenBloggie'''&lt;br /&gt;
| Summary: [http://www.lyften.com/products/lyftenbloggie.html LyftenBloggie] Component &amp;quot;author&amp;quot; SQL Injection Vulnerability LyftenBloggie 1.x Added 27 Nov 2009&lt;br /&gt;
|[http://secunia.com/advisories/product/28005/	 SA37499]&lt;br /&gt;
| [http://jeffchannell.com/Joomla/lyften-bloggie-sql-injection-fix.html Un official fix]. Developer fix not release at 30 Nov 09 ''' [http://www.lyften.com/products/lyftenbloggie/extensions/download/id-20.html 1.0.4a (last update on Dec 28, 2009)]'''&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== November 2009 Compiled Vulnerability Reports. ==&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
Items are not in any particular order.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  '''Extension'''&lt;br /&gt;
! class=&amp;quot;unsortable&amp;quot;| '''Details'''&lt;br /&gt;
!  '''Reference Link'''&lt;br /&gt;
!  '''Extension Update Link'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_djcatalog'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the DJ-Catalog ('''com_djcatalog''') component for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a showItem action and (2) cid parameter in a show action to index.php.&lt;br /&gt;
Published: 10/11/2009&lt;br /&gt;
CVSS Severity: 6.8 (MEDIUM)&lt;br /&gt;
|  [[NIST:CVE-2009-3661|CVE-2009-3661]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  |  '''com_soundset'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Soundset ('''com_soundset''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter to index.php.&lt;br /&gt;
Published: 10/09/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3644|CVE-2009-3644]]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  |  '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  |'''com_sportfusion'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Kinfusion SportFusion ('''com_sportfusion''') component 0.2.2 through 0.2.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid[0] parameter in a teamdetail action to index.php.&lt;br /&gt;
Published: 09/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3491|CVE-2009-3491]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  |'''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_icrmbasic'''&lt;br /&gt;
|  Summary: A certain interface in the iCRM Basic ('''com_icrmbasic''') component 1.4.2.31 for Joomla! does not require administrative authentication, which has unspecified impact and remote attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 09/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3481|CVE-2009-3481]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_mytube'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the MyRemote Video Gallery ('''com_mytube''') component 1.0 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter in a videos action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3446|CVE-2009-3446]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|   '''com_facebook'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the JoomlaFacebook ('''com_facebook''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a student action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3438|CVE-2009-3438]]&lt;br /&gt;
|   [http://extensions.joomla.org/extensions/4446/details JED entry.] [http://forge.joomla.org/gf/project/joomla-facebook/ Download site] Developer states reports not proven 24/07/10&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_tupinambis'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Tupinambis ('''com_tupinambis''') component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the proyecto parameter in a verproyecto action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3434|CVE-2009-3434]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_hbssearch'''&lt;br /&gt;
|  Summary: Cross-site scripting ('''XSS''') vulnerability in the Hotel Booking Reservation System ('''aka HBS or com_hbssearch''') component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the adult parameter in a showhoteldetails action to index.php.&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 4.3 ('''MEDIUM''')&lt;br /&gt;
|  [[NIST:CVE-2009-3368|CVE-2009-3368]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_hbssearch'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System ('''aka HBS or com_hbssearch''') component for Joomla! allow remote attackers to execute arbitrary SQL commands via the ('''1''') h_id, ('''2''') id, and ('''3''') rid parameters to longDesc.php, and the h_id parameter to ('''4''') detail.php, ('''5''') detail1.php, ('''6''') detail2.php, ('''7''') detail3.php, ('''8''') detail4.php, ('''9''') detail5.php, ('''10''') detail6.php, ('''11''') detail7.php, and ('''12''') detail8.php, different vectors than [[NIST:CVE-2008-5865|CVE-2008-5865]], [[NIST:CVE-2008-5874|CVE-2008-5874]], and [[NIST:CVE-2008-5875|CVE-2008-5875]].&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3357|CVE-2009-3357]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''TurtuShout'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the TurtuShout component 0.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Name field.&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3335|CVE-2009-3335]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jinc'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Lhacky! Extensions Cave Joomla! Integrated Newsletters Component ('''aka JINC or com_jinc''') component 0.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a messages action to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3334|CVE-2009-3334]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_surveymanager'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Focusplus Developments Survey Manager ('''com_surveymanager''') component 1.5.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the stype parameter in an editsurvey action to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3325|CVE-2009-3325]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_album'''&lt;br /&gt;
|  Summary: Directory traversal vulnerability in the Roland Breedveld Album ('''com_album''') component 1.14 for Joomla! allows remote attackers to access arbitrary directories and have unspecified other impact via a .. ('''dot dot''') in the target parameter to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3318|CVE-2009-3318]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''IXXO Cart Standalone'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in IXXO Cart Standalone before 3.9.6.1, and the IXXO Cart component for Joomla! 1.0.x, allows remote attackers to execute arbitrary SQL commands via the parent parameter.&lt;br /&gt;
Published: 09/16/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3215|CVE-2009-3215]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_digifolio'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the DigiFolio ('''com_digifolio''') component 1.52 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a project action to index.php.&lt;br /&gt;
Published: 09/15/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3193|CVE-2009-3193]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_aclassf'''&lt;br /&gt;
|  Summary: Cross-site scripting ('''XSS''') vulnerability in '''gmap.php''' in the Almond Classifieds ('''com_aclassf''') component 7.5 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the addr parameter.&lt;br /&gt;
Published: 09/10/2009&lt;br /&gt;
CVSS Severity: 4.3 ('''MEDIUM''')&lt;br /&gt;
|  [[NIST:CVE-2009-3155|CVE-2009-3155]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;   | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jabode'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in Jabode horoscope extension ('''com_jabode''') for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a sign task to index.php.&lt;br /&gt;
Published: 09/08/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
&lt;br /&gt;
|  [[NIST:CVE-2008-7169|CVE-2008-7169]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_gameserver'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Game Server ('''com_gameserver''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a gamepanel action to index.php.&lt;br /&gt;
Published: 09/03/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3063|CVE-2009-3063]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_artportal'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Artetics.com Art Portal ('''com_artportal''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the portalid parameter to index.php.&lt;br /&gt;
Published: 09/03/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3054|CVE-2009-3054]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_simpleshop'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Simple Shop Galore ('''com_simpleshop''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the section parameter in a section action to index.php, a different vulnerability than [[NIST:CVE-2008-2568|CVE-2008-2568]]. NOTE: this issue was disclosed by an unreliable researcher, so the details might be incorrect.&lt;br /&gt;
Published: 08/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-7033|CVE-2008-7033]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_groups'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Permis ('''com_groups''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a list action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 08/17/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-2789|CVE-2009-2789]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Live Chat ('''com_livechat''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the last parameter to getChatRoom.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6883|CVE-2008-6883]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: Live Chat ('''com_livechat''') component 1.0 for Joomla! allows remote attackers to use the xmlhttp.php script as an open HTTP proxy to hide network scanning activities or scan internal networks via a GET request with a full URL in the query string.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6882|CVE-2008-6882]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the Live Chat ('''com_livechat''') component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the last parameter to ('''1''') getChat.php, ('''2''') getChatRoom.php, and ('''3''') getSavedChatRooms.php.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6881|CVE-2008-6881]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jshop'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the JShop ('''com_jshop''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a product action to index.php.&lt;br /&gt;
Published: 11/02/2009&lt;br /&gt;
CVSS Severity: 7.5 '''(HIGH)''' &lt;br /&gt;
|  [[NIST:CVE-2009-3835|CVE-2009-3835]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;| '''EasyBook 2.0.0rc4'''&lt;br /&gt;
|  Summary: The Joomla component '''EasyBook 2.0.0rc4''' suffers from multiple persistent XSS vulnerabilities. One seems fairly critical, while the others would take some incredible creativity to actively exploit. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/easybook-200rc4-multiple-xss-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:#cef2e0; color:black&amp;quot;| '''  &lt;br /&gt;
[http://www.kubik-rubik.de/joomla-hilfe/komponente-easybook-reloaded-joomla easybook reloaded released]&lt;br /&gt;
'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''F!BB 1.5.96''' &lt;br /&gt;
|  Summary: The Joomla component '''F!BB 1.5.96 RC''' suffers from multiple persistent XSS vulnerabilities, as well SQL Injection in its user search feature. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/fbb-1596-rc-multiple-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Testimonial Ku 2.0 Admin Panel'''&lt;br /&gt;
|  Summary: The Joomla component '''Testimonial Ku 2.0''' is vulnerable to persistent XSS in the administrator panel. A malicious user can submit a testimonial containing &amp;lt;script&amp;gt; tags with absolutely no quotes and inject that script into the administrator panel through any of the available inputs except &amp;quot;email&amp;quot;. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/testimonial-ku-20-admin-panel-persistent-xss.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''MS Comment 0.8.0b'''&lt;br /&gt;
|  Summary '''MS Comment 0.8.0b for Joomla''', a commenting plugin, suffers from an multiple vulnerabilities. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/ms-comment-080b-multiple-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''WebAmoeba Ticket System 3.0.0'''&lt;br /&gt;
|  Summary:  '''WebAmoeba Ticket System 3.0.0''', a Joomla help desk component. The vulnerability is with the BBCode library used to parse BBCode tags, as it does not strip javascript: urls from [url] tags. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/webamoeba-ticket-system-300-bbcode-xss.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_siirler'''&lt;br /&gt;
|  Summary:  SQL injection vulnerability in the '''Q-Proje Siirler Bileseni (com_siirler)''' component 1.2 RC for Joomla! allows remote attackers to execute arbitrary SQL commands via the sid parameter in an sdetay action to index.php. Added 18 November 2009&lt;br /&gt;
|  [[NIST:CVE-2009-3972 | CVE-2009-3972]]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''jTips (com_jtips)'''&lt;br /&gt;
|SUmmary:SQL injection vulnerability in the '''jTips (com_jtips)''' component 1.0.7 and 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the season parameter in a ladder action to index.php. Added 18 November 2009&lt;br /&gt;
| [[NIST:CVE-2009-3971 |CVE-2009-3971]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''JoomClip'''&lt;br /&gt;
|Summary: The '''JoomClip component for Joomla!''' is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements to the index.php script using the cat parameter, which could allow the attacker to view, add, modify or delete information in the back-end database.  Nov 18, 2009&lt;br /&gt;
|[http://secunia.com/advisories/37400/ secunia.com 37400/]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Mygallery Remote SQL Injection Vulnerability''' &lt;br /&gt;
|Summary: Joomla Component mygallery ( farbinform_krell) Remote SQL Injection Vulnerability Added 27 Nov 2009 {{JVer|1.5}} NB: This could be an error in our database as the only one we could find was for wordpress.If anyone know of one for joomla please let us know..(poss joomlicious.com CM)&lt;br /&gt;
|[http://www.exploit-db.com] &lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Extreme Google Calendar'''&lt;br /&gt;
|Summary: '''com_gcalendar 1.1.2''' (gcid) Remote SQL Injection Vulnerability&lt;br /&gt;
Remote SQL Injection were identified in Google Calendar Component [http://extensions.joomla.org/extensions/calendars-a-events/calendars/4188 Extension Link] Added 27 Nov 2009 &lt;br /&gt;
|[http://www.exploit-db.com reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''LyftenBloggie'''&lt;br /&gt;
| Summary: [http://www.lyften.com/products/lyftenbloggie.html LyftenBloggie] Component &amp;quot;author&amp;quot; SQL Injection Vulnerability LyftenBloggie 1.x Added 27 Nov 2009&lt;br /&gt;
|[http://secunia.com/advisories/product/28005/	 SA37499]&lt;br /&gt;
| [http://jeffchannell.com/Joomla/lyften-bloggie-sql-injection-fix.html Un official fix]. Developer fix not release at 30 Nov 09 ''' [http://www.lyften.com/products/lyftenbloggie/extensions/download/id-20.html 1.0.4a (last update on Dec 28, 2009)]'''&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== December 2009 Compiled Reports ==&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  '''Extension'''&lt;br /&gt;
! class=&amp;quot;unsortable&amp;quot;| '''Details'''&lt;br /&gt;
!  '''Reference Link'''&lt;br /&gt;
!  '''Extension Update Link'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Omilen Photo Gallery'''&lt;br /&gt;
|Summary: Directory traversal vulnerability in the [http://extensions.joomla.org/extensions/photos-&amp;amp;-images/photo-flash-gallery/6373/details Omilen Photo Gallery] (com_omphotogallery) component Beta 0.5 for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the controller parameter to index.php.&lt;br /&gt;
Published: 12/04/2009&lt;br /&gt;
|[[NIST:CVE-2009-4202 | CVE-2009-4202]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   | '''Seminar'''&lt;br /&gt;
|Summary: SQL injection vulnerability in the [http://seminar.vollmar.ws/ Seminar] (com_seminar) component 1.28 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a View_seminar action to index.php.&lt;br /&gt;
Published: 12/04/2009&lt;br /&gt;
|[[NIST:CVE-2009-4200 | CVE-2009-4200]]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   | '''  released V1.29, released'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''ProofReader''' &lt;br /&gt;
|Summary: Multiple cross-site scripting (XSS) vulnerabilities in index.php in the ProofReader (com_proofreader) component 1.0 RC9 and earlier for Joomla! allow remote attackers to inject arbitrary web script or HTML via the URI, which is not properly handled in (1) 404 or (2) error pages. Published: 12/02/2009 CVSS Severity: 4.3 (MEDIUM)&lt;br /&gt;
| [[NIST:CVE-2009-4157 | CVE-2009-4157]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''D4J eZine'''&lt;br /&gt;
|Summary: PHP remote file inclusion vulnerability in class/php/d4m_ajax_pagenav.php in the D4J eZine (com_ezine) component 2.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS mosConfig_absolute_path parameter. Published: 11/29/2009 CVSS Severity: 7.5 (HIGH)&lt;br /&gt;
|[[NIST:CVE-2009-4094 | CVE-2009-4094]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''Quick News'''&lt;br /&gt;
| Summary: The Joomla [http://joomlacode.org/gf/project/quicknews/ Quick News component] suffers from a remote SQL injection vulnerability. added 1st Dec 09&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''mojoblog'''&lt;br /&gt;
|Summary [http://www.joomlify.com/files/mojoblog/ MojoBlog] Multiple Remote File Include Vulnerability added 1st Dec 09 {{JVer|1.5}}&lt;br /&gt;
|[http://securityreason.com/exploitalert/7509 7509]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''TP Whois''' &lt;br /&gt;
|summary: [http://www.templateplazza.com/view-details/tpwhois/183-component-tp-whois-for-joomla-1.5.x.html TP Whois ] Malicious users may inject JavaScript, VBScript, ActiveX, HTML or Flash into a vulnerable application to fool a user in order to gather data from them. An attacker can steal the session cookie and take over the account. Added 3 december {{JVer|1.5}}&lt;br /&gt;
|[http://www.exploit-db.com Refrence]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''com_job'''&lt;br /&gt;
|Summary: Component com_job ( showMoreUse) SQL injection vulnerability  Added 9th Dec&lt;br /&gt;
|[http://xforce.iss.net/xforce/xfdb/54626 Reference]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''Mamboleto Component 2.0 RC3'''&lt;br /&gt;
|Summary: [http://www.fernandosoares.com.br/index.php?option=com_docman&amp;amp;task=cat_view&amp;amp;gid=28&amp;amp;Itemid=28 Mamboleto Component 2.0 RC3]SQL injection vulnerability {{JVer|1.5}} added 12 December&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | ''' Kide Shoutbox'''&lt;br /&gt;
|Summary: The Kide Shoutbox (com_kide) component 0.4.6 for Joomla! does not properly perform authentication, which allows remote attackers to post messages with an arbitrary account name via an insertar action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Added: December 08&lt;br /&gt;
|[[NIST:CVE-2009-4232 | CVE-2009-4232]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | ''' JoomPortfolio Component'''&lt;br /&gt;
|Summary: [http://www.joomplace.com/joomportfolio/joomportfolio.html JoomPortfolio] Input passed via the &amp;quot;secid&amp;quot; parameter to index.php (when &amp;quot;option&amp;quot; is set to &amp;quot;com_joomportfolio&amp;quot; and &amp;quot;task&amp;quot; is set to &amp;quot;showcat&amp;quot;) is not properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.The vulnerability is reported in version 1.0.0. Other versions may also be affected. Added: December 18 {{JVer|1.5}}&lt;br /&gt;
|[http://secunia.com/advisories/37838/ Reporting Site]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''City Portal (templates?)'''&lt;br /&gt;
|Summary:   City Portal Blind SQL Injection Vulnerability added: 2009-12-18&lt;br /&gt;
|[http://www.exploit-db.com Reference] Possibly this [http://www.youjoomla.com/jclick-city-portal-joomla-template.html tempate]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''Event Manager'''&lt;br /&gt;
|Summary:  [http://www.jforjoomla.com/Joomla-Components/event-manager-15-component.html Event Manager] Blind SQL Injection Vulnerability EDB-ID: 10549&lt;br /&gt;
added: 2009-12-18&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | com_zcalendar&lt;br /&gt;
|Summary:  com_zcalendar Blind SQL-injection Vulnerability&lt;br /&gt;
EDB-ID: 10548 added: 2009-12-18&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''com_acmisc'''&lt;br /&gt;
|Summary:  com_acmisc SQL injection added: 2009-12-18&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''com_jbook'''&lt;br /&gt;
|Summary:   com_jbook Blind SQL-injection EDB-ID: 10545 added: 2009-12-18 {{JVer|1.0}}&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |  '''com_personel'''&lt;br /&gt;
|Summary: com_personel component for Joomla! is vulnerable to SQL injection.&lt;br /&gt;
|[http://xforce.iss.net/xforce/xfdb/54903 iss.net reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |  '''HotBrackets Tournament Brackets '''&lt;br /&gt;
|Summary: The [http://extensions.joomla.org/extensions/sports-a-games/sports/10746 HotBrackets Tournament Brackets] component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. {{JVer|1.5}} added 22 dec &lt;br /&gt;
|[http://www.securityfocus.com/bid/37439/ Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''Car Manager'''&lt;br /&gt;
|Summary: http://webformatique.com/ com_carman Cross Site Scripting Vulnerability added 24 december 09{{JVer|1.5}}&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot; |'''Schools component'''&lt;br /&gt;
|Summary: The 'com_schools' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.&lt;br /&gt;
|[http://www.securityfocus.com/bid/37469 Reference] added 24 dec 09&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''webcamxp'''&lt;br /&gt;
|[http://extensions.joomla.org/extensions/communication/video-conference/4490 com_webcamxp] Cross Site Scripting Vulnerabilities  Last version 2008 {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''jm-recommend'''&lt;br /&gt;
|jm-recommendCross Site Scripting Vulnerabilities. unable to locate on jed. {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | facileforms&lt;br /&gt;
| com_facileforms Cross Site Scripting Vulnerabilities. unable to locate on jed. Product considered retired.  {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''adagency'''&lt;br /&gt;
| [http://www.ijoomla.com/ijoomla-ad-agency/ijoomla-ad-agency/index/ adagency ]Vulnerabilities {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |  '''com_intuit'''&lt;br /&gt;
|[http://www.san-diego-web-designer.com/new-file-download/item/root/aboutimage-igateway-for-joomla.html com_intuit]Local File Inclusion Vulnerability {{JVer|1.5}} Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | '''  [http://www.securityfocus.com/bid/37494/discuss Retired]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''MemoryBook'''&lt;br /&gt;
|[http://extensions.joomla.org/extensions/calendars-a-events/birthdays-a-historic-events/10868 MemoryBook 1.2]  Multiple Vulnerabilities. requires: magic quotes OFF, user account {{JVer|1.5}} Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''qpersonel'''&lt;br /&gt;
|[http://extensions.joomla.org/extensions/directory-a-documentation/thematic-directory/7049 qpersonel ] Cross Site Scripting Vulnerabilities {{JVer|1.0}}[[Image:http://extensions.joomla.org/images/jed/compat_15_legacy.png]] Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''opryknings point''' &lt;br /&gt;
|com_oprykningspoint_mc Cross Site Scripting Vulnerabilities {{JVer|1.5}} Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''trabalhe conosco'''&lt;br /&gt;
|com_trabalhe_conosco Cross Site Scripting Vulnerabilities {{JVer|1.5}} Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''DhForum'''&lt;br /&gt;
|com_dhforum SQL Injection Vulnerability. considered retired/EOL Dec. 27 {{JVer|1.0}}1.5 legacy&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== January 2010 Reported Vulnerable Extensions ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Please check with the extension publisher in case of any questions over the security of their product.'''&lt;br /&gt;
Report Vulnerable extensions either in the [[jforum:432]] security topic or the [http://forum.joomla.org/viewforum.php?f=470 extensions] topic clearly marked with the first word in the title being ''Vulnerable'' where the security moderators or JSST team will respond. &lt;br /&gt;
''This list is change protected, for updates or editing requests [http://forum.joomla.org/memberlist.php?mode=viewprofile&amp;amp;u=28000 Mandville] or [http://forum.joomla.org/memberlist.php?mode=viewprofile&amp;amp;u=87230 lafrance]&lt;br /&gt;
''&lt;br /&gt;
&lt;br /&gt;
[http://docs.joomla.org/Vulnerable_Extensions_List Back To Top]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  '''Extension'''&lt;br /&gt;
! class=&amp;quot;unsortable&amp;quot;| '''Details'''&lt;br /&gt;
!  '''Reference Link'''&lt;br /&gt;
!  '''Extension Update Link'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   |JvideoDirect&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/multimedia/video-players-a-gallery/9501 Jvideodirect] SQLi Jan 29&lt;br /&gt;
|&lt;br /&gt;
|[http://www.jvideodirect.com/ Update version 2.5]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   |'''JEvent search plugin'''&lt;br /&gt;
|Summary: JEvent search plugin for [http://extensions.joomla.org/extensions/calendars-a-events/events/95 JEvent] SQLi reported Jan 29&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | '''  [http://www.jevents.net/forum/viewtopic.php?f=17&amp;amp;t=3910#p15526 upgrade to 1.5.3b]'''&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   |'''Kunena'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/communication/forum/7256/details kunena] re reported suffering SQLi in version 1.5.9 Jan 29 Confirmation Required '''Now found to be malicious'''&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; | '''  [http://www.kunena.com/blog/19-developer-blog/51-kunena-157-security-release-now-available Versions 1.5.5 and below only]'''&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |'''JE Quiz'''&lt;br /&gt;
|Summary : http://extensions.joomla.org/extensions/contacts-and-feedback/quiz-a-surveys/11212 JeQuiz SQLi reported 29 Jan&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;&amp;quot;   |'''idoblog'''&lt;br /&gt;
|summary: exploitable due to open file permissions. 28 Jan&lt;br /&gt;
|Private Notification&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; | '''  [http://idojoomla.com/news.html build 35 released] '''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;    |'''ccnewsletter'''&lt;br /&gt;
|Summary [http://extensions.joomla.org/extensions/5112/details ccnewsletter Directory Traversal Vulnerability] Jan 28 &lt;br /&gt;
|Private Notification&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | ''' [http://www.chillcreations.com/en/blog/ccnewsletter-joomla-newsletter/ccnewsletter-106-security-release.html version 1.0.6 released 29 Jan]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;   |'''Virtuemart 1.1.4'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/e-commerce/shopping-cart/129 virtuemart] Input var order_status_id is vulnerable to SQLi NB Requires Higher Level access before exploiting. Jan 27&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; | '''  [http://forum.joomla.org/viewtopic.php?p=2027005#p2027005 developer patches]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   |'''JBDiary'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/calendars-a-events/events/11009 JBDiary] BLIND SQL Injection Vulnerabilities Jan 24 [http://www.jb-soft.nl/ http://www.jb-soft.nl/]&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;   | ''' [http://www.jb-soft.nl/index.php?option=com_content&amp;amp;view=article&amp;amp;id=64 Developer Update 27 Jan]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   |'''JbPublishDownFp'''&lt;br /&gt;
|Sumary: [http://extensions.joomla.org/extensions/news-production/timed-content/6496 JbPublishDownFp] SQL Injection Vulnerability Jan 24 [http://www.jb-soft.nl http://www.jb-soft.nl]&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |'''  [http://www.jb-soft.nl/index.php?option=com_content&amp;amp;view=article&amp;amp;id=64 Developer Update Jan 27]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''com_casino'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/sports-a-games/tips-a-betts com_casino]&lt;br /&gt;
SQL Injection Vulnerabilities Jan24&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   |'''Mochigames'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/search/mochigames com_Mochigames]&lt;br /&gt;
SQL Injection Vulnerabilities Jan24&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | ''' [http://www.yoflash.com/download.html mochigames_alpha052 Released]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |'''ContentBlogList'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/news-production/blog/10989 com_ContentBlogList] SQL Injection Vulnerability Jan 23&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |MailChimp for Joomla 1.5&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/bridges/mailing-a-newsletter-bridges/7836 MailChimp for Joomla 1.5]  jan 17&lt;br /&gt;
|Developer Statement&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |'''JoomlaXML'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/tools/design-tools/5020 JoomlaXML] malicious code insertion&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''JVClouds3D SWF module'''&lt;br /&gt;
|[http://joomlapro.ru/3djvclouds JVClouds3D SWF module] Cross Site Scripting . jan 14&lt;br /&gt;
|[http://xforce.iss.net/xforce/xfdb/55535 xforce]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''JVClouds3D'''&lt;br /&gt;
|[http://joomlapro.ru/3djvclouds JVClouds3D module] Cross Site Scripting . jan 14&lt;br /&gt;
|[http://xforce.iss.net/xforce/xfdb/55534 xforce]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |'''JA Showcase'''&lt;br /&gt;
|[http://www.joomlart.com/addons/components_and_modules/ja_showcase.html JA Showcase component] Directory Traversal jan 14&lt;br /&gt;
|[http://xforce.iss.net/xforce/xfdb/55512 xforce]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |'''jprojects'''&lt;br /&gt;
|Summary:   Unknown Author com_j-projects Blind SQL Injection Vulnerability. Jan 10 detail update&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |'''jEmbed-Embed Anything'''&lt;br /&gt;
|[http://www.joshprakash.com/index.php?option=com_docman&amp;amp;task=doc_details&amp;amp;gid=70 jEmbed-Embed Anything] A vulnerability has been discovered in the jEmbed-Embed Anything component for Joomla, which can be exploited by malicious people to conduct SQL injection attacks. Jan 10&lt;br /&gt;
|[http://secunia.com/advisories/38112 Secunia Advisory: SA38112] &lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | [http://extensions.joomla.org/extensions/3699/details Product considered retired]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;    |'''perchagallery '''&lt;br /&gt;
|Summary: perchagallery  [http://extensions.joomla.org/extensions/photos-a-images/photo-gallery/10350 com_perchagallery] SQL Injection Vulnerability  Jan 7&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | '''  [http://www.percha.com/index.php?option=com_phocadownload&amp;amp;view=file&amp;amp;id=22:1.5&amp;amp;Itemid=20 Developer Update 1.5b]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0;  color:black&amp;quot;   |  '''CARTwebERP'''&lt;br /&gt;
|Summary:  [http://extensions.joomla.org/extensions/bridges/e-commerce-bridges/8753 CARTwebERP] Local File Inclusion Vulnerability  Jan. 3&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | '''  [http://extensions.joomla.org/extensions/bridges/e-commerce-bridges/8753 1.56.76 (last update on Jan 11, 2010)]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |   '''JoomlaBibleStudy'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/miscellaneous/religion/3461 JoomlaBibleStudy] LFI Vulnerability  Jan. 3&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;   | '''[http://joomlabiblestudy.org/invisible-downloads/category/3-component.html Developer reported update]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |  '''com_bfsurvey_basic and pro'''&lt;br /&gt;
|Summary: [http://www.tamlyncreative.com.au/software/ BFsurvey] SQL Injection Vulnerability ,LFI Vulnerability   Jan. 3&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | '''  [http://www.tamlyncreative.com.au/software/forum/index.php?topic=641.0 Developer Update announcement]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''Alfresco'''&lt;br /&gt;
|Summary:  SQL Injection Vulnerability. Not believed to be Joomlatools extension Jan. 3&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''abbrev'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/directory-a-documentation/glossary-a-dictionary/4965 abbrev] Local File Inclusion Vulnerability Jan. 3&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''countries'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/miscellaneous/development/6553 countries] SQL Injection Vulnerability  Jan. 3&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   |  '''Dedicated Component com_tpjobs'''&lt;br /&gt;
|Summary: [http://www.templateplazza.com/ tpjobs] SQL Injection Vulnerability unable to locate files probably template plaza  Jan. 3&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;     | '''  [http://www.templateplazza.com/extensions-updates/tpjobs-component-update-v-1.1.html Developer Update] '''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''Component com_doqment'''&lt;br /&gt;
|SQL Injection Vulnerability Jan. 3&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''Component com_otzivi''' &lt;br /&gt;
|Blind SQL Injection Vulnerability  Jan. 3&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''aprice'''&lt;br /&gt;
|Summary: [http://adeptweb.info/component/option,com_aprice/Itemid,109/ com_aprice] Component 'analog' Parameter SQL Injection Vulnerability&lt;br /&gt;
|[http://www.securityfocus.com/bid/37575 Report]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |'''cartikads'''&lt;br /&gt;
|Summary: [http://www.cartikahosting.com com_cartikads] Remote File Upload Vulnerability &lt;br /&gt;
'''Mambo''' Open Source ads management component&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   | '''Docman seller''' &lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/e-commerce/subscriptions/5000 Document seller]  Input passed via the &amp;quot;id&amp;quot; parameter to index.php (when &amp;quot;option&amp;quot; is set to &amp;quot;com_dm_orders&amp;quot;, &amp;quot;task&amp;quot; is set to &amp;quot;order_form&amp;quot;, and &amp;quot;payment_method&amp;quot; is set to &amp;quot;Paypal&amp;quot;) is not properly sanitised before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.&lt;br /&gt;
|[http://secunia.com/advisories/38024/ secunia]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;   | [http://extensions.joomla.org/extensions/e-commerce/subscriptions/5000 Updated 10th Jan]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |  '''ozio gallery''' &lt;br /&gt;
|summary: [http://extensions.joomla.org/extensions/photos-a-images/photo-flash-gallery/4883 Ozio Gallery2] SQLi eploit &lt;br /&gt;
|[http://www.viruslist.com/en/advisories/37974 Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;   |[http://oziogallery.joomla.it/index.php?option=com_content&amp;amp;view=article&amp;amp;id=62%3Anuova-ozio-gallery-23-aggiornamento-di-sicurezza&amp;amp;catid=2%3Anotizie&amp;amp;Itemid=13&amp;amp;lang=en developer update Jan 11]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   | '''RD-Autos Free''' &lt;br /&gt;
|[http://extensions.joomla.org/extensions/vertical-markets/vehicles/5458 RD-Autos Free ] This version is now commercial not free&lt;br /&gt;
|Private advisory to JED Jan 11&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | ''' Product Retired and replaced'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''DailyMeals'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/vertical-markets/food-a-beverage/4764 dailymeals] Local File Inclusion  Vulnerability  Jan 02&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''RD-Autos Pro''' &lt;br /&gt;
|[http://extensions.joomla.org/extensions/vertical-markets/vehicles/6357 RD Autos Pro]&lt;br /&gt;
|Private advisory to JED Jan 11&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   | '''  Upgrade to  Latest version  be 2.0.2'''&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
[[Category:Security]]&lt;/div&gt;</summary>
		<author><name>CirTap</name></author>	</entry>

	<entry>
		<id>http://docs.joomla.org/Vulnerable_Extensions_List/Archive/2010-11</id>
		<title>Vulnerable Extensions List/Archive/2010-11</title>
		<link rel="alternate" type="text/html" href="http://docs.joomla.org/Vulnerable_Extensions_List/Archive/2010-11"/>
				<updated>2011-07-15T12:31:26Z</updated>
		
		<summary type="html">&lt;p&gt;CirTap: moved Vulnerable Extensions List/Archive/2010-11 to Vulnerable Extensions List (Archived) over redirect&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;#REDIRECT [[Vulnerable Extensions List (Archived)]]&lt;/div&gt;</summary>
		<author><name>CirTap</name></author>	</entry>

	<entry>
		<id>http://docs.joomla.org/Vulnerable_Extensions_List_(Archived)</id>
		<title>Vulnerable Extensions List (Archived)</title>
		<link rel="alternate" type="text/html" href="http://docs.joomla.org/Vulnerable_Extensions_List_(Archived)"/>
				<updated>2011-07-15T12:31:26Z</updated>
		
		<summary type="html">&lt;p&gt;CirTap: moved Vulnerable Extensions List/Archive/2010-11 to Vulnerable Extensions List (Archived) over redirect&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{underconstruction}} &lt;br /&gt;
For a more recent list please see [[Vulnerable_Extensions_List_oct]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;3&amp;quot; cellspacing=&amp;quot;3&amp;quot;&amp;gt;&lt;br /&gt;
		&amp;lt;tr style=&amp;quot;background-color: #ff9900&amp;quot; valign=&amp;quot;bottom&amp;quot;&amp;gt;&lt;br /&gt;
			&amp;lt;th align=&amp;quot;left&amp;quot; width=&amp;quot;25%&amp;quot;&amp;gt;Name&amp;lt;/th&amp;gt;&lt;br /&gt;
  			&amp;lt;th align=&amp;quot;left&amp;quot;&amp;gt;Versions&amp;lt;/th&amp;gt;&lt;br /&gt;
			&amp;lt;th align=&amp;quot;left&amp;quot;&amp;gt;Solution&amp;lt;/th&amp;gt;&lt;br /&gt;
			&amp;lt;th align=&amp;quot;left&amp;quot;&amp;gt;References&amp;lt;/th&amp;gt;&lt;br /&gt;
			&amp;lt;th&amp;gt;Updated&amp;lt;/th&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;A6MamboCredits&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;com_a6mambocredits&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;All &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Abandoned. Remove completely or use at your own risk.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://secunia.com/advisories/21540/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,86978.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;A6MamboHelpDesk&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_a6mambohelpdesk &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned. Remove completely or use at your own risk.&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,80890.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://secunia.com/advisories/21540/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			 [http://secunia.com/advisories/21227/ Secunia Advisory] &lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;Advanced Poll&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_advancedpoll (?) &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 2.2.0&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &lt;br /&gt;
			Abandoned. Remove completely or use at your own risk. &lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; [http://forum.joomla.org/index.php/topic,76621.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt;Adobe Acrobat Reader&amp;lt;/b&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;i&amp;gt;(Not a Joomla! extension, but worth noting.)&amp;lt;/i&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 7.0.8&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version.&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://www.adobe.com/support/security/advisories/apsa07-01.html Adobe Advisory] &lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;lt;b&amp;gt;Akocomment&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;SQL Injection with PHP magic_quotes OFF. No upgrade path yet. &amp;lt;br /&amp;gt;&lt;br /&gt;
			Fix: Turn PHP magic_quotes ON&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php?topic=185805.msg882326#msg882326 Forum Topic]&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;June 30, 2006&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt;Article&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.1&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; [http://www.milw0rm.com/exploits/3736 milwOrm Advisory]&amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://www.frsirt.com/english/adisories/2007/1394 FrSIRT Advisory]&amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,160876.msg775119.html#msg775119 Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 26 June 2007&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;ArtLinks&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_artlinks &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All &lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned.  Remove completely or use at your own risk.&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,76328.0.html Forum Topic] &lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;lt;b&amp;gt;AutoStand &amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.1&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; No further information at this time.&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;[http://www.milw0rm.com/exploits/3734 milwOrm Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://www.frsirt.com/english/advisories/2007/1392 FrSIRT Advisory]&amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,160876.msg775119.html#msg775119 Forum Topic]&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;amp;nbsp;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 26 June 2007&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Bayesian Naive Filter&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			com_bayesiannaivefilter &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.1&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; No Fix Available. Disable or remove until a fix is available.&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,81594.0.html Forum Topic] &lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Bible Study&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			com_biblestudy &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 6.0.7b and below&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Fix Available. SQL Insertion attack&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;http://joomlacode.org/gf/project/biblestudy/&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2008&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;BigApe Backup&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_babackup &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; A patch is available from the developer.  [http://forum.joomla.org/index.php/topic,87736.msg465256.html#msg465256 See this post.] &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://secunia.com/advisories/21574/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,87736.0.html Forum Topic] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;BSQ Site Stats&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_bsqsitestats &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 2.2.1&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version.&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,77899.0.html Forum Topic]&amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://secunia.com/advisories/22142/ Secunia Advisory] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt;Car Manager&amp;lt;/b&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.1&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  No further information at this time.&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,154777.msg748946.html#msg748946 Forum Topic] &amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 26 June 2007&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;Classifieds&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_classifieds &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.3&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,82457.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Colophon&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_colophon &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.2&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://secunia.com/advisories/21288/ Secunia Advisory]&amp;lt;br /&amp;gt;&lt;br /&gt;
			[http://forum.joomla.org/index.php/topic,81587.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Community Builder&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_profiler &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.0.0&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			Upgrade to latest stable version.&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			[http://forum.joomla.org/index.php/topic,86525.msg441456.html#msg441456 See here for a fix for register_globals = off] &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://www.joomlapolis.com/content/view/1538/37/ Jomopolis Topic]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			[http://forum.joomla.org/index.php/topic,84436.0.html Forum Topic]&amp;lt;br /&amp;gt;&lt;br /&gt;
			[http://forum.joomla.org/index.php/topic,86525.msg441456.html#msg441456 Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;DS-Syndicate&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_ds-syndicate &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;All versions?&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;SQL injection vulnerability.&amp;lt;br /&amp;gt;&lt;br /&gt;
			Remove completely or use at your own risk.&amp;lt;br /&amp;gt;Component has been removed from JED. Abandoned?&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &lt;br /&gt;
			[http://www.frsirt.com/english/advisories/2008/2859 http://www.frsirt.com/english/advisories/2008/2859] &lt;br /&gt;
			&amp;lt;td&amp;gt;Nov. 27, 2008&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;Events&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_events &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.3 Beta&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,80411.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt;Expose Flash Gallery&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; RC4&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://joomlacode.org/gf/project/expose/frs/?action=FrsReleaseView&amp;amp;amp;release_id=5053 Download patch]&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,192172.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;20 July 2007&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;ExtCalendar&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_extcalendar &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 0.9.1&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to version 0.9.2.  See[http://forum.joomla.org/index.php/topic,75390.msg402249.html#msg402249 this post] for details. Also check the new forked project, JCal. &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; [http://secunia.com/advisories/19321/ Secunia Advisory]&amp;lt;br /&amp;gt;&lt;br /&gt;
			[http://forum.joomla.org/index.php/topic,75390.0.html Forum Topic]&amp;lt;br /&amp;gt;&lt;br /&gt;
			[http://forum.joomla.org/index.php/topic,79050.0.html Forum Topic]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			[http://forum.joomla.org/index.php/topic,78268.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Facile Forms&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_facileforms &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.4.6&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,98973.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Galleria&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_galleria &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned.  Remove completely or use at your own risk.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-3396 NVD Advisory]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			[http://forum.joomla.org/index.php/topic,77706.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Gmaps&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_gmaps&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;amp;lt;=1.01 &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to the latest version, which can be downloaded [http://firestorm-technologies.com/component/option,com_docman/Itemid,27/task,doc_download/gid,22/ here]&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://www.securityfocus.com/bid/25146 Security Focus Advisory]&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 6 August 2007&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;Hash Cash&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_hashcash &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned.  Remove completely or use at your own risk.&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://secunia.com/product/11046/ Secunia Advisory]&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;Hot Property&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_hotproperties (?) &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 0.97&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to [http://www.mosets.com/download/ latest stable version].&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; No references available at this time.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;JCE&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_jce &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.0.4&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Apply patch, download it [http://www.cellardoor.za.net/index.php?option=com_docman&amp;amp;amp;task=cat_view&amp;amp;amp;gid=1&amp;amp;amp;Itemid=6 here], or use latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			[http://secunia.com/advisories/23160/ Secunia Advisory]&amp;lt;br /&amp;gt;&lt;br /&gt;
			[http://www.cellardoor.za.net/ Cellardoor]&amp;lt;br /&amp;gt;&lt;br /&gt;
			[http://secunia.com/advisories/23160/ Secunia Advisory] &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;JoomlaPack&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_jpack &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 1.0.4a2 RE&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version.&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			 [http://www.milw0rm.com/exploits/3753 MilwOrm Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://www.frsirt.com/english/advisories/2007/1429 FrSIRT Advisory]  &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;JoomlaBoard&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_joomlaboard &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.1.1&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			Upgrade to latest stable version.&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,86525.msg441456.html#msg441456 RG_EMULATION Fix]  &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://secunia.com/advisories/21059/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,76852.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,86525.msg441513.html#msg441513 Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;JoomlaLib&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_joomlalib &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.2.1&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,77899.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;JD-WordPress&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_jd-wp &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 2.0-1.0 RC2&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Patch Available.  &amp;lt;br /&amp;gt;&lt;br /&gt;
			See [http://forum.joomla.org/index.php/topic,81064.msg418374.html#msg418374 this post]. &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,81064.0.html Forum Topic] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			JD-Wiki&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_jd-wiki &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;All &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			Abandoned project. &amp;lt;br /&amp;gt;&lt;br /&gt;
			Upgrade to [http://joomlacode.org/gf/project/nuwiki/ nuWiki] &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,80188.msg427986.html#msg427986 Forum Topic] &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php?topic=177926.0 Forum Topic] &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;6 July 2007&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;&lt;br /&gt;
			JIM 1.0.1. (PMS)&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			com_jim &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 1.0.1&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version. The developer fixed security issues but didn't create a higher version number.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://secunia.com/advisories/21545/ Secunia Advisory] &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt;joomSEF (&amp;lt;/b&amp;gt;&amp;lt;b&amp;gt;ARTIO)&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;=2.2.1&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,226147.0.html  Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;27 Oct 2007&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;jPack&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_jpack &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;amp;lt;  1.0.4-b1&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,163589.msg847010.html#msg847010 Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 26 June 2007&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Link Directory&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_linkdirectory &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Remove. Abandoned project.&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; No references.&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Letterman&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			mod_letterman &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.2.4&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version. [http://www.thejfactory.com] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php?topic=180367 Forum Topic]  &lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; May 2007&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;LMO&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_lmo &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.0b2&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version. [http://forge.joomla.org/sf/frs/do/viewRelease/projects.lmo/frs.com_lmo.com_lmo_1_0_b3  ] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://www.frsirt.com/english/advisories/2006/3063 FrSIRT Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,81590.0.html Forum Topic] &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;LoudMouth&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_loudmouth &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 4.0j&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to version 4.1 then apply Security Patch 1.   [http://mamboxchange.com/frs/?group_id=39&amp;amp;amp;release_id=5995 Download here].&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://forum.joomla.org/index.php/topic,76337.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			 [http://mamboxchange.com/forum/forum.php?forum_id=7638 MamboExchange Advisory]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;MamCom (?)&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_trade &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned.  Remove completely or use at your own risk. &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; *Unconfirmed*&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;MambelFish 1.x&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_mambelfish &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.x&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to 1.5 (or to Joom!Fish)   [http://mamboxchange.com/frs/download.php/4518/MambelFish_1.5.zip Download Mambelfish&amp;lt;br /&amp;gt;]   [http://extensions.joomla.org/component/option,com_mtree/task,viewlink/link_id,460/Itemid,35/ Download Joom!Fish] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://secunia.com/advisories/21544/ Secunia Advisory] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;&lt;br /&gt;
			Mambo Gallery Manager&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/b&amp;gt;com_mgm&amp;lt;b&amp;gt; &lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned.  Remove completely or use at your own risk.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://forum.joomla.org/index.php/topic,81616.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			 [http://www.frsirt.com/english/advisories/2006/3054 FrSIRT Advisory] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;MiniBB&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_minibb &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.5a&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned.  Remove completely or use at your own risk.&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			 [http://securityreason.com/exploitalert/846 Security Reason Advisory]   [http://forum.joomla.org/index.php/topic,76898.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://securityreason.com/exploitalert/846 Security Reason] &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Mos Tree&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_mtree &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.5.8&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version. [http://www.mosets.com/download/] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://forum.joomla.org/index.php/topic,78298.0.html Forum Topic] &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;MosMedia&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_mosmedia &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.0.8&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Temporary Fix Available.  See  [http://forum.joomla.org/index.php/topic,78533.0.html this thread] for details.&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://forum.joomla.org/index.php/topic,78533.0.html Forum Topic] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;MoSpray&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_mospray&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.8 RC1&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned.  Remove completely or use at your own risk.&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://forum.joomla.org/index.php/topic,76331.0.html Forum Topic] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Multibanners&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_multibanners &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;i&amp;gt;* Note: Not the same as the Multibanners Module.&amp;lt;/i&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned.  Remove completely or use at your own risk.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://secunia.com/advisories/21168/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,77977.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;OpenSEF&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_sef &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 2.0.0 RC5 Unpatched&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; [http://projects.j-prosolution.com/project-news/opensef-news/security-patch-for-opensef.html Download patch] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt; [http://forum.joomla.org/index.php/topic,77301.0.html Forum Topic] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;PC Cook Book&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_pccookbook &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.3.1&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; No Fix Available. Disable or remove.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://www.frsirt.com/english/advisories/2006/2739 FrSIRT Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,76009.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Per Forms&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_performs &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;amp;lt;= v1_beta &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version. [http://forge.joomla.org/sf/frs/do/viewRelease/projects.performs/frs.com_performs.com_performs_v2_beta ] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://secunia.com/advisories/21044/ Secunia Advisory]&amp;lt;br /&amp;gt;   [http://forum.joomla.org/index.php/topic,76654.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,76862.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;lt;b&amp;gt;Phil-A-Form&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt; 1.2&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to latest version.&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://forum.joomla.org/index.php?topic=174770.new#new Forum Topic] &lt;br /&gt;
&lt;br /&gt;
			&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; May 2007&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;People Book&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_peoplebook &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.1.5&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version. [http://forge.joomla.org/sf/frs/do/viewRelease/projects.peoplebook/frs.component.component_1_1_6_0] &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forge.joomla.org/sf/go/artf5410?nav=1 Joomla Forge]  &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;Prince Clan Chess&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_pcchess &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 0.8&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Author suggest manually patching. [http://www.princeclan.org/] &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; See  [http://www.princeclan.org/ this site]. &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;PollXT&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_pollxt &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.22.07&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version. [http://www.joomlaxt.com/index.php?option=com_remository&amp;amp;amp;Itemid=77&amp;amp;amp;func=fileinfo&amp;amp;amp;id=9] &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; [http://secunia.com/advisories/21068/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,77975.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://secunia.com/advisories/21068/ Secunia Advisory] &lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt; RS Gallery2&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_rsgallery2&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.11.3&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version. [http://forge.joomla.org/sf/go/projects.rsgallery2/frs.rsg2_alpha_builds.rsg2_1_11_4]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://forum.joomla.org/index.php/topic,73453.0.html Forum Topic] &lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 06&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt;RWCards&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt; 2.4.4&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt; [http://forum.joomla.org/index.php/topic,154792.msg749006.html#msg749006 Forum Topic] &amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 26 June 2007&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;lt;b&amp;gt;Security Images&amp;lt;/b&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			com_securityimages&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 3.0.5&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://secunia.com/advisories/21260/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,81589.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; June 2007&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;lt;b&amp;gt;SEF404x&amp;lt;/b&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
			com_sef&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; No Fix Available.  Remove completely or use at your own risk.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; No references.&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;2006&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt;sh404SEF&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;1.2.4 t, u, or w &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Patch or update.&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt; [http://forum.joomla.org/index.php/topic,226147.0.html  Forum Topic] &amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;23 Oct, 2007&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Site Map&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_sitemap &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned.  Remove completely or use at your own risk.&amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://www.simplemachines.org/community/index.php?topic=97649.0] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &lt;br /&gt;
			 [http://secunia.com/advisories/21055/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,76326.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://secunia.com/advisories/21055/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;SimpleBoard&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_simpleboard &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest JoomlaBoard.  JoomlaBoard is compatible with SimpleBoard.  [http://developer.joomla.org/sf/frs/do/viewRelease/projects.simpleboard/frs.joomlaboard_1_1.joomlaboard_1_1_2 Download here].&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			 [http://secunia.com/advisories/20981/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://secunia.com/advisories/20409/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,75668.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://secunia.com/advisories/20981/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;SMF Bridge&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_smf &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.1.4&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			Versions other than 1.1RC2.  Fix Available.   [http://www.simplemachines.org/community/index.php?topic=100140.0 See this thread]. &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;amp;nbsp;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			Version 1.1RC2 only.  Upgrade available.  &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://www.simplemachines.org/community/index.php?topic=97649.0 See this thread.]  &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://secunia.com/advisories/21079/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://www.simplemachines.org/community/index.php?topic=100140.0 Simple Machines Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,78313.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,77716.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,78359.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,76609.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			 [http://secunia.com/advisories/21079/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;TaskHopper&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_thopper &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.1&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to latest version.&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,159111.0.html Forum Topic] &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;User Home Pages 1 and 2&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_uhp and com_uhp2 &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.1.1 (?)&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version. [http://www.ravenswoodit.co.uk/index.php?option=com_docman&amp;amp;amp;task=cat_view&amp;amp;amp;gid=78&amp;amp;amp;Itemid=13] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://forum.joomla.org/index.php/topic,81308.msg416865.html#msg416865 Forum Topic]&amp;lt;br /&amp;gt;&lt;br /&gt;
   [http://secunia.com/advisories/21305/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,81308.msg416865.html#msg416865 Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; June 2007&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt;VirtueMart&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.0.13a&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to version &amp;gt;= 1.0.14. Available  [http://virtuemart.net/index.php?option=com_content&amp;amp;task=view&amp;amp;id=54&amp;amp;Itemid=147 here]. &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; [http://virtuemart.net/index.php?option=com_content&amp;amp;task=view&amp;amp;id=275&amp;amp;Itemid=127 Security Bulletin] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;January 2008&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt;WordPress&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/b&amp;gt;&amp;lt;i&amp;gt;(Not a Joomla! extension, but worth noting.)&amp;lt;/i&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2.1.1&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,146478.msg737784.html#msg737784 Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 26 June 2007&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;lt;b&amp;gt;zOOm Media Gallery&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;amp;lt;= 2.5.1 RC4&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; [http://www.zoomfactory.org/index.php?option=com_remository&amp;amp;amp;Itemid=61&amp;amp;amp;func=select&amp;amp;amp;id=1 Upgrade to latest stable version].&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; [http://www.frsirt.com/english/advisories/2007/1353 FrSIRT Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,160119.0.html Forum Topic] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
                &amp;lt;tr&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt; &amp;lt;b&amp;gt;BF Survey Pro&amp;lt;br /&amp;gt;BF Survey Basic&amp;lt;br /&amp;gt;BF Quiz&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt;&amp;amp;lt;=1.2.5&amp;lt;br /&amp;gt;&amp;amp;lt;=1.0&amp;lt;br /&amp;gt;&amp;amp;lt;=1.1.1&amp;lt;/td&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt;[http://www.tamlyncreative.com.au/software/index.php/downloads.html Upgrade to latest versions]&amp;lt;/td&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt;[http://forum.joomla.org/viewtopic.php?f=431&amp;amp;t=336055&amp;amp;start=0 Forum Post]&amp;lt;br /&amp;gt;[http://www.tamlyncreative.com.au/software/forum/index.php?topic=357.0 Developer's Forum Post]&amp;lt;/td&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt;September, 2009&amp;lt;/td&amp;gt;&lt;br /&gt;
                &amp;lt;/tr&amp;gt;&lt;br /&gt;
                &amp;lt;tr&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt; &amp;lt;b&amp;gt;Photoblog (com_photoblog)&amp;lt;/td&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt;Unknown&amp;lt;/td&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt;Unknown&amp;lt;/td&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt;[http://www.securityfocus.com/bid/36809/info Security Focus Advisory]&amp;lt;/td&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt;October 26, 2009&amp;lt;/td&amp;gt;&lt;br /&gt;
                &amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Security]]&lt;br /&gt;
[[Category:Security_FAQ]]&lt;/div&gt;</summary>
		<author><name>CirTap</name></author>	</entry>

	<entry>
		<id>http://docs.joomla.org/Vulnerable_Extensions_List_(Archived)</id>
		<title>Vulnerable Extensions List (Archived)</title>
		<link rel="alternate" type="text/html" href="http://docs.joomla.org/Vulnerable_Extensions_List_(Archived)"/>
				<updated>2011-07-15T12:25:34Z</updated>
		
		<summary type="html">&lt;p&gt;CirTap: Reverted edits by CirTap (talk) to last revision by Chris Davenport&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{underconstruction}} &lt;br /&gt;
For a more recent list please see [[Vulnerable_Extensions_List_oct]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;3&amp;quot; cellspacing=&amp;quot;3&amp;quot;&amp;gt;&lt;br /&gt;
		&amp;lt;tr style=&amp;quot;background-color: #ff9900&amp;quot; valign=&amp;quot;bottom&amp;quot;&amp;gt;&lt;br /&gt;
			&amp;lt;th align=&amp;quot;left&amp;quot; width=&amp;quot;25%&amp;quot;&amp;gt;Name&amp;lt;/th&amp;gt;&lt;br /&gt;
  			&amp;lt;th align=&amp;quot;left&amp;quot;&amp;gt;Versions&amp;lt;/th&amp;gt;&lt;br /&gt;
			&amp;lt;th align=&amp;quot;left&amp;quot;&amp;gt;Solution&amp;lt;/th&amp;gt;&lt;br /&gt;
			&amp;lt;th align=&amp;quot;left&amp;quot;&amp;gt;References&amp;lt;/th&amp;gt;&lt;br /&gt;
			&amp;lt;th&amp;gt;Updated&amp;lt;/th&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;A6MamboCredits&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;com_a6mambocredits&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;All &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Abandoned. Remove completely or use at your own risk.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://secunia.com/advisories/21540/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,86978.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;A6MamboHelpDesk&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_a6mambohelpdesk &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned. Remove completely or use at your own risk.&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,80890.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://secunia.com/advisories/21540/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			 [http://secunia.com/advisories/21227/ Secunia Advisory] &lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;Advanced Poll&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_advancedpoll (?) &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 2.2.0&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &lt;br /&gt;
			Abandoned. Remove completely or use at your own risk. &lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; [http://forum.joomla.org/index.php/topic,76621.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt;Adobe Acrobat Reader&amp;lt;/b&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;i&amp;gt;(Not a Joomla! extension, but worth noting.)&amp;lt;/i&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 7.0.8&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version.&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://www.adobe.com/support/security/advisories/apsa07-01.html Adobe Advisory] &lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;lt;b&amp;gt;Akocomment&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;SQL Injection with PHP magic_quotes OFF. No upgrade path yet. &amp;lt;br /&amp;gt;&lt;br /&gt;
			Fix: Turn PHP magic_quotes ON&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php?topic=185805.msg882326#msg882326 Forum Topic]&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;June 30, 2006&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt;Article&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.1&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; [http://www.milw0rm.com/exploits/3736 milwOrm Advisory]&amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://www.frsirt.com/english/adisories/2007/1394 FrSIRT Advisory]&amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,160876.msg775119.html#msg775119 Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 26 June 2007&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;ArtLinks&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_artlinks &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All &lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned.  Remove completely or use at your own risk.&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,76328.0.html Forum Topic] &lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;lt;b&amp;gt;AutoStand &amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.1&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; No further information at this time.&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;[http://www.milw0rm.com/exploits/3734 milwOrm Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://www.frsirt.com/english/advisories/2007/1392 FrSIRT Advisory]&amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,160876.msg775119.html#msg775119 Forum Topic]&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;amp;nbsp;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 26 June 2007&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Bayesian Naive Filter&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			com_bayesiannaivefilter &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.1&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; No Fix Available. Disable or remove until a fix is available.&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,81594.0.html Forum Topic] &lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Bible Study&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			com_biblestudy &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 6.0.7b and below&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Fix Available. SQL Insertion attack&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;http://joomlacode.org/gf/project/biblestudy/&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2008&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;BigApe Backup&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_babackup &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; A patch is available from the developer.  [http://forum.joomla.org/index.php/topic,87736.msg465256.html#msg465256 See this post.] &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://secunia.com/advisories/21574/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,87736.0.html Forum Topic] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;BSQ Site Stats&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_bsqsitestats &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 2.2.1&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version.&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,77899.0.html Forum Topic]&amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://secunia.com/advisories/22142/ Secunia Advisory] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt;Car Manager&amp;lt;/b&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.1&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  No further information at this time.&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,154777.msg748946.html#msg748946 Forum Topic] &amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 26 June 2007&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;Classifieds&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_classifieds &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.3&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,82457.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Colophon&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_colophon &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.2&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://secunia.com/advisories/21288/ Secunia Advisory]&amp;lt;br /&amp;gt;&lt;br /&gt;
			[http://forum.joomla.org/index.php/topic,81587.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Community Builder&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_profiler &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.0.0&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			Upgrade to latest stable version.&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			[http://forum.joomla.org/index.php/topic,86525.msg441456.html#msg441456 See here for a fix for register_globals = off] &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://www.joomlapolis.com/content/view/1538/37/ Jomopolis Topic]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			[http://forum.joomla.org/index.php/topic,84436.0.html Forum Topic]&amp;lt;br /&amp;gt;&lt;br /&gt;
			[http://forum.joomla.org/index.php/topic,86525.msg441456.html#msg441456 Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;DS-Syndicate&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_ds-syndicate &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;All versions?&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;SQL injection vulnerability.&amp;lt;br /&amp;gt;&lt;br /&gt;
			Remove completely or use at your own risk.&amp;lt;br /&amp;gt;Component has been removed from JED. Abandoned?&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &lt;br /&gt;
			[http://www.frsirt.com/english/advisories/2008/2859 http://www.frsirt.com/english/advisories/2008/2859] &lt;br /&gt;
			&amp;lt;td&amp;gt;Nov. 27, 2008&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;Events&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_events &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.3 Beta&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,80411.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt;Expose Flash Gallery&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; RC4&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://joomlacode.org/gf/project/expose/frs/?action=FrsReleaseView&amp;amp;amp;release_id=5053 Download patch]&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,192172.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;20 July 2007&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;ExtCalendar&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_extcalendar &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 0.9.1&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to version 0.9.2.  See[http://forum.joomla.org/index.php/topic,75390.msg402249.html#msg402249 this post] for details. Also check the new forked project, JCal. &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; [http://secunia.com/advisories/19321/ Secunia Advisory]&amp;lt;br /&amp;gt;&lt;br /&gt;
			[http://forum.joomla.org/index.php/topic,75390.0.html Forum Topic]&amp;lt;br /&amp;gt;&lt;br /&gt;
			[http://forum.joomla.org/index.php/topic,79050.0.html Forum Topic]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			[http://forum.joomla.org/index.php/topic,78268.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Facile Forms&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_facileforms &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.4.6&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,98973.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Galleria&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_galleria &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned.  Remove completely or use at your own risk.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-3396 NVD Advisory]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			[http://forum.joomla.org/index.php/topic,77706.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Gmaps&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_gmaps&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;amp;lt;=1.01 &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to the latest version, which can be downloaded [http://firestorm-technologies.com/component/option,com_docman/Itemid,27/task,doc_download/gid,22/ here]&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://www.securityfocus.com/bid/25146 Security Focus Advisory]&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 6 August 2007&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;Hash Cash&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_hashcash &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned.  Remove completely or use at your own risk.&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://secunia.com/product/11046/ Secunia Advisory]&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;Hot Property&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_hotproperties (?) &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 0.97&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to [http://www.mosets.com/download/ latest stable version].&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; No references available at this time.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;JCE&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_jce &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.0.4&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Apply patch, download it [http://www.cellardoor.za.net/index.php?option=com_docman&amp;amp;amp;task=cat_view&amp;amp;amp;gid=1&amp;amp;amp;Itemid=6 here], or use latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			[http://secunia.com/advisories/23160/ Secunia Advisory]&amp;lt;br /&amp;gt;&lt;br /&gt;
			[http://www.cellardoor.za.net/ Cellardoor]&amp;lt;br /&amp;gt;&lt;br /&gt;
			[http://secunia.com/advisories/23160/ Secunia Advisory] &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;JoomlaPack&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_jpack &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 1.0.4a2 RE&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version.&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			 [http://www.milw0rm.com/exploits/3753 MilwOrm Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://www.frsirt.com/english/advisories/2007/1429 FrSIRT Advisory]  &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;JoomlaBoard&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_joomlaboard &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.1.1&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			Upgrade to latest stable version.&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,86525.msg441456.html#msg441456 RG_EMULATION Fix]  &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://secunia.com/advisories/21059/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,76852.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,86525.msg441513.html#msg441513 Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;JoomlaLib&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_joomlalib &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.2.1&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,77899.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;JD-WordPress&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_jd-wp &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 2.0-1.0 RC2&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Patch Available.  &amp;lt;br /&amp;gt;&lt;br /&gt;
			See [http://forum.joomla.org/index.php/topic,81064.msg418374.html#msg418374 this post]. &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,81064.0.html Forum Topic] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			JD-Wiki&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_jd-wiki &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;All &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			Abandoned project. &amp;lt;br /&amp;gt;&lt;br /&gt;
			Upgrade to [http://joomlacode.org/gf/project/nuwiki/ nuWiki] &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,80188.msg427986.html#msg427986 Forum Topic] &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php?topic=177926.0 Forum Topic] &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;6 July 2007&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;&lt;br /&gt;
			JIM 1.0.1. (PMS)&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			com_jim &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 1.0.1&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version. The developer fixed security issues but didn't create a higher version number.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://secunia.com/advisories/21545/ Secunia Advisory] &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt;joomSEF (&amp;lt;/b&amp;gt;&amp;lt;b&amp;gt;ARTIO)&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;=2.2.1&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,226147.0.html  Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;27 Oct 2007&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;jPack&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_jpack &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;amp;lt;  1.0.4-b1&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,163589.msg847010.html#msg847010 Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 26 June 2007&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Link Directory&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_linkdirectory &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Remove. Abandoned project.&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; No references.&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Letterman&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			mod_letterman &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.2.4&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version. [http://www.thejfactory.com] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php?topic=180367 Forum Topic]  &lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; May 2007&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;LMO&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_lmo &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.0b2&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version. [http://forge.joomla.org/sf/frs/do/viewRelease/projects.lmo/frs.com_lmo.com_lmo_1_0_b3  ] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://www.frsirt.com/english/advisories/2006/3063 FrSIRT Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,81590.0.html Forum Topic] &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;LoudMouth&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_loudmouth &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 4.0j&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to version 4.1 then apply Security Patch 1.   [http://mamboxchange.com/frs/?group_id=39&amp;amp;amp;release_id=5995 Download here].&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://forum.joomla.org/index.php/topic,76337.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			 [http://mamboxchange.com/forum/forum.php?forum_id=7638 MamboExchange Advisory]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;MamCom (?)&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_trade &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned.  Remove completely or use at your own risk. &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; *Unconfirmed*&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;MambelFish 1.x&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_mambelfish &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.x&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to 1.5 (or to Joom!Fish)   [http://mamboxchange.com/frs/download.php/4518/MambelFish_1.5.zip Download Mambelfish&amp;lt;br /&amp;gt;]   [http://extensions.joomla.org/component/option,com_mtree/task,viewlink/link_id,460/Itemid,35/ Download Joom!Fish] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://secunia.com/advisories/21544/ Secunia Advisory] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;&lt;br /&gt;
			Mambo Gallery Manager&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/b&amp;gt;com_mgm&amp;lt;b&amp;gt; &lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned.  Remove completely or use at your own risk.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://forum.joomla.org/index.php/topic,81616.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			 [http://www.frsirt.com/english/advisories/2006/3054 FrSIRT Advisory] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;MiniBB&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_minibb &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.5a&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned.  Remove completely or use at your own risk.&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			 [http://securityreason.com/exploitalert/846 Security Reason Advisory]   [http://forum.joomla.org/index.php/topic,76898.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://securityreason.com/exploitalert/846 Security Reason] &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Mos Tree&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_mtree &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.5.8&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version. [http://www.mosets.com/download/] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://forum.joomla.org/index.php/topic,78298.0.html Forum Topic] &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;MosMedia&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_mosmedia &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.0.8&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Temporary Fix Available.  See  [http://forum.joomla.org/index.php/topic,78533.0.html this thread] for details.&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://forum.joomla.org/index.php/topic,78533.0.html Forum Topic] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;MoSpray&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_mospray&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.8 RC1&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned.  Remove completely or use at your own risk.&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://forum.joomla.org/index.php/topic,76331.0.html Forum Topic] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Multibanners&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_multibanners &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;i&amp;gt;* Note: Not the same as the Multibanners Module.&amp;lt;/i&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned.  Remove completely or use at your own risk.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://secunia.com/advisories/21168/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,77977.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;OpenSEF&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_sef &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 2.0.0 RC5 Unpatched&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; [http://projects.j-prosolution.com/project-news/opensef-news/security-patch-for-opensef.html Download patch] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt; [http://forum.joomla.org/index.php/topic,77301.0.html Forum Topic] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;PC Cook Book&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_pccookbook &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.3.1&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; No Fix Available. Disable or remove.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://www.frsirt.com/english/advisories/2006/2739 FrSIRT Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,76009.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Per Forms&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_performs &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;amp;lt;= v1_beta &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version. [http://forge.joomla.org/sf/frs/do/viewRelease/projects.performs/frs.com_performs.com_performs_v2_beta ] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://secunia.com/advisories/21044/ Secunia Advisory]&amp;lt;br /&amp;gt;   [http://forum.joomla.org/index.php/topic,76654.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,76862.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;lt;b&amp;gt;Phil-A-Form&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt; 1.2&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to latest version.&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://forum.joomla.org/index.php?topic=174770.new#new Forum Topic] &lt;br /&gt;
&lt;br /&gt;
			&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; May 2007&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;People Book&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_peoplebook &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.1.5&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version. [http://forge.joomla.org/sf/frs/do/viewRelease/projects.peoplebook/frs.component.component_1_1_6_0] &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forge.joomla.org/sf/go/artf5410?nav=1 Joomla Forge]  &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;Prince Clan Chess&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_pcchess &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 0.8&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Author suggest manually patching. [http://www.princeclan.org/] &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; See  [http://www.princeclan.org/ this site]. &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;PollXT&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_pollxt &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.22.07&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version. [http://www.joomlaxt.com/index.php?option=com_remository&amp;amp;amp;Itemid=77&amp;amp;amp;func=fileinfo&amp;amp;amp;id=9] &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; [http://secunia.com/advisories/21068/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,77975.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://secunia.com/advisories/21068/ Secunia Advisory] &lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt; RS Gallery2&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_rsgallery2&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.11.3&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version. [http://forge.joomla.org/sf/go/projects.rsgallery2/frs.rsg2_alpha_builds.rsg2_1_11_4]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://forum.joomla.org/index.php/topic,73453.0.html Forum Topic] &lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 06&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt;RWCards&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt; 2.4.4&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt; [http://forum.joomla.org/index.php/topic,154792.msg749006.html#msg749006 Forum Topic] &amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 26 June 2007&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;lt;b&amp;gt;Security Images&amp;lt;/b&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			com_securityimages&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 3.0.5&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://secunia.com/advisories/21260/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,81589.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; June 2007&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;lt;b&amp;gt;SEF404x&amp;lt;/b&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
			com_sef&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; No Fix Available.  Remove completely or use at your own risk.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; No references.&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;2006&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt;sh404SEF&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;1.2.4 t, u, or w &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Patch or update.&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt; [http://forum.joomla.org/index.php/topic,226147.0.html  Forum Topic] &amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;23 Oct, 2007&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Site Map&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_sitemap &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned.  Remove completely or use at your own risk.&amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://www.simplemachines.org/community/index.php?topic=97649.0] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &lt;br /&gt;
			 [http://secunia.com/advisories/21055/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,76326.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://secunia.com/advisories/21055/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;SimpleBoard&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_simpleboard &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest JoomlaBoard.  JoomlaBoard is compatible with SimpleBoard.  [http://developer.joomla.org/sf/frs/do/viewRelease/projects.simpleboard/frs.joomlaboard_1_1.joomlaboard_1_1_2 Download here].&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			 [http://secunia.com/advisories/20981/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://secunia.com/advisories/20409/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,75668.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://secunia.com/advisories/20981/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;SMF Bridge&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_smf &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.1.4&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			Versions other than 1.1RC2.  Fix Available.   [http://www.simplemachines.org/community/index.php?topic=100140.0 See this thread]. &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;amp;nbsp;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			Version 1.1RC2 only.  Upgrade available.  &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://www.simplemachines.org/community/index.php?topic=97649.0 See this thread.]  &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://secunia.com/advisories/21079/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://www.simplemachines.org/community/index.php?topic=100140.0 Simple Machines Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,78313.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,77716.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,78359.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,76609.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			 [http://secunia.com/advisories/21079/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;TaskHopper&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_thopper &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.1&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to latest version.&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,159111.0.html Forum Topic] &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;User Home Pages 1 and 2&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_uhp and com_uhp2 &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.1.1 (?)&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version. [http://www.ravenswoodit.co.uk/index.php?option=com_docman&amp;amp;amp;task=cat_view&amp;amp;amp;gid=78&amp;amp;amp;Itemid=13] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://forum.joomla.org/index.php/topic,81308.msg416865.html#msg416865 Forum Topic]&amp;lt;br /&amp;gt;&lt;br /&gt;
   [http://secunia.com/advisories/21305/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,81308.msg416865.html#msg416865 Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; June 2007&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt;VirtueMart&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.0.13a&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to version &amp;gt;= 1.0.14. Available  [http://virtuemart.net/index.php?option=com_content&amp;amp;task=view&amp;amp;id=54&amp;amp;Itemid=147 here]. &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; [http://virtuemart.net/index.php?option=com_content&amp;amp;task=view&amp;amp;id=275&amp;amp;Itemid=127 Security Bulletin] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;January 2008&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt;WordPress&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/b&amp;gt;&amp;lt;i&amp;gt;(Not a Joomla! extension, but worth noting.)&amp;lt;/i&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2.1.1&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,146478.msg737784.html#msg737784 Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 26 June 2007&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;lt;b&amp;gt;zOOm Media Gallery&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;amp;lt;= 2.5.1 RC4&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; [http://www.zoomfactory.org/index.php?option=com_remository&amp;amp;amp;Itemid=61&amp;amp;amp;func=select&amp;amp;amp;id=1 Upgrade to latest stable version].&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; [http://www.frsirt.com/english/advisories/2007/1353 FrSIRT Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,160119.0.html Forum Topic] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
                &amp;lt;tr&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt; &amp;lt;b&amp;gt;BF Survey Pro&amp;lt;br /&amp;gt;BF Survey Basic&amp;lt;br /&amp;gt;BF Quiz&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt;&amp;amp;lt;=1.2.5&amp;lt;br /&amp;gt;&amp;amp;lt;=1.0&amp;lt;br /&amp;gt;&amp;amp;lt;=1.1.1&amp;lt;/td&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt;[http://www.tamlyncreative.com.au/software/index.php/downloads.html Upgrade to latest versions]&amp;lt;/td&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt;[http://forum.joomla.org/viewtopic.php?f=431&amp;amp;t=336055&amp;amp;start=0 Forum Post]&amp;lt;br /&amp;gt;[http://www.tamlyncreative.com.au/software/forum/index.php?topic=357.0 Developer's Forum Post]&amp;lt;/td&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt;September, 2009&amp;lt;/td&amp;gt;&lt;br /&gt;
                &amp;lt;/tr&amp;gt;&lt;br /&gt;
                &amp;lt;tr&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt; &amp;lt;b&amp;gt;Photoblog (com_photoblog)&amp;lt;/td&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt;Unknown&amp;lt;/td&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt;Unknown&amp;lt;/td&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt;[http://www.securityfocus.com/bid/36809/info Security Focus Advisory]&amp;lt;/td&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt;October 26, 2009&amp;lt;/td&amp;gt;&lt;br /&gt;
                &amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Security]]&lt;br /&gt;
[[Category:Security_FAQ]]&lt;/div&gt;</summary>
		<author><name>CirTap</name></author>	</entry>

	<entry>
		<id>http://docs.joomla.org/Folderlist_form_field_type</id>
		<title>Folderlist form field type</title>
		<link rel="alternate" type="text/html" href="http://docs.joomla.org/Folderlist_form_field_type"/>
				<updated>2011-07-15T12:05:37Z</updated>
		
		<summary type="html">&lt;p&gt;CirTap: fixed marker box using &amp;quot;notice&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Image:Params.folderlist.jpg|right]]&lt;br /&gt;
&lt;br /&gt;
{{notice|In Joomla! 1.5, [[Form field|form fields]] were [[Parameter|parameters]]. For that version, you may want to use the corresponding [[Folderlist parameter type]].}}&lt;br /&gt;
&lt;br /&gt;
The '''folderlist''' form field type provides a drop down list of folders from a specfied directory. If the field has a saved value this is selected when the page is first loaded. If not, the default value (if any) is selected. &lt;br /&gt;
&lt;br /&gt;
By default, the first item on the list is '- Do not use -' (which is translatable) and is given the value '-1' and this is followed by '- Use default -' (also translatable) given the value '0'.&lt;br /&gt;
&lt;br /&gt;
* '''type''' (mandatory) must be '''folderlist'''.&lt;br /&gt;
* '''name''' (mandatory) is the unique name of the field.&lt;br /&gt;
* '''label''' (mandatory) (translatable) is the descriptive title of the field.&lt;br /&gt;
* '''directory''' (mandatory) is the filesystem path to the directory containing the folders to be listed.&lt;br /&gt;
* '''default''' (optional) is the default folder name.&lt;br /&gt;
* '''description''' (optional) (translatable) is text that will be shown as a tooltip when the user moves the mouse over the drop-down box.&lt;br /&gt;
* '''filter''' (optional) is a regular expression string which is used to filter the list of folders selected for inclusion in the drop-down list. If omitted, all folders in the directory are included. The filter argument expression is applied before the exclude argument expression.  For information on constructing regular expressions see [[Regular expressions in parameter arguments]].&lt;br /&gt;
* '''exclude''' (optional) is a regular expression string which is used to exclude folders from the list.  The exclude argument expression is applied after the filter argument expression.  For information on constructing regular expressions see [[Regular expressions in parameter arguments]].&lt;br /&gt;
* '''hide_none''' (optional) is a Boolean argument. If true, the '- Do not use -' item is omitted from the drop-down list.&lt;br /&gt;
* '''hide_default''' (optional) is a Boolean argument. If true, the '- Use default -' item is omitted from the drop-down list.&lt;br /&gt;
&lt;br /&gt;
Example XML field definition:&lt;br /&gt;
&amp;lt;source lang=&amp;quot;xml&amp;quot;&amp;gt;&amp;lt;field name=&amp;quot;myfolder&amp;quot; type=&amp;quot;folderlist&amp;quot; default=&amp;quot;&amp;quot; label=&amp;quot;Select a folder&amp;quot; directory=&amp;quot;administrator&amp;quot; filter=&amp;quot;&amp;quot; exclude=&amp;quot;&amp;quot; stripext=&amp;quot;&amp;quot; /&amp;gt;&amp;lt;/source&amp;gt;&lt;br /&gt;
&amp;lt;noinclude&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== See also ===&lt;br /&gt;
* [[Filelist form field type]]&lt;br /&gt;
* [[Imagelist form field type]]&lt;br /&gt;
* [[Standard form field types|List of standard form field types]]&lt;br /&gt;
[[Category:Standard form field types]]&amp;lt;/noinclude&amp;gt;&lt;/div&gt;</summary>
		<author><name>CirTap</name></author>	</entry>

	<entry>
		<id>http://docs.joomla.org/Vulnerable_Extensions_List_(Archived)</id>
		<title>Vulnerable Extensions List (Archived)</title>
		<link rel="alternate" type="text/html" href="http://docs.joomla.org/Vulnerable_Extensions_List_(Archived)"/>
				<updated>2011-07-15T11:35:48Z</updated>
		
		<summary type="html">&lt;p&gt;CirTap: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;For a more recent list please see [[Vulnerable Extensions List]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;3&amp;quot; cellspacing=&amp;quot;3&amp;quot;&amp;gt;&lt;br /&gt;
		&amp;lt;tr style=&amp;quot;background-color: #ff9900&amp;quot; valign=&amp;quot;bottom&amp;quot;&amp;gt;&lt;br /&gt;
			&amp;lt;th align=&amp;quot;left&amp;quot; width=&amp;quot;25%&amp;quot;&amp;gt;Name&amp;lt;/th&amp;gt;&lt;br /&gt;
  			&amp;lt;th align=&amp;quot;left&amp;quot;&amp;gt;Versions&amp;lt;/th&amp;gt;&lt;br /&gt;
			&amp;lt;th align=&amp;quot;left&amp;quot;&amp;gt;Solution&amp;lt;/th&amp;gt;&lt;br /&gt;
			&amp;lt;th align=&amp;quot;left&amp;quot;&amp;gt;References&amp;lt;/th&amp;gt;&lt;br /&gt;
			&amp;lt;th&amp;gt;Updated&amp;lt;/th&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;A6MamboCredits&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;com_a6mambocredits&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;All &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Abandoned. Remove completely or use at your own risk.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://secunia.com/advisories/21540/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,86978.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;A6MamboHelpDesk&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_a6mambohelpdesk &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned. Remove completely or use at your own risk.&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,80890.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://secunia.com/advisories/21540/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			 [http://secunia.com/advisories/21227/ Secunia Advisory] &lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;Advanced Poll&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_advancedpoll (?) &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 2.2.0&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &lt;br /&gt;
			Abandoned. Remove completely or use at your own risk. &lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; [http://forum.joomla.org/index.php/topic,76621.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt;Adobe Acrobat Reader&amp;lt;/b&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;i&amp;gt;(Not a Joomla! extension, but worth noting.)&amp;lt;/i&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 7.0.8&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version.&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://www.adobe.com/support/security/advisories/apsa07-01.html Adobe Advisory] &lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;lt;b&amp;gt;Akocomment&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;SQL Injection with PHP magic_quotes OFF. No upgrade path yet. &amp;lt;br /&amp;gt;&lt;br /&gt;
			Fix: Turn PHP magic_quotes ON&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php?topic=185805.msg882326#msg882326 Forum Topic]&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;June 30, 2006&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt;Article&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.1&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; [http://www.milw0rm.com/exploits/3736 milwOrm Advisory]&amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://www.frsirt.com/english/adisories/2007/1394 FrSIRT Advisory]&amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,160876.msg775119.html#msg775119 Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 26 June 2007&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;ArtLinks&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_artlinks &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All &lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned.  Remove completely or use at your own risk.&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,76328.0.html Forum Topic] &lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;lt;b&amp;gt;AutoStand &amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.1&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; No further information at this time.&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;[http://www.milw0rm.com/exploits/3734 milwOrm Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://www.frsirt.com/english/advisories/2007/1392 FrSIRT Advisory]&amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,160876.msg775119.html#msg775119 Forum Topic]&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;amp;nbsp;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 26 June 2007&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Bayesian Naive Filter&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			com_bayesiannaivefilter &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.1&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; No Fix Available. Disable or remove until a fix is available.&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,81594.0.html Forum Topic] &lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Bible Study&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			com_biblestudy &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 6.0.7b and below&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Fix Available. SQL Insertion attack&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;http://joomlacode.org/gf/project/biblestudy/&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2008&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;BigApe Backup&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_babackup &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; A patch is available from the developer.  [http://forum.joomla.org/index.php/topic,87736.msg465256.html#msg465256 See this post.] &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://secunia.com/advisories/21574/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,87736.0.html Forum Topic] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;BSQ Site Stats&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_bsqsitestats &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 2.2.1&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version.&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,77899.0.html Forum Topic]&amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://secunia.com/advisories/22142/ Secunia Advisory] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt;Car Manager&amp;lt;/b&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.1&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  No further information at this time.&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,154777.msg748946.html#msg748946 Forum Topic] &amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 26 June 2007&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;Classifieds&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_classifieds &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.3&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,82457.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Colophon&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_colophon &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.2&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://secunia.com/advisories/21288/ Secunia Advisory]&amp;lt;br /&amp;gt;&lt;br /&gt;
			[http://forum.joomla.org/index.php/topic,81587.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Community Builder&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_profiler &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.0.0&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			Upgrade to latest stable version.&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			[http://forum.joomla.org/index.php/topic,86525.msg441456.html#msg441456 See here for a fix for register_globals = off] &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://www.joomlapolis.com/content/view/1538/37/ Jomopolis Topic]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			[http://forum.joomla.org/index.php/topic,84436.0.html Forum Topic]&amp;lt;br /&amp;gt;&lt;br /&gt;
			[http://forum.joomla.org/index.php/topic,86525.msg441456.html#msg441456 Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;DS-Syndicate&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_ds-syndicate &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;All versions?&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;SQL injection vulnerability.&amp;lt;br /&amp;gt;&lt;br /&gt;
			Remove completely or use at your own risk.&amp;lt;br /&amp;gt;Component has been removed from JED. Abandoned?&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &lt;br /&gt;
			[http://www.frsirt.com/english/advisories/2008/2859 http://www.frsirt.com/english/advisories/2008/2859] &lt;br /&gt;
			&amp;lt;td&amp;gt;Nov. 27, 2008&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;Events&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_events &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.3 Beta&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,80411.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt;Expose Flash Gallery&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; RC4&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://joomlacode.org/gf/project/expose/frs/?action=FrsReleaseView&amp;amp;amp;release_id=5053 Download patch]&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,192172.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;20 July 2007&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;ExtCalendar&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_extcalendar &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 0.9.1&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to version 0.9.2.  See[http://forum.joomla.org/index.php/topic,75390.msg402249.html#msg402249 this post] for details. Also check the new forked project, JCal. &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; [http://secunia.com/advisories/19321/ Secunia Advisory]&amp;lt;br /&amp;gt;&lt;br /&gt;
			[http://forum.joomla.org/index.php/topic,75390.0.html Forum Topic]&amp;lt;br /&amp;gt;&lt;br /&gt;
			[http://forum.joomla.org/index.php/topic,79050.0.html Forum Topic]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			[http://forum.joomla.org/index.php/topic,78268.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Facile Forms&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_facileforms &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.4.6&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,98973.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Galleria&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_galleria &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned.  Remove completely or use at your own risk.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-3396 NVD Advisory]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			[http://forum.joomla.org/index.php/topic,77706.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Gmaps&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_gmaps&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;amp;lt;=1.01 &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to the latest version, which can be downloaded [http://firestorm-technologies.com/component/option,com_docman/Itemid,27/task,doc_download/gid,22/ here]&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://www.securityfocus.com/bid/25146 Security Focus Advisory]&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 6 August 2007&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;Hash Cash&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_hashcash &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned.  Remove completely or use at your own risk.&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://secunia.com/product/11046/ Secunia Advisory]&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;Hot Property&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_hotproperties (?) &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 0.97&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to [http://www.mosets.com/download/ latest stable version].&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; No references available at this time.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;JCE&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_jce &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.0.4&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Apply patch, download it [http://www.cellardoor.za.net/index.php?option=com_docman&amp;amp;amp;task=cat_view&amp;amp;amp;gid=1&amp;amp;amp;Itemid=6 here], or use latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			[http://secunia.com/advisories/23160/ Secunia Advisory]&amp;lt;br /&amp;gt;&lt;br /&gt;
			[http://www.cellardoor.za.net/ Cellardoor]&amp;lt;br /&amp;gt;&lt;br /&gt;
			[http://secunia.com/advisories/23160/ Secunia Advisory] &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;JoomlaPack&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_jpack &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 1.0.4a2 RE&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version.&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			 [http://www.milw0rm.com/exploits/3753 MilwOrm Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://www.frsirt.com/english/advisories/2007/1429 FrSIRT Advisory]  &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;JoomlaBoard&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_joomlaboard &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.1.1&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			Upgrade to latest stable version.&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,86525.msg441456.html#msg441456 RG_EMULATION Fix]  &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://secunia.com/advisories/21059/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,76852.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,86525.msg441513.html#msg441513 Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;JoomlaLib&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_joomlalib &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.2.1&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,77899.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;JD-WordPress&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_jd-wp &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 2.0-1.0 RC2&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Patch Available.  &amp;lt;br /&amp;gt;&lt;br /&gt;
			See [http://forum.joomla.org/index.php/topic,81064.msg418374.html#msg418374 this post]. &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,81064.0.html Forum Topic] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			JD-Wiki&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_jd-wiki &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;All &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			Abandoned project. &amp;lt;br /&amp;gt;&lt;br /&gt;
			Upgrade to [http://joomlacode.org/gf/project/nuwiki/ nuWiki] &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,80188.msg427986.html#msg427986 Forum Topic] &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php?topic=177926.0 Forum Topic] &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;6 July 2007&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;&lt;br /&gt;
			JIM 1.0.1. (PMS)&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			com_jim &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 1.0.1&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version. The developer fixed security issues but didn't create a higher version number.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://secunia.com/advisories/21545/ Secunia Advisory] &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt;joomSEF (&amp;lt;/b&amp;gt;&amp;lt;b&amp;gt;ARTIO)&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;=2.2.1&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,226147.0.html  Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;27 Oct 2007&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;jPack&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_jpack &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;amp;lt;  1.0.4-b1&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,163589.msg847010.html#msg847010 Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 26 June 2007&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Link Directory&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_linkdirectory &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Remove. Abandoned project.&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; No references.&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Letterman&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			mod_letterman &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.2.4&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version. [http://www.thejfactory.com] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php?topic=180367 Forum Topic]  &lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; May 2007&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;LMO&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_lmo &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.0b2&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version. [http://forge.joomla.org/sf/frs/do/viewRelease/projects.lmo/frs.com_lmo.com_lmo_1_0_b3  ] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://www.frsirt.com/english/advisories/2006/3063 FrSIRT Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,81590.0.html Forum Topic] &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;LoudMouth&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_loudmouth &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 4.0j&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to version 4.1 then apply Security Patch 1.   [http://mamboxchange.com/frs/?group_id=39&amp;amp;amp;release_id=5995 Download here].&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://forum.joomla.org/index.php/topic,76337.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			 [http://mamboxchange.com/forum/forum.php?forum_id=7638 MamboExchange Advisory]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;MamCom (?)&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_trade &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned.  Remove completely or use at your own risk. &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; *Unconfirmed*&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;MambelFish 1.x&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_mambelfish &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.x&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to 1.5 (or to Joom!Fish)   [http://mamboxchange.com/frs/download.php/4518/MambelFish_1.5.zip Download Mambelfish&amp;lt;br /&amp;gt;]   [http://extensions.joomla.org/component/option,com_mtree/task,viewlink/link_id,460/Itemid,35/ Download Joom!Fish] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://secunia.com/advisories/21544/ Secunia Advisory] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;&lt;br /&gt;
			Mambo Gallery Manager&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/b&amp;gt;com_mgm&amp;lt;b&amp;gt; &lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned.  Remove completely or use at your own risk.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://forum.joomla.org/index.php/topic,81616.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			 [http://www.frsirt.com/english/advisories/2006/3054 FrSIRT Advisory] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;MiniBB&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_minibb &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.5a&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned.  Remove completely or use at your own risk.&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			 [http://securityreason.com/exploitalert/846 Security Reason Advisory]   [http://forum.joomla.org/index.php/topic,76898.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://securityreason.com/exploitalert/846 Security Reason] &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Mos Tree&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_mtree &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.5.8&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version. [http://www.mosets.com/download/] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://forum.joomla.org/index.php/topic,78298.0.html Forum Topic] &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;MosMedia&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_mosmedia &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.0.8&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Temporary Fix Available.  See  [http://forum.joomla.org/index.php/topic,78533.0.html this thread] for details.&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://forum.joomla.org/index.php/topic,78533.0.html Forum Topic] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;MoSpray&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_mospray&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.8 RC1&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned.  Remove completely or use at your own risk.&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://forum.joomla.org/index.php/topic,76331.0.html Forum Topic] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Multibanners&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_multibanners &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;i&amp;gt;* Note: Not the same as the Multibanners Module.&amp;lt;/i&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned.  Remove completely or use at your own risk.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://secunia.com/advisories/21168/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,77977.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;OpenSEF&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_sef &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 2.0.0 RC5 Unpatched&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; [http://projects.j-prosolution.com/project-news/opensef-news/security-patch-for-opensef.html Download patch] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt; [http://forum.joomla.org/index.php/topic,77301.0.html Forum Topic] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;PC Cook Book&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_pccookbook &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.3.1&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; No Fix Available. Disable or remove.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://www.frsirt.com/english/advisories/2006/2739 FrSIRT Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,76009.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Per Forms&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_performs &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;amp;lt;= v1_beta &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version. [http://forge.joomla.org/sf/frs/do/viewRelease/projects.performs/frs.com_performs.com_performs_v2_beta ] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://secunia.com/advisories/21044/ Secunia Advisory]&amp;lt;br /&amp;gt;   [http://forum.joomla.org/index.php/topic,76654.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,76862.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;lt;b&amp;gt;Phil-A-Form&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt; 1.2&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to latest version.&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://forum.joomla.org/index.php?topic=174770.new#new Forum Topic] &lt;br /&gt;
&lt;br /&gt;
			&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; May 2007&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;People Book&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_peoplebook &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.1.5&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version. [http://forge.joomla.org/sf/frs/do/viewRelease/projects.peoplebook/frs.component.component_1_1_6_0] &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forge.joomla.org/sf/go/artf5410?nav=1 Joomla Forge]  &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;Prince Clan Chess&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_pcchess &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 0.8&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Author suggest manually patching. [http://www.princeclan.org/] &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; See  [http://www.princeclan.org/ this site]. &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;PollXT&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_pollxt &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.22.07&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version. [http://www.joomlaxt.com/index.php?option=com_remository&amp;amp;amp;Itemid=77&amp;amp;amp;func=fileinfo&amp;amp;amp;id=9] &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; [http://secunia.com/advisories/21068/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,77975.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://secunia.com/advisories/21068/ Secunia Advisory] &lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt; RS Gallery2&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_rsgallery2&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.11.3&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version. [http://forge.joomla.org/sf/go/projects.rsgallery2/frs.rsg2_alpha_builds.rsg2_1_11_4]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://forum.joomla.org/index.php/topic,73453.0.html Forum Topic] &lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 06&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt;RWCards&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt; 2.4.4&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt; [http://forum.joomla.org/index.php/topic,154792.msg749006.html#msg749006 Forum Topic] &amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 26 June 2007&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;lt;b&amp;gt;Security Images&amp;lt;/b&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			com_securityimages&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 3.0.5&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://secunia.com/advisories/21260/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,81589.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; June 2007&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;lt;b&amp;gt;SEF404x&amp;lt;/b&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
			com_sef&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; No Fix Available.  Remove completely or use at your own risk.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; No references.&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;2006&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt;sh404SEF&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;1.2.4 t, u, or w &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Patch or update.&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt; [http://forum.joomla.org/index.php/topic,226147.0.html  Forum Topic] &amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;23 Oct, 2007&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Site Map&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_sitemap &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned.  Remove completely or use at your own risk.&amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://www.simplemachines.org/community/index.php?topic=97649.0] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &lt;br /&gt;
			 [http://secunia.com/advisories/21055/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,76326.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://secunia.com/advisories/21055/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;SimpleBoard&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_simpleboard &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest JoomlaBoard.  JoomlaBoard is compatible with SimpleBoard.  [http://developer.joomla.org/sf/frs/do/viewRelease/projects.simpleboard/frs.joomlaboard_1_1.joomlaboard_1_1_2 Download here].&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			 [http://secunia.com/advisories/20981/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://secunia.com/advisories/20409/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,75668.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://secunia.com/advisories/20981/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;SMF Bridge&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_smf &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.1.4&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			Versions other than 1.1RC2.  Fix Available.   [http://www.simplemachines.org/community/index.php?topic=100140.0 See this thread]. &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;amp;nbsp;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			Version 1.1RC2 only.  Upgrade available.  &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://www.simplemachines.org/community/index.php?topic=97649.0 See this thread.]  &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://secunia.com/advisories/21079/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://www.simplemachines.org/community/index.php?topic=100140.0 Simple Machines Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,78313.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,77716.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,78359.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,76609.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			 [http://secunia.com/advisories/21079/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;TaskHopper&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_thopper &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.1&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to latest version.&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,159111.0.html Forum Topic] &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;User Home Pages 1 and 2&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_uhp and com_uhp2 &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.1.1 (?)&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version. [http://www.ravenswoodit.co.uk/index.php?option=com_docman&amp;amp;amp;task=cat_view&amp;amp;amp;gid=78&amp;amp;amp;Itemid=13] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://forum.joomla.org/index.php/topic,81308.msg416865.html#msg416865 Forum Topic]&amp;lt;br /&amp;gt;&lt;br /&gt;
   [http://secunia.com/advisories/21305/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,81308.msg416865.html#msg416865 Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; June 2007&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt;VirtueMart&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.0.13a&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to version &amp;gt;= 1.0.14. Available  [http://virtuemart.net/index.php?option=com_content&amp;amp;task=view&amp;amp;id=54&amp;amp;Itemid=147 here]. &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; [http://virtuemart.net/index.php?option=com_content&amp;amp;task=view&amp;amp;id=275&amp;amp;Itemid=127 Security Bulletin] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;January 2008&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt;WordPress&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/b&amp;gt;&amp;lt;i&amp;gt;(Not a Joomla! extension, but worth noting.)&amp;lt;/i&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2.1.1&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,146478.msg737784.html#msg737784 Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 26 June 2007&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;lt;b&amp;gt;zOOm Media Gallery&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;amp;lt;= 2.5.1 RC4&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; [http://www.zoomfactory.org/index.php?option=com_remository&amp;amp;amp;Itemid=61&amp;amp;amp;func=select&amp;amp;amp;id=1 Upgrade to latest stable version].&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; [http://www.frsirt.com/english/advisories/2007/1353 FrSIRT Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,160119.0.html Forum Topic] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
                &amp;lt;tr&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt; &amp;lt;b&amp;gt;BF Survey Pro&amp;lt;br /&amp;gt;BF Survey Basic&amp;lt;br /&amp;gt;BF Quiz&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt;&amp;amp;lt;=1.2.5&amp;lt;br /&amp;gt;&amp;amp;lt;=1.0&amp;lt;br /&amp;gt;&amp;amp;lt;=1.1.1&amp;lt;/td&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt;[http://www.tamlyncreative.com.au/software/index.php/downloads.html Upgrade to latest versions]&amp;lt;/td&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt;[http://forum.joomla.org/viewtopic.php?f=431&amp;amp;t=336055&amp;amp;start=0 Forum Post]&amp;lt;br /&amp;gt;[http://www.tamlyncreative.com.au/software/forum/index.php?topic=357.0 Developer's Forum Post]&amp;lt;/td&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt;September, 2009&amp;lt;/td&amp;gt;&lt;br /&gt;
                &amp;lt;/tr&amp;gt;&lt;br /&gt;
                &amp;lt;tr&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt; &amp;lt;b&amp;gt;Photoblog (com_photoblog)&amp;lt;/td&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt;Unknown&amp;lt;/td&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt;Unknown&amp;lt;/td&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt;[http://www.securityfocus.com/bid/36809/info Security Focus Advisory]&amp;lt;/td&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt;October 26, 2009&amp;lt;/td&amp;gt;&lt;br /&gt;
                &amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Security]]&lt;/div&gt;</summary>
		<author><name>CirTap</name></author>	</entry>

	<entry>
		<id>http://docs.joomla.org/Vulnerable_Extensions_List/Archive</id>
		<title>Vulnerable Extensions List/Archive</title>
		<link rel="alternate" type="text/html" href="http://docs.joomla.org/Vulnerable_Extensions_List/Archive"/>
				<updated>2011-07-15T11:27:51Z</updated>
		
		<summary type="html">&lt;p&gt;CirTap: Changed protection level for &amp;quot;Vulnerable Extensions List/Archive&amp;quot; ([edit=sysop] (indefinite) [move=sysop] (indefinite))&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Former Lists of vulnerable extensions.&lt;br /&gt;
&amp;lt;splist/&amp;gt;&lt;br /&gt;
[[Category:Security]]&lt;br /&gt;
[[Category:Security_FAQ]]&lt;/div&gt;</summary>
		<author><name>CirTap</name></author>	</entry>

	<entry>
		<id>http://docs.joomla.org/Vulnerable_Extensions_List_(Archived)</id>
		<title>Vulnerable Extensions List (Archived)</title>
		<link rel="alternate" type="text/html" href="http://docs.joomla.org/Vulnerable_Extensions_List_(Archived)"/>
				<updated>2011-07-15T11:27:39Z</updated>
		
		<summary type="html">&lt;p&gt;CirTap: Protected &amp;quot;Vulnerable Extensions List/Archive/2010-11&amp;quot; ([edit=sysop] (indefinite) [move=sysop] (indefinite))&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;For a more recent list please see [[Vulnerable Extensions List]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;3&amp;quot; cellspacing=&amp;quot;3&amp;quot;&amp;gt;&lt;br /&gt;
		&amp;lt;tr style=&amp;quot;background-color: #ff9900&amp;quot; valign=&amp;quot;bottom&amp;quot;&amp;gt;&lt;br /&gt;
			&amp;lt;th align=&amp;quot;left&amp;quot; width=&amp;quot;25%&amp;quot;&amp;gt;Name&amp;lt;/th&amp;gt;&lt;br /&gt;
  			&amp;lt;th align=&amp;quot;left&amp;quot;&amp;gt;Versions&amp;lt;/th&amp;gt;&lt;br /&gt;
			&amp;lt;th align=&amp;quot;left&amp;quot;&amp;gt;Solution&amp;lt;/th&amp;gt;&lt;br /&gt;
			&amp;lt;th align=&amp;quot;left&amp;quot;&amp;gt;References&amp;lt;/th&amp;gt;&lt;br /&gt;
			&amp;lt;th&amp;gt;Updated&amp;lt;/th&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;A6MamboCredits&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;com_a6mambocredits&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;All &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Abandoned. Remove completely or use at your own risk.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://secunia.com/advisories/21540/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,86978.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;A6MamboHelpDesk&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_a6mambohelpdesk &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned. Remove completely or use at your own risk.&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,80890.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://secunia.com/advisories/21540/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			 [http://secunia.com/advisories/21227/ Secunia Advisory] &lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;Advanced Poll&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_advancedpoll (?) &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 2.2.0&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &lt;br /&gt;
			Abandoned. Remove completely or use at your own risk. &lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; [http://forum.joomla.org/index.php/topic,76621.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt;Adobe Acrobat Reader&amp;lt;/b&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;i&amp;gt;(Not a Joomla! extension, but worth noting.)&amp;lt;/i&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 7.0.8&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version.&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://www.adobe.com/support/security/advisories/apsa07-01.html Adobe Advisory] &lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;lt;b&amp;gt;Akocomment&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;SQL Injection with PHP magic_quotes OFF. No upgrade path yet. &amp;lt;br /&amp;gt;&lt;br /&gt;
			Fix: Turn PHP magic_quotes ON&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php?topic=185805.msg882326#msg882326 Forum Topic]&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;June 30, 2006&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt;Article&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.1&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; [http://www.milw0rm.com/exploits/3736 milwOrm Advisory]&amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://www.frsirt.com/english/adisories/2007/1394 FrSIRT Advisory]&amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,160876.msg775119.html#msg775119 Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 26 June 2007&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;ArtLinks&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_artlinks &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All &lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned.  Remove completely or use at your own risk.&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,76328.0.html Forum Topic] &lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;lt;b&amp;gt;AutoStand &amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.1&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; No further information at this time.&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;[http://www.milw0rm.com/exploits/3734 milwOrm Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://www.frsirt.com/english/advisories/2007/1392 FrSIRT Advisory]&amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,160876.msg775119.html#msg775119 Forum Topic]&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;amp;nbsp;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 26 June 2007&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Bayesian Naive Filter&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			com_bayesiannaivefilter &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.1&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; No Fix Available. Disable or remove until a fix is available.&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,81594.0.html Forum Topic] &lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Bible Study&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			com_biblestudy &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 6.0.7b and below&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Fix Available. SQL Insertion attack&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;http://joomlacode.org/gf/project/biblestudy/&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2008&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;BigApe Backup&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_babackup &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; A patch is available from the developer.  [http://forum.joomla.org/index.php/topic,87736.msg465256.html#msg465256 See this post.] &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://secunia.com/advisories/21574/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,87736.0.html Forum Topic] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;BSQ Site Stats&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_bsqsitestats &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 2.2.1&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version.&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,77899.0.html Forum Topic]&amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://secunia.com/advisories/22142/ Secunia Advisory] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt;Car Manager&amp;lt;/b&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.1&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  No further information at this time.&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,154777.msg748946.html#msg748946 Forum Topic] &amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 26 June 2007&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;Classifieds&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_classifieds &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.3&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,82457.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Colophon&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_colophon &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.2&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://secunia.com/advisories/21288/ Secunia Advisory]&amp;lt;br /&amp;gt;&lt;br /&gt;
			[http://forum.joomla.org/index.php/topic,81587.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Community Builder&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_profiler &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.0.0&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			Upgrade to latest stable version.&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			[http://forum.joomla.org/index.php/topic,86525.msg441456.html#msg441456 See here for a fix for register_globals = off] &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://www.joomlapolis.com/content/view/1538/37/ Jomopolis Topic]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			[http://forum.joomla.org/index.php/topic,84436.0.html Forum Topic]&amp;lt;br /&amp;gt;&lt;br /&gt;
			[http://forum.joomla.org/index.php/topic,86525.msg441456.html#msg441456 Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;DS-Syndicate&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_ds-syndicate &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;All versions?&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;SQL injection vulnerability.&amp;lt;br /&amp;gt;&lt;br /&gt;
			Remove completely or use at your own risk.&amp;lt;br /&amp;gt;Component has been removed from JED. Abandoned?&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &lt;br /&gt;
			[http://www.frsirt.com/english/advisories/2008/2859 http://www.frsirt.com/english/advisories/2008/2859] &lt;br /&gt;
			&amp;lt;td&amp;gt;Nov. 27, 2008&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;Events&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_events &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.3 Beta&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,80411.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt;Expose Flash Gallery&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; RC4&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://joomlacode.org/gf/project/expose/frs/?action=FrsReleaseView&amp;amp;amp;release_id=5053 Download patch]&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,192172.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;20 July 2007&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;ExtCalendar&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_extcalendar &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 0.9.1&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to version 0.9.2.  See[http://forum.joomla.org/index.php/topic,75390.msg402249.html#msg402249 this post] for details. Also check the new forked project, JCal. &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; [http://secunia.com/advisories/19321/ Secunia Advisory]&amp;lt;br /&amp;gt;&lt;br /&gt;
			[http://forum.joomla.org/index.php/topic,75390.0.html Forum Topic]&amp;lt;br /&amp;gt;&lt;br /&gt;
			[http://forum.joomla.org/index.php/topic,79050.0.html Forum Topic]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			[http://forum.joomla.org/index.php/topic,78268.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Facile Forms&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_facileforms &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.4.6&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,98973.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Galleria&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_galleria &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned.  Remove completely or use at your own risk.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-3396 NVD Advisory]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			[http://forum.joomla.org/index.php/topic,77706.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Gmaps&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_gmaps&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;amp;lt;=1.01 &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to the latest version, which can be downloaded [http://firestorm-technologies.com/component/option,com_docman/Itemid,27/task,doc_download/gid,22/ here]&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://www.securityfocus.com/bid/25146 Security Focus Advisory]&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 6 August 2007&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;Hash Cash&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_hashcash &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned.  Remove completely or use at your own risk.&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://secunia.com/product/11046/ Secunia Advisory]&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;Hot Property&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_hotproperties (?) &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 0.97&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to [http://www.mosets.com/download/ latest stable version].&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; No references available at this time.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;JCE&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_jce &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.0.4&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Apply patch, download it [http://www.cellardoor.za.net/index.php?option=com_docman&amp;amp;amp;task=cat_view&amp;amp;amp;gid=1&amp;amp;amp;Itemid=6 here], or use latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			[http://secunia.com/advisories/23160/ Secunia Advisory]&amp;lt;br /&amp;gt;&lt;br /&gt;
			[http://www.cellardoor.za.net/ Cellardoor]&amp;lt;br /&amp;gt;&lt;br /&gt;
			[http://secunia.com/advisories/23160/ Secunia Advisory] &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;JoomlaPack&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_jpack &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 1.0.4a2 RE&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version.&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			 [http://www.milw0rm.com/exploits/3753 MilwOrm Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://www.frsirt.com/english/advisories/2007/1429 FrSIRT Advisory]  &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;JoomlaBoard&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_joomlaboard &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.1.1&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			Upgrade to latest stable version.&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,86525.msg441456.html#msg441456 RG_EMULATION Fix]  &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://secunia.com/advisories/21059/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,76852.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,86525.msg441513.html#msg441513 Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;JoomlaLib&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_joomlalib &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.2.1&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,77899.0.html Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;JD-WordPress&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_jd-wp &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 2.0-1.0 RC2&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Patch Available.  &amp;lt;br /&amp;gt;&lt;br /&gt;
			See [http://forum.joomla.org/index.php/topic,81064.msg418374.html#msg418374 this post]. &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,81064.0.html Forum Topic] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			JD-Wiki&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_jd-wiki &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;All &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			Abandoned project. &amp;lt;br /&amp;gt;&lt;br /&gt;
			Upgrade to [http://joomlacode.org/gf/project/nuwiki/ nuWiki] &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,80188.msg427986.html#msg427986 Forum Topic] &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php?topic=177926.0 Forum Topic] &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;6 July 2007&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;&lt;br /&gt;
			JIM 1.0.1. (PMS)&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			com_jim &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 1.0.1&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version. The developer fixed security issues but didn't create a higher version number.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://secunia.com/advisories/21545/ Secunia Advisory] &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt;joomSEF (&amp;lt;/b&amp;gt;&amp;lt;b&amp;gt;ARTIO)&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;=2.2.1&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,226147.0.html  Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;27 Oct 2007&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;jPack&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_jpack &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;amp;lt;  1.0.4-b1&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,163589.msg847010.html#msg847010 Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 26 June 2007&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Link Directory&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_linkdirectory &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Remove. Abandoned project.&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; No references.&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Letterman&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			mod_letterman &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.2.4&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version. [http://www.thejfactory.com] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php?topic=180367 Forum Topic]  &lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; May 2007&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;LMO&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_lmo &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.0b2&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version. [http://forge.joomla.org/sf/frs/do/viewRelease/projects.lmo/frs.com_lmo.com_lmo_1_0_b3  ] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://www.frsirt.com/english/advisories/2006/3063 FrSIRT Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,81590.0.html Forum Topic] &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;LoudMouth&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_loudmouth &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 4.0j&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to version 4.1 then apply Security Patch 1.   [http://mamboxchange.com/frs/?group_id=39&amp;amp;amp;release_id=5995 Download here].&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://forum.joomla.org/index.php/topic,76337.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			 [http://mamboxchange.com/forum/forum.php?forum_id=7638 MamboExchange Advisory]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;MamCom (?)&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_trade &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned.  Remove completely or use at your own risk. &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; *Unconfirmed*&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;MambelFish 1.x&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_mambelfish &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.x&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to 1.5 (or to Joom!Fish)   [http://mamboxchange.com/frs/download.php/4518/MambelFish_1.5.zip Download Mambelfish&amp;lt;br /&amp;gt;]   [http://extensions.joomla.org/component/option,com_mtree/task,viewlink/link_id,460/Itemid,35/ Download Joom!Fish] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://secunia.com/advisories/21544/ Secunia Advisory] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;&lt;br /&gt;
			Mambo Gallery Manager&lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/b&amp;gt;com_mgm&amp;lt;b&amp;gt; &lt;br /&gt;
			&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned.  Remove completely or use at your own risk.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://forum.joomla.org/index.php/topic,81616.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			 [http://www.frsirt.com/english/advisories/2006/3054 FrSIRT Advisory] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;MiniBB&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_minibb &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.5a&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned.  Remove completely or use at your own risk.&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			 [http://securityreason.com/exploitalert/846 Security Reason Advisory]   [http://forum.joomla.org/index.php/topic,76898.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://securityreason.com/exploitalert/846 Security Reason] &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Mos Tree&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_mtree &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.5.8&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version. [http://www.mosets.com/download/] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://forum.joomla.org/index.php/topic,78298.0.html Forum Topic] &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;MosMedia&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_mosmedia &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.0.8&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Temporary Fix Available.  See  [http://forum.joomla.org/index.php/topic,78533.0.html this thread] for details.&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://forum.joomla.org/index.php/topic,78533.0.html Forum Topic] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;MoSpray&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_mospray&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.8 RC1&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned.  Remove completely or use at your own risk.&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://forum.joomla.org/index.php/topic,76331.0.html Forum Topic] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Multibanners&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_multibanners &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;i&amp;gt;* Note: Not the same as the Multibanners Module.&amp;lt;/i&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned.  Remove completely or use at your own risk.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://secunia.com/advisories/21168/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,77977.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;OpenSEF&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_sef &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 2.0.0 RC5 Unpatched&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; [http://projects.j-prosolution.com/project-news/opensef-news/security-patch-for-opensef.html Download patch] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt; [http://forum.joomla.org/index.php/topic,77301.0.html Forum Topic] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;PC Cook Book&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_pccookbook &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.3.1&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; No Fix Available. Disable or remove.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://www.frsirt.com/english/advisories/2006/2739 FrSIRT Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,76009.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Per Forms&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_performs &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;amp;lt;= v1_beta &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version. [http://forge.joomla.org/sf/frs/do/viewRelease/projects.performs/frs.com_performs.com_performs_v2_beta ] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://secunia.com/advisories/21044/ Secunia Advisory]&amp;lt;br /&amp;gt;   [http://forum.joomla.org/index.php/topic,76654.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,76862.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;lt;b&amp;gt;Phil-A-Form&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt; 1.2&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to latest version.&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://forum.joomla.org/index.php?topic=174770.new#new Forum Topic] &lt;br /&gt;
&lt;br /&gt;
			&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; May 2007&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;People Book&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_peoplebook &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.1.5&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version. [http://forge.joomla.org/sf/frs/do/viewRelease/projects.peoplebook/frs.component.component_1_1_6_0] &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forge.joomla.org/sf/go/artf5410?nav=1 Joomla Forge]  &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;Prince Clan Chess&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_pcchess &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 0.8&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Author suggest manually patching. [http://www.princeclan.org/] &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; See  [http://www.princeclan.org/ this site]. &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;PollXT&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_pollxt &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.22.07&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version. [http://www.joomlaxt.com/index.php?option=com_remository&amp;amp;amp;Itemid=77&amp;amp;amp;func=fileinfo&amp;amp;amp;id=9] &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; [http://secunia.com/advisories/21068/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,77975.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://secunia.com/advisories/21068/ Secunia Advisory] &lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt; RS Gallery2&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_rsgallery2&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.11.3&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version. [http://forge.joomla.org/sf/go/projects.rsgallery2/frs.rsg2_alpha_builds.rsg2_1_11_4]&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://forum.joomla.org/index.php/topic,73453.0.html Forum Topic] &lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 06&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt;RWCards&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt; 2.4.4&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt; [http://forum.joomla.org/index.php/topic,154792.msg749006.html#msg749006 Forum Topic] &amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 26 June 2007&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;lt;b&amp;gt;Security Images&amp;lt;/b&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			com_securityimages&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 3.0.5&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://secunia.com/advisories/21260/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,81589.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; June 2007&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;lt;b&amp;gt;SEF404x&amp;lt;/b&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
			com_sef&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; No Fix Available.  Remove completely or use at your own risk.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; No references.&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;2006&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt;sh404SEF&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;1.2.4 t, u, or w &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Patch or update.&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt; [http://forum.joomla.org/index.php/topic,226147.0.html  Forum Topic] &amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;23 Oct, 2007&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;Site Map&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_sitemap &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; Abandoned.  Remove completely or use at your own risk.&amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://www.simplemachines.org/community/index.php?topic=97649.0] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &lt;br /&gt;
			 [http://secunia.com/advisories/21055/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,76326.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://secunia.com/advisories/21055/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;SimpleBoard&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_simpleboard &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; All&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest JoomlaBoard.  JoomlaBoard is compatible with SimpleBoard.  [http://developer.joomla.org/sf/frs/do/viewRelease/projects.simpleboard/frs.joomlaboard_1_1.joomlaboard_1_1_2 Download here].&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			 [http://secunia.com/advisories/20981/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://secunia.com/advisories/20409/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,75668.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://secunia.com/advisories/20981/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;SMF Bridge&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_smf &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.1.4&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			Versions other than 1.1RC2.  Fix Available.   [http://www.simplemachines.org/community/index.php?topic=100140.0 See this thread]. &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;amp;nbsp;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			Version 1.1RC2 only.  Upgrade available.  &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://www.simplemachines.org/community/index.php?topic=97649.0 See this thread.]  &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://secunia.com/advisories/21079/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://www.simplemachines.org/community/index.php?topic=100140.0 Simple Machines Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,78313.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,77716.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,78359.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,76609.0.html Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			 [http://secunia.com/advisories/21079/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;b&amp;gt;TaskHopper&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_thopper &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.1&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to latest version.&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,159111.0.html Forum Topic] &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			&amp;lt;b&amp;gt;User Home Pages 1 and 2&amp;lt;/b&amp;gt;&lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;p&amp;gt;&lt;br /&gt;
			com_uhp and com_uhp2 &lt;br /&gt;
			&amp;lt;/p&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.1.1 (?)&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to latest stable version. [http://www.ravenswoodit.co.uk/index.php?option=com_docman&amp;amp;amp;task=cat_view&amp;amp;amp;gid=78&amp;amp;amp;Itemid=13] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;  [http://forum.joomla.org/index.php/topic,81308.msg416865.html#msg416865 Forum Topic]&amp;lt;br /&amp;gt;&lt;br /&gt;
   [http://secunia.com/advisories/21305/ Secunia Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,81308.msg416865.html#msg416865 Forum Topic] &amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; June 2007&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt;VirtueMart&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;amp;lt;= 1.0.13a&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;Upgrade to version &amp;gt;= 1.0.14. Available  [http://virtuemart.net/index.php?option=com_content&amp;amp;task=view&amp;amp;id=54&amp;amp;Itemid=147 here]. &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; [http://virtuemart.net/index.php?option=com_content&amp;amp;task=view&amp;amp;id=275&amp;amp;Itemid=127 Security Bulletin] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;January 2008&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;lt;b&amp;gt;WordPress&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/b&amp;gt;&amp;lt;i&amp;gt;(Not a Joomla! extension, but worth noting.)&amp;lt;/i&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2.1.1&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; Upgrade to latest stable version.&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;[http://forum.joomla.org/index.php/topic,146478.msg737784.html#msg737784 Forum Topic]&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; 26 June 2007&amp;lt;br /&amp;gt;&lt;br /&gt;
			&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; &amp;lt;b&amp;gt;zOOm Media Gallery&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt;&amp;amp;lt;= 2.5.1 RC4&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td&amp;gt; [http://www.zoomfactory.org/index.php?option=com_remository&amp;amp;amp;Itemid=61&amp;amp;amp;func=select&amp;amp;amp;id=1 Upgrade to latest stable version].&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; [http://www.frsirt.com/english/advisories/2007/1353 FrSIRT Advisory] &amp;lt;br /&amp;gt;&lt;br /&gt;
			 [http://forum.joomla.org/index.php/topic,160119.0.html Forum Topic] &amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td&amp;gt; 2006&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
                &amp;lt;tr&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt; &amp;lt;b&amp;gt;BF Survey Pro&amp;lt;br /&amp;gt;BF Survey Basic&amp;lt;br /&amp;gt;BF Quiz&amp;lt;/b&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt;&amp;amp;lt;=1.2.5&amp;lt;br /&amp;gt;&amp;amp;lt;=1.0&amp;lt;br /&amp;gt;&amp;amp;lt;=1.1.1&amp;lt;/td&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt;[http://www.tamlyncreative.com.au/software/index.php/downloads.html Upgrade to latest versions]&amp;lt;/td&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt;[http://forum.joomla.org/viewtopic.php?f=431&amp;amp;t=336055&amp;amp;start=0 Forum Post]&amp;lt;br /&amp;gt;[http://www.tamlyncreative.com.au/software/forum/index.php?topic=357.0 Developer's Forum Post]&amp;lt;/td&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt;September, 2009&amp;lt;/td&amp;gt;&lt;br /&gt;
                &amp;lt;/tr&amp;gt;&lt;br /&gt;
                &amp;lt;tr&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt; &amp;lt;b&amp;gt;Photoblog (com_photoblog)&amp;lt;/td&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt;Unknown&amp;lt;/td&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt;Unknown&amp;lt;/td&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt;[http://www.securityfocus.com/bid/36809/info Security Focus Advisory]&amp;lt;/td&amp;gt;&lt;br /&gt;
                        &amp;lt;td&amp;gt;October 26, 2009&amp;lt;/td&amp;gt;&lt;br /&gt;
                &amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;/div&gt;</summary>
		<author><name>CirTap</name></author>	</entry>

	<entry>
		<id>http://docs.joomla.org/Archived_vel</id>
		<title>Archived vel</title>
		<link rel="alternate" type="text/html" href="http://docs.joomla.org/Archived_vel"/>
				<updated>2011-07-15T11:27:22Z</updated>
		
		<summary type="html">&lt;p&gt;CirTap: Protected &amp;quot;Vulnerable Extensions List/Archive/2009-10&amp;quot; ([edit=sysop] (indefinite) [move=sysop] (indefinite))&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{RightTOC}}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  '''Extension'''&lt;br /&gt;
! class=&amp;quot;unsortable&amp;quot;| '''Details'''&lt;br /&gt;
!  '''Reference Link'''&lt;br /&gt;
!  '''Extension Update Link'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''com_ajaxchat'''&lt;br /&gt;
|  Summary: PHP remote file inclusion vulnerability in Fiji Web Design Ajax Chat ('''com_ajaxchat''') component 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[mosConfig_absolute_path] parameter to tests/ajcuser.php.New version release December 22,2009&lt;br /&gt;
Published: october 28 2009&lt;br /&gt;
|  [[NIST:CVE-2009-3822|CVE-2009-3822]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | [http://extensions.joomla.org/extensions/communication/chat/10767 update v 1.1]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''com_booklibrary'''&lt;br /&gt;
|  PHP remote file inclusion vulnerability in doc/releasenote.php in the BookLibrary ('''com_booklibrary''') component 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter, a different vector than [[NIST:CVE-2009-2637|CVE-2009-2637]]. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 10/28/2009&lt;br /&gt;
CVSS Severity: 7.5 (HIGH)&lt;br /&gt;
|  [[NIST:CVE-2009-3817|CVE-2009-3817]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''[http://ordasoft.com/Download/Joomla1.0-extensions/Joomla1.0-components/View-category.html developer site updates]'''&lt;br /&gt;
|-&lt;br /&gt;
|   style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''com_foobla_suggestions'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the foobla Suggestions ('''com_foobla_suggestions''') component 1.5.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the idea_id parameter to index.php.&lt;br /&gt;
Published: 10/11/2009&lt;br /&gt;
CVSS Severity: 7.5 (HIGH)&lt;br /&gt;
|  [[NIST:CVE-2009-3669|CVE-2009-3669]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | [http://foobla.com/news/latest/fixed-foobla-suggestions-for-joomla-idea_id-sql-injection-vulnerability.html developer reported upgrade]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_djcatalog'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the DJ-Catalog ('''com_djcatalog''') component for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a showItem action and (2) cid parameter in a show action to index.php.&lt;br /&gt;
Published: 10/11/2009&lt;br /&gt;
CVSS Severity: 6.8 (MEDIUM)&lt;br /&gt;
|  [[NIST:CVE-2009-3661|CVE-2009-3661]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''com_cbresumebuilder'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the JoomlaCache CB Resume Builder (''''''com_cbresumebuilder''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the group_id parameter in a group_members action to index.php.&lt;br /&gt;
Published: 10/09/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3645|CVE-2009-3645]] &lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |'''[http://www.joomlacache.com/commercial-extensions/security-update.html Developer Update]'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  |  '''com_soundset'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Soundset ('''com_soundset''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter to index.php.&lt;br /&gt;
Published: 10/09/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3644|CVE-2009-3644]]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  |  '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  |'''com_sportfusion'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Kinfusion SportFusion ('''com_sportfusion''') component 0.2.2 through 0.2.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid[0] parameter in a teamdetail action to index.php.&lt;br /&gt;
Published: 09/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3491|CVE-2009-3491]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  |'''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_icrmbasic'''&lt;br /&gt;
|  Summary: A certain interface in the iCRM Basic ('''com_icrmbasic''') component 1.4.2.31 for Joomla! does not require administrative authentication, which has unspecified impact and remote attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 09/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3481|CVE-2009-3481]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_mytube'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the MyRemote Video Gallery ('''com_mytube''') component 1.0 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter in a videos action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3446|CVE-2009-3446]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_fastball'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Fastball ('''com_fastball''') component 1.1.0 through 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the league parameter to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3443|CVE-2009-3443]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | [http://www.fastballproductions.com   latest version] 1.2.1 &lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_facebook'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the JoomlaFacebook ('''com_facebook''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a student action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3438|CVE-2009-3438]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_tupinambis'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Tupinambis ('''com_tupinambis''') component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the proyecto parameter in a verproyecto action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3434|CVE-2009-3434]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''com_idoblog'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the IDoBlog ('''com_idoblog''') component 1.1 build 30 for Joomla! allows remote attackers to execute arbitrary SQL commands via the userid parameter in a profile action to index.php, a different vector than [[NIST:CVE-2008-2627|CVE-2008-2627]].&lt;br /&gt;
Published: 09/25/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3417|CVE-2009-3417]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot; |'''[http://idojoomla.com/download.html/ '''New Version v 1.1''' (build 32)]'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_hbssearch'''&lt;br /&gt;
|  Summary: Cross-site scripting ('''XSS''') vulnerability in the Hotel Booking Reservation System ('''aka HBS or com_hbssearch''') component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the adult parameter in a showhoteldetails action to index.php.&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 4.3 ('''MEDIUM''')&lt;br /&gt;
|  [[NIST:CVE-2009-3368|CVE-2009-3368]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_hbssearch'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System ('''aka HBS or com_hbssearch''') component for Joomla! allow remote attackers to execute arbitrary SQL commands via the ('''1''') h_id, ('''2''') id, and ('''3''') rid parameters to longDesc.php, and the h_id parameter to ('''4''') detail.php, ('''5''') detail1.php, ('''6''') detail2.php, ('''7''') detail3.php, ('''8''') detail4.php, ('''9''') detail5.php, ('''10''') detail6.php, ('''11''') detail7.php, and ('''12''') detail8.php, different vectors than [[NIST:CVE-2008-5865|CVE-2008-5865]], [[NIST:CVE-2008-5874|CVE-2008-5874]], and [[NIST:CVE-2008-5875|CVE-2008-5875]].&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3357|CVE-2009-3357]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''com_alphauserpoints'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in frontend/assets/ajax/checkusername.php in the AlphaUserPoints ('''com_alphauserpoints''') component 1.5.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the username2points parameter.&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3342|CVE-2009-3342]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |'''[http://www.alphaplug.com/index.php/news/142-alphauserpoints-153-released.html 1.5.3]'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''TurtuShout'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the TurtuShout component 0.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Name field.&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3335|CVE-2009-3335]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jinc'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Lhacky! Extensions Cave Joomla! Integrated Newsletters Component ('''aka JINC or com_jinc''') component 0.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a messages action to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3334|CVE-2009-3334]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''com_jbudgetsmagic'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the JBudgetsMagic ('''com_jbudgetsmagic''') component 0.3.2 through 0.4.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the bid parameter in a mybudget action to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3332|CVE-2009-3332]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | '''[http://sopinet.com/jbudgetsmagic/index.php?option=com_remository&amp;amp;Itemid=5&amp;amp;lang=en Update to 0.4.1]'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_surveymanager'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Focusplus Developments Survey Manager ('''com_surveymanager''') component 1.5.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the stype parameter in an editsurvey action to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3325|CVE-2009-3325]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_album'''&lt;br /&gt;
|  Summary: Directory traversal vulnerability in the Roland Breedveld Album ('''com_album''') component 1.14 for Joomla! allows remote attackers to access arbitrary directories and have unspecified other impact via a .. ('''dot dot''') in the target parameter to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3318|CVE-2009-3318]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;   | '''com_jreservation'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the [http://extensions.joomla.org/extensions/vertical-markets/booking-a-reservation/9798 JReservation] ('''com_jreservation''') component 1.0 and 1.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a propertycpanel action to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3316|CVE-2009-3316]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot; |  [http://www.jforjoomla.com Updated 28th] Jan fixed 13th Nov&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''IXXO Cart Standalone'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in IXXO Cart Standalone before 3.9.6.1, and the IXXO Cart component for Joomla! 1.0.x, allows remote attackers to execute arbitrary SQL commands via the parent parameter.&lt;br /&gt;
Published: 09/16/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3215|CVE-2009-3215]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_digifolio'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the DigiFolio ('''com_digifolio''') component 1.52 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a project action to index.php.&lt;br /&gt;
Published: 09/15/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3193|CVE-2009-3193]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_aclassf'''&lt;br /&gt;
|  Summary: Cross-site scripting ('''XSS''') vulnerability in '''gmap.php''' in the Almond Classifieds ('''com_aclassf''') component 7.5 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the addr parameter.&lt;br /&gt;
Published: 09/10/2009&lt;br /&gt;
CVSS Severity: 4.3 ('''MEDIUM''')&lt;br /&gt;
|  [[NIST:CVE-2009-3155|CVE-2009-3155]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;   | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''com_aclassf'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Almond Classifieds ('''com_aclassf''') component 7.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the replid parameter in a manw_repl add_form action to index.php, a different vector than [[NIST:CVE-2009-2567|CVE-2009-2567]].&lt;br /&gt;
Published: 09/10/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3154|CVE-2009-3154]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | [http://www.almondsoft.com/alcl.html Developer latest component]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jabode'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in Jabode horoscope extension ('''com_jabode''') for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a sign task to index.php.&lt;br /&gt;
Published: 09/08/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
&lt;br /&gt;
|  [[NIST:CVE-2008-7169|CVE-2008-7169]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_gameserver'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Game Server ('''com_gameserver''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a gamepanel action to index.php.&lt;br /&gt;
Published: 09/03/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3063|CVE-2009-3063]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_artportal'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Artetics.com Art Portal ('''com_artportal''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the portalid parameter to index.php.&lt;br /&gt;
Published: 09/03/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3054|CVE-2009-3054]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:#cef2e0; color:black&amp;quot; | '''com_agora'''&lt;br /&gt;
|  Summary: Directory traversal vulnerability in the Agora ('''com_agora''') component 3.0.0b for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the action parameter to the avatars page, reachable through index.php.&lt;br /&gt;
Published: 09/03/2009&lt;br /&gt;
CVSS Severity: 6.8 ('''MEDIUM''')&lt;br /&gt;
|  [[NIST:CVE-2009-3053|CVE-2009-3053]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot; |'''[http://jvitals.com/index.php?option=com_rokdownloads&amp;amp;view=file&amp;amp;Itemid=108&amp;amp;id=282:agora-3-0 3.0.7]'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_simpleshop'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Simple Shop Galore ('''com_simpleshop''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the section parameter in a section action to index.php, a different vulnerability than [[NIST:CVE-2008-2568|CVE-2008-2568]]. NOTE: this issue was disclosed by an unreliable researcher, so the details might be incorrect.&lt;br /&gt;
Published: 08/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-7033|CVE-2008-7033]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_groups'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Permis ('''com_groups''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a list action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 08/17/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-2789|CVE-2009-2789]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:#cef2e0; color:black&amp;quot; | '''com_content'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the content component ('''com_content''') 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a blogcategory action to index.php.&lt;br /&gt;
Published: 08/10/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6923|CVE-2008-6923]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |'''[http://developer.joomla.org/security/news/305-20091103-core-front-end-editor-issue-.html Resolution]'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Live Chat ('''com_livechat''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the last parameter to getChatRoom.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6883|CVE-2008-6883]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: Live Chat ('''com_livechat''') component 1.0 for Joomla! allows remote attackers to use the xmlhttp.php script as an open HTTP proxy to hide network scanning activities or scan internal networks via a GET request with a full URL in the query string.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6882|CVE-2008-6882]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the Live Chat ('''com_livechat''') component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the last parameter to ('''1''') getChat.php, ('''2''') getChatRoom.php, and ('''3''') getSavedChatRooms.php.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6881|CVE-2008-6881]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''JUMI'''&lt;br /&gt;
|  There is a backdoor in JUMI that installs itself when JUMI is installed on your web site. It sends your credentials to a website, and sets up a back door for remote code execution.&lt;br /&gt;
Please remove JUMI2.0.5 immediately. &lt;br /&gt;
It will be simple enough to remove the compromised code from this download, but you need to do &lt;br /&gt;
a full security audit on your site as well as you have been compromised. Added November 2009&lt;br /&gt;
|  [http://code.google.com/p/jumi/updates/list Report]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |[http://code.google.com/p/jumi/updates/list Jumi Update]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''com_photoblog'''&lt;br /&gt;
|  Input Validation Error Added November 2009&lt;br /&gt;
|  [http://www.securityfocus.com/bid/36809/ 36809]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |[http://webguerilla.net/downloads/3-components-for-joomla-1 webguerilla Photoblog alpha 3b]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jshop'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the JShop ('''com_jshop''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a product action to index.php.&lt;br /&gt;
Published: 11/02/2009&lt;br /&gt;
CVSS Severity: 7.5 '''(HIGH)''' &lt;br /&gt;
|  [[NIST:CVE-2009-3835|CVE-2009-3835]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot; |'''BF Survey Pro'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the '''BF Survey Pro''' v1.2.5 or lower  (fixed in version 1.2.6). '''BF Survey Basic v1.0''' (fixed in version 1.1). '''BF Quiz v1.1.1''' (fixed in version 1.2 or greater) Added November 2009&lt;br /&gt;
|  [http://www.tamlyncreative.com.au/software/forum/index.php?topic=357.0 tamlyncreative.com.au]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |[http://www.tamlyncreative.com.au/software/forum/index.php?topic=357.0 update]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot; |'''Joo!BB 0.9.1 '''&lt;br /&gt;
|  Summary: Persistent XSS/MySQL Injection vulnerabilities in Joo!BB 0.9.1 Added November 2009&lt;br /&gt;
|  [http://www.joobb.org/community/board/topic/700-MultipleXSSSQLInjectionVulnerabilities.html joob.org]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot; |[http://www.joobb.org/downloads/components.html update]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''sh404sef '''&lt;br /&gt;
|  Summary: sh404sef URI XSS Vulnerability  Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/sh404sef-uri-xss-vulnerability.html jeffchannell.com]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |[http://extensions.siliana.com/en/2009060876/sh404SEF-and-url-rewriting/Interim-release-of-sh404sef-for-Joomla-1.5.x.html update]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''AWD Wall 1.5''' &lt;br /&gt;
|  Summary '''AWD Wall 1.5''' Blind SQL Injection Vulnerability.The Joomla component AWD Wall 1.5 suffers from an SQL Injection vulnerability in its handling of the 'cbuser' parameter.Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/awd-wall-15-blind-sql-injection-vulnerability.html Notice]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | '''[http://www.awdsolution.com/template_demo/testsite/index.php?option=com_content&amp;amp;view=article&amp;amp;id=48&amp;amp;Itemid=72 developer update]'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''EasyBook 2.0.0rc4'''&lt;br /&gt;
|  Summary: The Joomla component '''EasyBook 2.0.0rc4''' suffers from multiple persistent XSS vulnerabilities. One seems fairly critical, while the others would take some incredible creativity to actively exploit. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/easybook-200rc4-multiple-xss-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''F!BB 1.5.96''' &lt;br /&gt;
|  Summary: The Joomla component '''F!BB 1.5.96 RC''' suffers from multiple persistent XSS vulnerabilities, as well SQL Injection in its user search feature. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/fbb-1596-rc-multiple-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Testimonial Ku 2.0 Admin Panel'''&lt;br /&gt;
|  Summary: The Joomla component '''Testimonial Ku 2.0''' is vulnerable to persistent XSS in the administrator panel. A malicious user can submit a testimonial containing &amp;lt;script&amp;gt; tags with absolutely no quotes and inject that script into the administrator panel through any of the available inputs except &amp;quot;email&amp;quot;. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/testimonial-ku-20-admin-panel-persistent-xss.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''MS Comment 0.8.0b'''&lt;br /&gt;
|  Summary '''MS Comment 0.8.0b for Joomla''', a commenting plugin, suffers from an multiple vulnerabilities. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/ms-comment-080b-multiple-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |  '''!JoomlaComment 4.0 beta1'''&lt;br /&gt;
|  Summary: '''!JoomlaComment 4.0 beta1''', a commenting plugin, suffers from multiple XSS vulnerabilities. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/joomlacomment-40-beta1-multiple-xss-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | '''  [http://compojoom.com/blog/8-news/121-joomlacomment-40-rc1-released Developer Notice 4.0 rc1]''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''WebAmoeba Ticket System 3.0.0'''&lt;br /&gt;
|  Summary:  '''WebAmoeba Ticket System 3.0.0''', a Joomla help desk component. The vulnerability is with the BBCode library used to parse BBCode tags, as it does not strip javascript: urls from [url] tags. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/webamoeba-ticket-system-300-bbcode-xss.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |'''Kunena 1.5.x''' &lt;br /&gt;
|Summary: This is an important security release and users are urged to update immediately. Five security issues and an Internet Explorer 8 table bug have been resolved in this release. This release also contains many other important bug fixes. Added 18 November 2009&lt;br /&gt;
|[http://www.kunena.com/blog/19-developer-blog/51-kunena-157-security-release-now-available Advisory]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |[http://www.kunena.com/blog/19-developer-blog/52-kunena-158-service-release-now-available Latest 1.5.8 Version]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_siirler'''&lt;br /&gt;
|  Summary:  SQL injection vulnerability in the '''Q-Proje Siirler Bileseni (com_siirler)''' component 1.2 RC for Joomla! allows remote attackers to execute arbitrary SQL commands via the sid parameter in an sdetay action to index.php. Added 18 November 2009&lt;br /&gt;
|  [[NIST:CVE-2009-3972 | CVE-2009-3972]]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''jTips (com_jtips)'''&lt;br /&gt;
|SUmmary:SQL injection vulnerability in the '''jTips (com_jtips)''' component 1.0.7 and 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the season parameter in a ladder action to index.php. Added 18 November 2009&lt;br /&gt;
| [[NIST:CVE-2009-3971 |CVE-2009-3971]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''NinjaMonials'''&lt;br /&gt;
| Summary: SQL injection vulnerability in the '''NinjaMonials (com_ninjacentral)''' component 1.1.0 for '''Joomla 1.0.x''' ! allows remote attackers to execute arbitrary SQL commands via the testimID parameter in a display action to index.php. Added 18 November 2009&lt;br /&gt;
|  [[NIST:CVE-2009-3964 | CVE-2009-3964]]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |'''  [http://ninjaforge.com/index.php?option=com_ninjacentral&amp;amp;page=show_package&amp;amp;id=14&amp;amp;Itemid=235 developer patch Ver 1.2]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   | '''webee 1.1.1 &amp;amp;1.2'''&lt;br /&gt;
|Summary: '''webee 1.1.1,''' a Joomla commenting plugin, suffers from multiple vulnerabilities. '''webee has been updated to 1.2''' as of 12 November 2009 and''' still suffers''' from SQL Injection. XSS was not tested in 1.2. Added 19 November 2009&lt;br /&gt;
| [http://jeffchannell.com/Joomla/webee-111-multiple-vulnerabilities.html jeffchannell.com]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | ''' [http://extensions.joomla.org/extensions/contacts-and-feedback/articles-comments/10155 developer update ver2.0]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''iF Portfolio Nexus'''&lt;br /&gt;
|Summary: The '''iF Portfolio Nexus component for Joomla!''' is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements using the id parameter, which could allow the attacker to view, add, modify or delete information in the back-end database. Nov 18, 2009&lt;br /&gt;
|[http://secunia.com/advisories/37408/ secunia.com 37408/]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; |[http://www.inertialfate.za.net/help/forums/topic?id=10&amp;amp;p=3#p172 iF Portfolio Nexus v1.1.1 released]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''JoomClip'''&lt;br /&gt;
|Summary: The '''JoomClip component for Joomla!''' is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements to the index.php script using the cat parameter, which could allow the attacker to view, add, modify or delete information in the back-end database.  Nov 18, 2009&lt;br /&gt;
|[http://secunia.com/advisories/37400/ secunia.com 37400/]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''Joomla XML'''&lt;br /&gt;
|Summary: Joomla! before 1.5.15 allows remote attackers to read an extension's XML file, and thereby obtain the extension's version number, via a direct request.&lt;br /&gt;
Published: 11/16/2009&lt;br /&gt;
|[[NIST:CVE-2009-3946 | CVE-2009-3946]] &lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |'''[http://developer.joomla.org/security/news/306-20091103-core-xml-file-read-issue.html Resolution]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Mygallery Remote SQL Injection Vulnerability''' &lt;br /&gt;
|Summary: Joomla Component mygallery ( farbinform_krell) Remote SQL Injection Vulnerability Added 27 Nov 2009 {{JVer|1.5}} NB: This could be an error in our database as the only one we could find was for wordpress.If anyone know of one for joomla please let us know..(poss joomlicious.com CM)&lt;br /&gt;
|[http://www.exploit-db.com] &lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Extreme Google Calendar'''&lt;br /&gt;
|Summary: '''com_gcalendar 1.1.2''' (gcid) Remote SQL Injection Vulnerability&lt;br /&gt;
Remote SQL Injection were identified in Google Calendar Component [http://extensions.joomla.org/extensions/calendars-a-events/calendars/4188 Extension Link] Added 27 Nov 2009 &lt;br /&gt;
|[http://www.exploit-db.com reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''LyftenBloggie'''&lt;br /&gt;
| Summary: [http://www.lyften.com/products/lyftenbloggie.html LyftenBloggie] Component &amp;quot;author&amp;quot; SQL Injection Vulnerability LyftenBloggie 1.x Added 27 Nov 2009&lt;br /&gt;
|[http://secunia.com/advisories/product/28005/	 SA37499]&lt;br /&gt;
| [http://jeffchannell.com/Joomla/lyften-bloggie-sql-injection-fix.html Un official fix]. Developer fix not release at 30 Nov 09 ''' [http://www.lyften.com/products/lyftenbloggie/extensions/download/id-20.html 1.0.4a (last update on Dec 28, 2009)]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''Sermon speaker'''&lt;br /&gt;
|Summary: [http://joomlacode.org/gf/project/sermon_speaker sermon speaker] sql vulnerability and password reset vulnerability version 3.2 and below&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |[http://joomlacode.org/gf/project/sermon_speaker/forum/?action=ForumBrowse&amp;amp;forum_id=7897&amp;amp;_forum_action=ForumMessageBrowse&amp;amp;thread_id=15219 Developer fix] 30 Nov 2009&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | [http://joomlacode.org/gf/project/musicgallery/ MusicGallery]&lt;br /&gt;
|Summary: [http://joomlacode.org/gf/project/musicgallery/ Component MusicGallery] SQL Injection Vulnerability 30 November {{JVer|1.5}}&lt;br /&gt;
|[[NIST:CVE-2009-4217 | CVE-2009-4217]]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; | [http://joomlacode.org/gf/project/musicgallery/ developer]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== December 2009 Compiled Reports ==&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  '''Extension'''&lt;br /&gt;
! class=&amp;quot;unsortable&amp;quot;| '''Details'''&lt;br /&gt;
!  '''Reference Link'''&lt;br /&gt;
!  '''Extension Update Link'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Omilen Photo Gallery'''&lt;br /&gt;
|Summary: Directory traversal vulnerability in the [http://extensions.joomla.org/extensions/photos-&amp;amp;-images/photo-flash-gallery/6373/details Omilen Photo Gallery] (com_omphotogallery) component Beta 0.5 for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the controller parameter to index.php.&lt;br /&gt;
Published: 12/04/2009&lt;br /&gt;
|[[NIST:CVE-2009-4202 | CVE-2009-4202]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Seminar'''&lt;br /&gt;
|Summary: SQL injection vulnerability in the [http://seminar.vollmar.ws/ Seminar] (com_seminar) component 1.28 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a View_seminar action to index.php.&lt;br /&gt;
Published: 12/04/2009&lt;br /&gt;
|[[NIST:CVE-2009-4200 | CVE-2009-4200]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''Mambo Resident'''&lt;br /&gt;
|Summary: Multiple SQL injection vulnerabilities in the Mambo Resident (aka Mos Res or com_mosres) component 1.0f for Mambo and Joomla!, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) property_uid parameter in a viewproperty action to index.php and the (2) regID parameter in a showregion action to index.php. Mambo Resident component for v4.5.2 '''may only be for 1.0.xx versions of J!'''&lt;br /&gt;
Published: 12/04/2009&lt;br /&gt;
|[[NIST:CVE-2009-4199 | CVE-2009-4199]]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; |[http://www.jomres.net/ Replacement Extension 08 dec 09]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''ProofReader''' &lt;br /&gt;
|Summary: Multiple cross-site scripting (XSS) vulnerabilities in index.php in the ProofReader (com_proofreader) component 1.0 RC9 and earlier for Joomla! allow remote attackers to inject arbitrary web script or HTML via the URI, which is not properly handled in (1) 404 or (2) error pages. Published: 12/02/2009 CVSS Severity: 4.3 (MEDIUM)&lt;br /&gt;
| [[NIST:CVE-2009-4157 | CVE-2009-4157]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''Laoneo Google Calendar GCalendar'''&lt;br /&gt;
|Summary: SQL injection vulnerability in the [http://g4j.laoneo.net/content/extensions/download/cat_view/20-joomla-15x/21-gcalendar.html Google Calendar GCalendar] (com_gcalendar) component 1.1.2, 2.1.4, and possibly earlier versions for Joomla! allows remote attackers to execute arbitrary SQL commands via the gcid parameter. NOTE: some of these details are obtained from third party information. Published: 11/29/2009 CVSS Severity: 7.5 (HIGH) Note: There is already a listing for GCalendar 1.1.2&lt;br /&gt;
|[[NIST:CVE-2009-4099 | CVE-2009-4099]]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;   | [http://g4j.laoneo.net/content/extensions/download/doc_details/28-gcalendar-suite-215.html Latest version GCalendar Suite 2.1.5]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''D4J eZine'''&lt;br /&gt;
|Summary: PHP remote file inclusion vulnerability in class/php/d4m_ajax_pagenav.php in the D4J eZine (com_ezine) component 2.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS mosConfig_absolute_path parameter. Published: 11/29/2009 CVSS Severity: 7.5 (HIGH)&lt;br /&gt;
|[[NIST:CVE-2009-4094 | CVE-2009-4094]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''Quick News'''&lt;br /&gt;
| Summary: The Joomla [http://joomlacode.org/gf/project/quicknews/ Quick News component] suffers from a remote SQL injection vulnerability. added 1st Dec 09&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''Joaktree component'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/miscellaneous/genealogy/9842 Joaktree] Vulnerability : SQL injection/ added 1st Dec 09&lt;br /&gt;
|[http://securityreason.com/exploitalert/7508 7508]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | '''  [http://naastniels.nl/index.php/en/joaktree/downloads version 1.1 update]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''mojoblog'''&lt;br /&gt;
|Summary [http://www.joomlify.com/files/mojoblog/ MojoBlog] Multiple Remote File Include Vulnerability added 1st Dec 09 {{JVer|1.5}}&lt;br /&gt;
|[http://securityreason.com/exploitalert/7509 7509]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''YJ Whois''' &lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/external-contents/domain-search/5774 YJ Whois] '''Low security risk''',and fixesMalicious users may inject JavaScript, VBScript, ActiveX, HTML or Flash into a vulnerable application to fool a user in order to gather data from them. An attacker can steal the session cookie and take over the account. Files affected is , modules/mod_yj_whois.php added 3 December 09&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; |[http://www.youjoomla.com/xss-security-patch-for-yj-whois.html Developer Notice and fix 03 dec 09]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; | '''yt_color YOOOtheme'''&lt;br /&gt;
|Summary: [http://www.yootheme.com/ YT_color yootheme] Malicious users may inject JavaScript, VBScript, ActiveX, HTML or Flash into a vulnerable application to fool a user in order to gather data from them. An attacker can steal the session cookie and take over the account. added 5 dec 09&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | '''  [http://www.yootheme.com/member-area/downloads/item/templates-15/xss-and-php-53-patches All members without an active membership can download the template patches here].'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''TP Whois''' &lt;br /&gt;
|summary: [http://www.templateplazza.com/view-details/tpwhois/183-component-tp-whois-for-joomla-1.5.x.html TP Whois ] Malicious users may inject JavaScript, VBScript, ActiveX, HTML or Flash into a vulnerable application to fool a user in order to gather data from them. An attacker can steal the session cookie and take over the account. Added 3 december {{JVer|1.5}}&lt;br /&gt;
|[http://www.exploit-db.com Refrence]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''com_job'''&lt;br /&gt;
|Summary: Component com_job ( showMoreUse) SQL injection vulnerability  Added 9th Dec&lt;br /&gt;
|[http://xforce.iss.net/xforce/xfdb/54626 Reference]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |  '''JQuarks''' &lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/contacts-and-feedback/quiz-a-surveys/10590 JQuarks] SQL injection vulnerability {{JVer|1.5}} added 8th dec 09&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | [http://www.iptechinside.com/labs/projects/list_files/jquarks Developer Update ]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''Mamboleto Component 2.0 RC3'''&lt;br /&gt;
|Summary: [http://www.fernandosoares.com.br/index.php?option=com_docman&amp;amp;task=cat_view&amp;amp;gid=28&amp;amp;Itemid=28 Mamboleto Component 2.0 RC3]SQL injection vulnerability {{JVer|1.5}} added 12 December&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |  ''' JS JOBS'''&lt;br /&gt;
|Summary [http://www.joomshark.com/index.php?option=com_content&amp;amp;view=article&amp;amp;id=4&amp;amp;Itemid=8 JS JOBS] Joomla Component com_jsjobs 1.0.5.6 SQL Injection Vulnerabilities {{JVer|1.5}} added 12 December&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | '''  [http://www.joomsky.com/index.php?option=com_rokdownloads&amp;amp;view=folder&amp;amp;Itemid=3&amp;amp;id=2:components Developer update 1.0.5.7]''' &lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |  '''corePHP JPhoto'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/photos-a-images/photo-gallery/10365 'corePHP' JPhoto]SQL injection vulnerability {{JVer|1.5}} added 12 December&lt;br /&gt;
|[http://secunia.com/advisories/37676/ Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | '''  [http://www.corephp.com/blog/uber-fast-jphoto-security-release/ Developer Upgrade]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;    | '''com_virtuemart'''&lt;br /&gt;
|Summary: &amp;quot;com_virtuemart&amp;quot; http://virtuemart.net/  '''Version : 1.0''' Vulnerability : SQL injection added Date : 07- dec -09 {{JVer|1.5}}&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |[http://virtuemart.net/ latest version]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | ''' Kide Shoutbox'''&lt;br /&gt;
&lt;br /&gt;
|Summary: The Kide Shoutbox (com_kide) component 0.4.6 for Joomla! does not properly perform authentication, which allows remote attackers to post messages with an arbitrary account name via an insertar action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Added: December 08&lt;br /&gt;
|[[NIST:CVE-2009-4232 | CVE-2009-4232]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | ''' JoomPortfolio Component'''&lt;br /&gt;
|Summary: [http://www.joomplace.com/joomportfolio/joomportfolio.html JoomPortfolio] Input passed via the &amp;quot;secid&amp;quot; parameter to index.php (when &amp;quot;option&amp;quot; is set to &amp;quot;com_joomportfolio&amp;quot; and &amp;quot;task&amp;quot; is set to &amp;quot;showcat&amp;quot;) is not properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.The vulnerability is reported in version 1.0.0. Other versions may also be affected. Added: December 18 {{JVer|1.5}}&lt;br /&gt;
|[http://secunia.com/advisories/37838/ Reporting Site]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''City Portal (templates?)'''&lt;br /&gt;
|Summary:   City Portal Blind SQL Injection Vulnerability added: 2009-12-18&lt;br /&gt;
|[http://www.exploit-db.com Reference] Possibly this [http://www.youjoomla.com/jclick-city-portal-joomla-template.html tempate]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''Event Manager'''&lt;br /&gt;
|Summary:  [http://www.jforjoomla.com/Joomla-Components/event-manager-15-component.html Event Manager] Blind SQL Injection Vulnerability EDB-ID: 10549&lt;br /&gt;
added: 2009-12-18&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | com_zcalendar&lt;br /&gt;
|Summary:  com_zcalendar Blind SQL-injection Vulnerability&lt;br /&gt;
EDB-ID: 10548 added: 2009-12-18&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''com_acmisc'''&lt;br /&gt;
|Summary:  com_acmisc SQL injection added: 2009-12-18&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''com_digistore'''&lt;br /&gt;
|Summary:  com_digistore SQL injection EDB-ID: 10546 added: 2009-12-18  {{JVer|1.5}}&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | '''  [http://www.ijoomla.com/ijoomla-digistore/ijoomla-digistore/ijoomla-digistore-change-log/ Update change log] '''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''com_jbook'''&lt;br /&gt;
|Summary:   com_jbook Blind SQL-injection EDB-ID: 10545 added: 2009-12-18 {{JVer|1.0}}&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |  '''com_personel'''&lt;br /&gt;
|Summary: com_personel component for Joomla! is vulnerable to SQL injection.&lt;br /&gt;
|[http://xforce.iss.net/xforce/xfdb/54903 iss.net reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |  '''JEEMA Article Collection'''&lt;br /&gt;
|Summary: [http://www.forum.jeema.net/component/content/article/4-jeema-article-collection-component/13-about-jeema-article-collection.html JEEMA Article Collection] Input passed via the &amp;quot;catid&amp;quot; parameter to index.php (when &amp;quot;option&amp;quot; is set to &amp;quot;com_jeemaarticlecollection&amp;quot; and &amp;quot;view&amp;quot; is set to &amp;quot;longlook&amp;quot;) is not properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. version 1.0.0.1 {{JVer|1.5}} added 22 dec 09&lt;br /&gt;
| [http://secunia.com/advisories/37865/ secunia]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;    | [http://www.jeema.net/downloads/free-joomla-extensions/joomla-components/12-jeema-joomla-article-collection.htm fixed the same in the version v102.]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |  '''HotBrackets Tournament Brackets '''&lt;br /&gt;
|Summary: The [http://extensions.joomla.org/extensions/sports-a-games/sports/10746 HotBrackets Tournament Brackets] component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. {{JVer|1.5}} added 22 dec &lt;br /&gt;
|[http://www.securityfocus.com/bid/37439/ Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''Car Manager'''&lt;br /&gt;
|Summary: http://webformatique.com/ com_carman Cross Site Scripting Vulnerability added 24 december 09{{JVer|1.5}}&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot; |'''Schools component'''&lt;br /&gt;
|Summary: The 'com_schools' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.&lt;br /&gt;
|[http://www.securityfocus.com/bid/37469 Reference] added 24 dec 09&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''webcamxp'''&lt;br /&gt;
|[http://extensions.joomla.org/extensions/communication/video-conference/4490 com_webcamxp] Cross Site Scripting Vulnerabilities  Last version 2008 {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''beeheard'''&lt;br /&gt;
|[http://extensions.joomla.org/extensions/contacts-and-feedback/testimonials-a-suggestions/10283 beeheard]  Blind SQL injection Vulnerability {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | '''  [http://beeheard.cmstactics.com/change-log Version 1.4.2] 04 Jan'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''jm-recommend'''&lt;br /&gt;
|jm-recommendCross Site Scripting Vulnerabilities. unable to locate on jed. {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | facileforms&lt;br /&gt;
| com_facileforms Cross Site Scripting Vulnerabilities. unable to locate on jed. Product considered retired.  {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''adagency'''&lt;br /&gt;
| [http://www.ijoomla.com/ijoomla-ad-agency/ijoomla-ad-agency/index/ adagency ]Vulnerabilities {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |  '''com_intuit'''&lt;br /&gt;
|[http://www.san-diego-web-designer.com/new-file-download/item/root/aboutimage-igateway-for-joomla.html com_intuit]Local File Inclusion Vulnerability {{JVer|1.5}} Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | '''  [http://www.securityfocus.com/bid/37494/discuss Retired]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''MemoryBook'''&lt;br /&gt;
|[http://extensions.joomla.org/extensions/calendars-a-events/birthdays-a-historic-events/10868 MemoryBook 1.2]  Multiple Vulnerabilities. requires: magic quotes OFF, user account {{JVer|1.5}} Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''qpersonel'''&lt;br /&gt;
|[http://extensions.joomla.org/extensions/directory-a-documentation/thematic-directory/7049 qpersonel ] Cross Site Scripting Vulnerabilities {{JVer|1.0}}[[Image:http://extensions.joomla.org/images/jed/compat_15_legacy.png]] Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''opryknings point''' &lt;br /&gt;
|com_oprykningspoint_mc Cross Site Scripting Vulnerabilities {{JVer|1.5}} Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''trabalhe conosco'''&lt;br /&gt;
|com_trabalhe_conosco Cross Site Scripting Vulnerabilities {{JVer|1.5}} Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''DhForum'''&lt;br /&gt;
|com_dhforum SQL Injection Vulnerability. considered retired/EOL Dec. 27 {{JVer|1.0}}1.5 legacy&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |'''com_morfeoshow'''&lt;br /&gt;
|[http://extensions.joomla.org/extensions/photos-a-images/photo-gallery-add-ons/9810 morfeoshow] this was a false report &lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''  false report'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''Run Digital Download rd-download''' &lt;br /&gt;
|[http://extensions.joomla.org/extensions/directory-a-documentation/downloads/7838 RD Download] Local File Disclosure Vulnerability  {{JVer|1.5}} Dec. 30 Version affected not disclosed.&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | [http://extensions.joomla.org/extensions/directory-a-documentation/downloads/7838 Version 0.9 relased] &lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|}&lt;br /&gt;
== November 2009 Compiled Vulnerability Reports. RESOLVED ONLY  ==&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
Items are not in any particular order.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  '''Extension'''&lt;br /&gt;
! class=&amp;quot;unsortable&amp;quot;| '''Details'''&lt;br /&gt;
!  '''Reference Link'''&lt;br /&gt;
!  '''Extension Update Link'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_djcatalog'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the DJ-Catalog ('''com_djcatalog''') component for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a showItem action and (2) cid parameter in a show action to index.php.&lt;br /&gt;
Published: 10/11/2009&lt;br /&gt;
CVSS Severity: 6.8 (MEDIUM)&lt;br /&gt;
|  [[NIST:CVE-2009-3661|CVE-2009-3661]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  |  '''com_soundset'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Soundset ('''com_soundset''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter to index.php.&lt;br /&gt;
Published: 10/09/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3644|CVE-2009-3644]]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  |  '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  |'''com_sportfusion'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Kinfusion SportFusion ('''com_sportfusion''') component 0.2.2 through 0.2.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid[0] parameter in a teamdetail action to index.php.&lt;br /&gt;
Published: 09/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3491|CVE-2009-3491]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  |'''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_icrmbasic'''&lt;br /&gt;
|  Summary: A certain interface in the iCRM Basic ('''com_icrmbasic''') component 1.4.2.31 for Joomla! does not require administrative authentication, which has unspecified impact and remote attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 09/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3481|CVE-2009-3481]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_mytube'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the MyRemote Video Gallery ('''com_mytube''') component 1.0 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter in a videos action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3446|CVE-2009-3446]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|   '''com_facebook'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the JoomlaFacebook ('''com_facebook''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a student action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3438|CVE-2009-3438]]&lt;br /&gt;
|   [http://extensions.joomla.org/extensions/4446/details JED entry.] [http://forge.joomla.org/gf/project/joomla-facebook/ Download site] Developer states reports not proven 24/07/10&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_tupinambis'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Tupinambis ('''com_tupinambis''') component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the proyecto parameter in a verproyecto action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3434|CVE-2009-3434]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_hbssearch'''&lt;br /&gt;
|  Summary: Cross-site scripting ('''XSS''') vulnerability in the Hotel Booking Reservation System ('''aka HBS or com_hbssearch''') component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the adult parameter in a showhoteldetails action to index.php.&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 4.3 ('''MEDIUM''')&lt;br /&gt;
|  [[NIST:CVE-2009-3368|CVE-2009-3368]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_hbssearch'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System ('''aka HBS or com_hbssearch''') component for Joomla! allow remote attackers to execute arbitrary SQL commands via the ('''1''') h_id, ('''2''') id, and ('''3''') rid parameters to longDesc.php, and the h_id parameter to ('''4''') detail.php, ('''5''') detail1.php, ('''6''') detail2.php, ('''7''') detail3.php, ('''8''') detail4.php, ('''9''') detail5.php, ('''10''') detail6.php, ('''11''') detail7.php, and ('''12''') detail8.php, different vectors than [[NIST:CVE-2008-5865|CVE-2008-5865]], [[NIST:CVE-2008-5874|CVE-2008-5874]], and [[NIST:CVE-2008-5875|CVE-2008-5875]].&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3357|CVE-2009-3357]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''TurtuShout'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the TurtuShout component 0.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Name field.&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3335|CVE-2009-3335]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jinc'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Lhacky! Extensions Cave Joomla! Integrated Newsletters Component ('''aka JINC or com_jinc''') component 0.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a messages action to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3334|CVE-2009-3334]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_surveymanager'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Focusplus Developments Survey Manager ('''com_surveymanager''') component 1.5.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the stype parameter in an editsurvey action to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3325|CVE-2009-3325]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_album'''&lt;br /&gt;
|  Summary: Directory traversal vulnerability in the Roland Breedveld Album ('''com_album''') component 1.14 for Joomla! allows remote attackers to access arbitrary directories and have unspecified other impact via a .. ('''dot dot''') in the target parameter to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3318|CVE-2009-3318]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''IXXO Cart Standalone'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in IXXO Cart Standalone before 3.9.6.1, and the IXXO Cart component for Joomla! 1.0.x, allows remote attackers to execute arbitrary SQL commands via the parent parameter.&lt;br /&gt;
Published: 09/16/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3215|CVE-2009-3215]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_digifolio'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the DigiFolio ('''com_digifolio''') component 1.52 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a project action to index.php.&lt;br /&gt;
Published: 09/15/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3193|CVE-2009-3193]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_aclassf'''&lt;br /&gt;
|  Summary: Cross-site scripting ('''XSS''') vulnerability in '''gmap.php''' in the Almond Classifieds ('''com_aclassf''') component 7.5 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the addr parameter.&lt;br /&gt;
Published: 09/10/2009&lt;br /&gt;
CVSS Severity: 4.3 ('''MEDIUM''')&lt;br /&gt;
|  [[NIST:CVE-2009-3155|CVE-2009-3155]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;   | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jabode'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in Jabode horoscope extension ('''com_jabode''') for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a sign task to index.php.&lt;br /&gt;
Published: 09/08/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
&lt;br /&gt;
|  [[NIST:CVE-2008-7169|CVE-2008-7169]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_gameserver'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Game Server ('''com_gameserver''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a gamepanel action to index.php.&lt;br /&gt;
Published: 09/03/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3063|CVE-2009-3063]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_artportal'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Artetics.com Art Portal ('''com_artportal''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the portalid parameter to index.php.&lt;br /&gt;
Published: 09/03/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3054|CVE-2009-3054]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_simpleshop'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Simple Shop Galore ('''com_simpleshop''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the section parameter in a section action to index.php, a different vulnerability than [[NIST:CVE-2008-2568|CVE-2008-2568]]. NOTE: this issue was disclosed by an unreliable researcher, so the details might be incorrect.&lt;br /&gt;
Published: 08/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-7033|CVE-2008-7033]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_groups'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Permis ('''com_groups''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a list action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 08/17/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-2789|CVE-2009-2789]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Live Chat ('''com_livechat''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the last parameter to getChatRoom.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6883|CVE-2008-6883]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: Live Chat ('''com_livechat''') component 1.0 for Joomla! allows remote attackers to use the xmlhttp.php script as an open HTTP proxy to hide network scanning activities or scan internal networks via a GET request with a full URL in the query string.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6882|CVE-2008-6882]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the Live Chat ('''com_livechat''') component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the last parameter to ('''1''') getChat.php, ('''2''') getChatRoom.php, and ('''3''') getSavedChatRooms.php.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6881|CVE-2008-6881]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jshop'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the JShop ('''com_jshop''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a product action to index.php.&lt;br /&gt;
Published: 11/02/2009&lt;br /&gt;
CVSS Severity: 7.5 '''(HIGH)''' &lt;br /&gt;
|  [[NIST:CVE-2009-3835|CVE-2009-3835]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;| '''EasyBook 2.0.0rc4'''&lt;br /&gt;
|  Summary: The Joomla component '''EasyBook 2.0.0rc4''' suffers from multiple persistent XSS vulnerabilities. One seems fairly critical, while the others would take some incredible creativity to actively exploit. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/easybook-200rc4-multiple-xss-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:#cef2e0; color:black&amp;quot;| '''  &lt;br /&gt;
[http://www.kubik-rubik.de/joomla-hilfe/komponente-easybook-reloaded-joomla easybook reloaded released]&lt;br /&gt;
'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''F!BB 1.5.96''' &lt;br /&gt;
|  Summary: The Joomla component '''F!BB 1.5.96 RC''' suffers from multiple persistent XSS vulnerabilities, as well SQL Injection in its user search feature. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/fbb-1596-rc-multiple-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Testimonial Ku 2.0 Admin Panel'''&lt;br /&gt;
|  Summary: The Joomla component '''Testimonial Ku 2.0''' is vulnerable to persistent XSS in the administrator panel. A malicious user can submit a testimonial containing &amp;lt;script&amp;gt; tags with absolutely no quotes and inject that script into the administrator panel through any of the available inputs except &amp;quot;email&amp;quot;. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/testimonial-ku-20-admin-panel-persistent-xss.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''MS Comment 0.8.0b'''&lt;br /&gt;
|  Summary '''MS Comment 0.8.0b for Joomla''', a commenting plugin, suffers from an multiple vulnerabilities. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/ms-comment-080b-multiple-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''WebAmoeba Ticket System 3.0.0'''&lt;br /&gt;
|  Summary:  '''WebAmoeba Ticket System 3.0.0''', a Joomla help desk component. The vulnerability is with the BBCode library used to parse BBCode tags, as it does not strip javascript: urls from [url] tags. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/webamoeba-ticket-system-300-bbcode-xss.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_siirler'''&lt;br /&gt;
|  Summary:  SQL injection vulnerability in the '''Q-Proje Siirler Bileseni (com_siirler)''' component 1.2 RC for Joomla! allows remote attackers to execute arbitrary SQL commands via the sid parameter in an sdetay action to index.php. Added 18 November 2009&lt;br /&gt;
|  [[NIST:CVE-2009-3972 | CVE-2009-3972]]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''jTips (com_jtips)'''&lt;br /&gt;
|SUmmary:SQL injection vulnerability in the '''jTips (com_jtips)''' component 1.0.7 and 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the season parameter in a ladder action to index.php. Added 18 November 2009&lt;br /&gt;
| [[NIST:CVE-2009-3971 |CVE-2009-3971]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''JoomClip'''&lt;br /&gt;
|Summary: The '''JoomClip component for Joomla!''' is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements to the index.php script using the cat parameter, which could allow the attacker to view, add, modify or delete information in the back-end database.  Nov 18, 2009&lt;br /&gt;
|[http://secunia.com/advisories/37400/ secunia.com 37400/]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Mygallery Remote SQL Injection Vulnerability''' &lt;br /&gt;
|Summary: Joomla Component mygallery ( farbinform_krell) Remote SQL Injection Vulnerability Added 27 Nov 2009 {{JVer|1.5}} NB: This could be an error in our database as the only one we could find was for wordpress.If anyone know of one for joomla please let us know..(poss joomlicious.com CM)&lt;br /&gt;
|[http://www.exploit-db.com] &lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Extreme Google Calendar'''&lt;br /&gt;
|Summary: '''com_gcalendar 1.1.2''' (gcid) Remote SQL Injection Vulnerability&lt;br /&gt;
Remote SQL Injection were identified in Google Calendar Component [http://extensions.joomla.org/extensions/calendars-a-events/calendars/4188 Extension Link] Added 27 Nov 2009 &lt;br /&gt;
|[http://www.exploit-db.com reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''LyftenBloggie'''&lt;br /&gt;
| Summary: [http://www.lyften.com/products/lyftenbloggie.html LyftenBloggie] Component &amp;quot;author&amp;quot; SQL Injection Vulnerability LyftenBloggie 1.x Added 27 Nov 2009&lt;br /&gt;
|[http://secunia.com/advisories/product/28005/	 SA37499]&lt;br /&gt;
| [http://jeffchannell.com/Joomla/lyften-bloggie-sql-injection-fix.html Un official fix]. Developer fix not release at 30 Nov 09 ''' [http://www.lyften.com/products/lyftenbloggie/extensions/download/id-20.html 1.0.4a (last update on Dec 28, 2009)]'''&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== November 2009 Compiled Vulnerability Reports. ==&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
Items are not in any particular order.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  '''Extension'''&lt;br /&gt;
! class=&amp;quot;unsortable&amp;quot;| '''Details'''&lt;br /&gt;
!  '''Reference Link'''&lt;br /&gt;
!  '''Extension Update Link'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_djcatalog'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the DJ-Catalog ('''com_djcatalog''') component for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a showItem action and (2) cid parameter in a show action to index.php.&lt;br /&gt;
Published: 10/11/2009&lt;br /&gt;
CVSS Severity: 6.8 (MEDIUM)&lt;br /&gt;
|  [[NIST:CVE-2009-3661|CVE-2009-3661]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  |  '''com_soundset'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Soundset ('''com_soundset''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter to index.php.&lt;br /&gt;
Published: 10/09/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3644|CVE-2009-3644]]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  |  '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  |'''com_sportfusion'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Kinfusion SportFusion ('''com_sportfusion''') component 0.2.2 through 0.2.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid[0] parameter in a teamdetail action to index.php.&lt;br /&gt;
Published: 09/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3491|CVE-2009-3491]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  |'''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_icrmbasic'''&lt;br /&gt;
|  Summary: A certain interface in the iCRM Basic ('''com_icrmbasic''') component 1.4.2.31 for Joomla! does not require administrative authentication, which has unspecified impact and remote attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 09/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3481|CVE-2009-3481]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_mytube'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the MyRemote Video Gallery ('''com_mytube''') component 1.0 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter in a videos action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3446|CVE-2009-3446]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|   '''com_facebook'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the JoomlaFacebook ('''com_facebook''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a student action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3438|CVE-2009-3438]]&lt;br /&gt;
|   [http://extensions.joomla.org/extensions/4446/details JED entry.] [http://forge.joomla.org/gf/project/joomla-facebook/ Download site] Developer states reports not proven 24/07/10&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_tupinambis'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Tupinambis ('''com_tupinambis''') component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the proyecto parameter in a verproyecto action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3434|CVE-2009-3434]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_hbssearch'''&lt;br /&gt;
|  Summary: Cross-site scripting ('''XSS''') vulnerability in the Hotel Booking Reservation System ('''aka HBS or com_hbssearch''') component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the adult parameter in a showhoteldetails action to index.php.&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 4.3 ('''MEDIUM''')&lt;br /&gt;
|  [[NIST:CVE-2009-3368|CVE-2009-3368]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_hbssearch'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System ('''aka HBS or com_hbssearch''') component for Joomla! allow remote attackers to execute arbitrary SQL commands via the ('''1''') h_id, ('''2''') id, and ('''3''') rid parameters to longDesc.php, and the h_id parameter to ('''4''') detail.php, ('''5''') detail1.php, ('''6''') detail2.php, ('''7''') detail3.php, ('''8''') detail4.php, ('''9''') detail5.php, ('''10''') detail6.php, ('''11''') detail7.php, and ('''12''') detail8.php, different vectors than [[NIST:CVE-2008-5865|CVE-2008-5865]], [[NIST:CVE-2008-5874|CVE-2008-5874]], and [[NIST:CVE-2008-5875|CVE-2008-5875]].&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3357|CVE-2009-3357]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''TurtuShout'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the TurtuShout component 0.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Name field.&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3335|CVE-2009-3335]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jinc'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Lhacky! Extensions Cave Joomla! Integrated Newsletters Component ('''aka JINC or com_jinc''') component 0.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a messages action to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3334|CVE-2009-3334]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_surveymanager'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Focusplus Developments Survey Manager ('''com_surveymanager''') component 1.5.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the stype parameter in an editsurvey action to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3325|CVE-2009-3325]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_album'''&lt;br /&gt;
|  Summary: Directory traversal vulnerability in the Roland Breedveld Album ('''com_album''') component 1.14 for Joomla! allows remote attackers to access arbitrary directories and have unspecified other impact via a .. ('''dot dot''') in the target parameter to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3318|CVE-2009-3318]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''IXXO Cart Standalone'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in IXXO Cart Standalone before 3.9.6.1, and the IXXO Cart component for Joomla! 1.0.x, allows remote attackers to execute arbitrary SQL commands via the parent parameter.&lt;br /&gt;
Published: 09/16/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3215|CVE-2009-3215]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_digifolio'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the DigiFolio ('''com_digifolio''') component 1.52 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a project action to index.php.&lt;br /&gt;
Published: 09/15/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3193|CVE-2009-3193]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_aclassf'''&lt;br /&gt;
|  Summary: Cross-site scripting ('''XSS''') vulnerability in '''gmap.php''' in the Almond Classifieds ('''com_aclassf''') component 7.5 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the addr parameter.&lt;br /&gt;
Published: 09/10/2009&lt;br /&gt;
CVSS Severity: 4.3 ('''MEDIUM''')&lt;br /&gt;
|  [[NIST:CVE-2009-3155|CVE-2009-3155]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;   | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jabode'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in Jabode horoscope extension ('''com_jabode''') for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a sign task to index.php.&lt;br /&gt;
Published: 09/08/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
&lt;br /&gt;
|  [[NIST:CVE-2008-7169|CVE-2008-7169]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_gameserver'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Game Server ('''com_gameserver''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a gamepanel action to index.php.&lt;br /&gt;
Published: 09/03/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3063|CVE-2009-3063]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_artportal'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Artetics.com Art Portal ('''com_artportal''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the portalid parameter to index.php.&lt;br /&gt;
Published: 09/03/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3054|CVE-2009-3054]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_simpleshop'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Simple Shop Galore ('''com_simpleshop''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the section parameter in a section action to index.php, a different vulnerability than [[NIST:CVE-2008-2568|CVE-2008-2568]]. NOTE: this issue was disclosed by an unreliable researcher, so the details might be incorrect.&lt;br /&gt;
Published: 08/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-7033|CVE-2008-7033]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_groups'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Permis ('''com_groups''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a list action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 08/17/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-2789|CVE-2009-2789]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Live Chat ('''com_livechat''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the last parameter to getChatRoom.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6883|CVE-2008-6883]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: Live Chat ('''com_livechat''') component 1.0 for Joomla! allows remote attackers to use the xmlhttp.php script as an open HTTP proxy to hide network scanning activities or scan internal networks via a GET request with a full URL in the query string.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6882|CVE-2008-6882]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the Live Chat ('''com_livechat''') component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the last parameter to ('''1''') getChat.php, ('''2''') getChatRoom.php, and ('''3''') getSavedChatRooms.php.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6881|CVE-2008-6881]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jshop'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the JShop ('''com_jshop''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a product action to index.php.&lt;br /&gt;
Published: 11/02/2009&lt;br /&gt;
CVSS Severity: 7.5 '''(HIGH)''' &lt;br /&gt;
|  [[NIST:CVE-2009-3835|CVE-2009-3835]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;| '''EasyBook 2.0.0rc4'''&lt;br /&gt;
|  Summary: The Joomla component '''EasyBook 2.0.0rc4''' suffers from multiple persistent XSS vulnerabilities. One seems fairly critical, while the others would take some incredible creativity to actively exploit. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/easybook-200rc4-multiple-xss-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:#cef2e0; color:black&amp;quot;| '''  &lt;br /&gt;
[http://www.kubik-rubik.de/joomla-hilfe/komponente-easybook-reloaded-joomla easybook reloaded released]&lt;br /&gt;
'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''F!BB 1.5.96''' &lt;br /&gt;
|  Summary: The Joomla component '''F!BB 1.5.96 RC''' suffers from multiple persistent XSS vulnerabilities, as well SQL Injection in its user search feature. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/fbb-1596-rc-multiple-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Testimonial Ku 2.0 Admin Panel'''&lt;br /&gt;
|  Summary: The Joomla component '''Testimonial Ku 2.0''' is vulnerable to persistent XSS in the administrator panel. A malicious user can submit a testimonial containing &amp;lt;script&amp;gt; tags with absolutely no quotes and inject that script into the administrator panel through any of the available inputs except &amp;quot;email&amp;quot;. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/testimonial-ku-20-admin-panel-persistent-xss.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''MS Comment 0.8.0b'''&lt;br /&gt;
|  Summary '''MS Comment 0.8.0b for Joomla''', a commenting plugin, suffers from an multiple vulnerabilities. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/ms-comment-080b-multiple-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''WebAmoeba Ticket System 3.0.0'''&lt;br /&gt;
|  Summary:  '''WebAmoeba Ticket System 3.0.0''', a Joomla help desk component. The vulnerability is with the BBCode library used to parse BBCode tags, as it does not strip javascript: urls from [url] tags. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/webamoeba-ticket-system-300-bbcode-xss.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_siirler'''&lt;br /&gt;
|  Summary:  SQL injection vulnerability in the '''Q-Proje Siirler Bileseni (com_siirler)''' component 1.2 RC for Joomla! allows remote attackers to execute arbitrary SQL commands via the sid parameter in an sdetay action to index.php. Added 18 November 2009&lt;br /&gt;
|  [[NIST:CVE-2009-3972 | CVE-2009-3972]]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''jTips (com_jtips)'''&lt;br /&gt;
|SUmmary:SQL injection vulnerability in the '''jTips (com_jtips)''' component 1.0.7 and 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the season parameter in a ladder action to index.php. Added 18 November 2009&lt;br /&gt;
| [[NIST:CVE-2009-3971 |CVE-2009-3971]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''JoomClip'''&lt;br /&gt;
|Summary: The '''JoomClip component for Joomla!''' is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements to the index.php script using the cat parameter, which could allow the attacker to view, add, modify or delete information in the back-end database.  Nov 18, 2009&lt;br /&gt;
|[http://secunia.com/advisories/37400/ secunia.com 37400/]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Mygallery Remote SQL Injection Vulnerability''' &lt;br /&gt;
|Summary: Joomla Component mygallery ( farbinform_krell) Remote SQL Injection Vulnerability Added 27 Nov 2009 {{JVer|1.5}} NB: This could be an error in our database as the only one we could find was for wordpress.If anyone know of one for joomla please let us know..(poss joomlicious.com CM)&lt;br /&gt;
|[http://www.exploit-db.com] &lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Extreme Google Calendar'''&lt;br /&gt;
|Summary: '''com_gcalendar 1.1.2''' (gcid) Remote SQL Injection Vulnerability&lt;br /&gt;
Remote SQL Injection were identified in Google Calendar Component [http://extensions.joomla.org/extensions/calendars-a-events/calendars/4188 Extension Link] Added 27 Nov 2009 &lt;br /&gt;
|[http://www.exploit-db.com reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''LyftenBloggie'''&lt;br /&gt;
| Summary: [http://www.lyften.com/products/lyftenbloggie.html LyftenBloggie] Component &amp;quot;author&amp;quot; SQL Injection Vulnerability LyftenBloggie 1.x Added 27 Nov 2009&lt;br /&gt;
|[http://secunia.com/advisories/product/28005/	 SA37499]&lt;br /&gt;
| [http://jeffchannell.com/Joomla/lyften-bloggie-sql-injection-fix.html Un official fix]. Developer fix not release at 30 Nov 09 ''' [http://www.lyften.com/products/lyftenbloggie/extensions/download/id-20.html 1.0.4a (last update on Dec 28, 2009)]'''&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== December 2009 Compiled Reports ==&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  '''Extension'''&lt;br /&gt;
! class=&amp;quot;unsortable&amp;quot;| '''Details'''&lt;br /&gt;
!  '''Reference Link'''&lt;br /&gt;
!  '''Extension Update Link'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Omilen Photo Gallery'''&lt;br /&gt;
|Summary: Directory traversal vulnerability in the [http://extensions.joomla.org/extensions/photos-&amp;amp;-images/photo-flash-gallery/6373/details Omilen Photo Gallery] (com_omphotogallery) component Beta 0.5 for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the controller parameter to index.php.&lt;br /&gt;
Published: 12/04/2009&lt;br /&gt;
|[[NIST:CVE-2009-4202 | CVE-2009-4202]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   | '''Seminar'''&lt;br /&gt;
|Summary: SQL injection vulnerability in the [http://seminar.vollmar.ws/ Seminar] (com_seminar) component 1.28 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a View_seminar action to index.php.&lt;br /&gt;
Published: 12/04/2009&lt;br /&gt;
|[[NIST:CVE-2009-4200 | CVE-2009-4200]]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   | '''  released V1.29, released'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''ProofReader''' &lt;br /&gt;
|Summary: Multiple cross-site scripting (XSS) vulnerabilities in index.php in the ProofReader (com_proofreader) component 1.0 RC9 and earlier for Joomla! allow remote attackers to inject arbitrary web script or HTML via the URI, which is not properly handled in (1) 404 or (2) error pages. Published: 12/02/2009 CVSS Severity: 4.3 (MEDIUM)&lt;br /&gt;
| [[NIST:CVE-2009-4157 | CVE-2009-4157]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''D4J eZine'''&lt;br /&gt;
|Summary: PHP remote file inclusion vulnerability in class/php/d4m_ajax_pagenav.php in the D4J eZine (com_ezine) component 2.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS mosConfig_absolute_path parameter. Published: 11/29/2009 CVSS Severity: 7.5 (HIGH)&lt;br /&gt;
|[[NIST:CVE-2009-4094 | CVE-2009-4094]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''Quick News'''&lt;br /&gt;
| Summary: The Joomla [http://joomlacode.org/gf/project/quicknews/ Quick News component] suffers from a remote SQL injection vulnerability. added 1st Dec 09&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''mojoblog'''&lt;br /&gt;
|Summary [http://www.joomlify.com/files/mojoblog/ MojoBlog] Multiple Remote File Include Vulnerability added 1st Dec 09 {{JVer|1.5}}&lt;br /&gt;
|[http://securityreason.com/exploitalert/7509 7509]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''TP Whois''' &lt;br /&gt;
|summary: [http://www.templateplazza.com/view-details/tpwhois/183-component-tp-whois-for-joomla-1.5.x.html TP Whois ] Malicious users may inject JavaScript, VBScript, ActiveX, HTML or Flash into a vulnerable application to fool a user in order to gather data from them. An attacker can steal the session cookie and take over the account. Added 3 december {{JVer|1.5}}&lt;br /&gt;
|[http://www.exploit-db.com Refrence]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''com_job'''&lt;br /&gt;
|Summary: Component com_job ( showMoreUse) SQL injection vulnerability  Added 9th Dec&lt;br /&gt;
|[http://xforce.iss.net/xforce/xfdb/54626 Reference]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''Mamboleto Component 2.0 RC3'''&lt;br /&gt;
|Summary: [http://www.fernandosoares.com.br/index.php?option=com_docman&amp;amp;task=cat_view&amp;amp;gid=28&amp;amp;Itemid=28 Mamboleto Component 2.0 RC3]SQL injection vulnerability {{JVer|1.5}} added 12 December&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | ''' Kide Shoutbox'''&lt;br /&gt;
|Summary: The Kide Shoutbox (com_kide) component 0.4.6 for Joomla! does not properly perform authentication, which allows remote attackers to post messages with an arbitrary account name via an insertar action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Added: December 08&lt;br /&gt;
|[[NIST:CVE-2009-4232 | CVE-2009-4232]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | ''' JoomPortfolio Component'''&lt;br /&gt;
|Summary: [http://www.joomplace.com/joomportfolio/joomportfolio.html JoomPortfolio] Input passed via the &amp;quot;secid&amp;quot; parameter to index.php (when &amp;quot;option&amp;quot; is set to &amp;quot;com_joomportfolio&amp;quot; and &amp;quot;task&amp;quot; is set to &amp;quot;showcat&amp;quot;) is not properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.The vulnerability is reported in version 1.0.0. Other versions may also be affected. Added: December 18 {{JVer|1.5}}&lt;br /&gt;
|[http://secunia.com/advisories/37838/ Reporting Site]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''City Portal (templates?)'''&lt;br /&gt;
|Summary:   City Portal Blind SQL Injection Vulnerability added: 2009-12-18&lt;br /&gt;
|[http://www.exploit-db.com Reference] Possibly this [http://www.youjoomla.com/jclick-city-portal-joomla-template.html tempate]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''Event Manager'''&lt;br /&gt;
|Summary:  [http://www.jforjoomla.com/Joomla-Components/event-manager-15-component.html Event Manager] Blind SQL Injection Vulnerability EDB-ID: 10549&lt;br /&gt;
added: 2009-12-18&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | com_zcalendar&lt;br /&gt;
|Summary:  com_zcalendar Blind SQL-injection Vulnerability&lt;br /&gt;
EDB-ID: 10548 added: 2009-12-18&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''com_acmisc'''&lt;br /&gt;
|Summary:  com_acmisc SQL injection added: 2009-12-18&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''com_jbook'''&lt;br /&gt;
|Summary:   com_jbook Blind SQL-injection EDB-ID: 10545 added: 2009-12-18 {{JVer|1.0}}&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |  '''com_personel'''&lt;br /&gt;
|Summary: com_personel component for Joomla! is vulnerable to SQL injection.&lt;br /&gt;
|[http://xforce.iss.net/xforce/xfdb/54903 iss.net reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |  '''HotBrackets Tournament Brackets '''&lt;br /&gt;
|Summary: The [http://extensions.joomla.org/extensions/sports-a-games/sports/10746 HotBrackets Tournament Brackets] component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. {{JVer|1.5}} added 22 dec &lt;br /&gt;
|[http://www.securityfocus.com/bid/37439/ Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''Car Manager'''&lt;br /&gt;
|Summary: http://webformatique.com/ com_carman Cross Site Scripting Vulnerability added 24 december 09{{JVer|1.5}}&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot; |'''Schools component'''&lt;br /&gt;
|Summary: The 'com_schools' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.&lt;br /&gt;
|[http://www.securityfocus.com/bid/37469 Reference] added 24 dec 09&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''webcamxp'''&lt;br /&gt;
|[http://extensions.joomla.org/extensions/communication/video-conference/4490 com_webcamxp] Cross Site Scripting Vulnerabilities  Last version 2008 {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''jm-recommend'''&lt;br /&gt;
|jm-recommendCross Site Scripting Vulnerabilities. unable to locate on jed. {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | facileforms&lt;br /&gt;
| com_facileforms Cross Site Scripting Vulnerabilities. unable to locate on jed. Product considered retired.  {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''adagency'''&lt;br /&gt;
| [http://www.ijoomla.com/ijoomla-ad-agency/ijoomla-ad-agency/index/ adagency ]Vulnerabilities {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |  '''com_intuit'''&lt;br /&gt;
|[http://www.san-diego-web-designer.com/new-file-download/item/root/aboutimage-igateway-for-joomla.html com_intuit]Local File Inclusion Vulnerability {{JVer|1.5}} Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | '''  [http://www.securityfocus.com/bid/37494/discuss Retired]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''MemoryBook'''&lt;br /&gt;
|[http://extensions.joomla.org/extensions/calendars-a-events/birthdays-a-historic-events/10868 MemoryBook 1.2]  Multiple Vulnerabilities. requires: magic quotes OFF, user account {{JVer|1.5}} Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''qpersonel'''&lt;br /&gt;
|[http://extensions.joomla.org/extensions/directory-a-documentation/thematic-directory/7049 qpersonel ] Cross Site Scripting Vulnerabilities {{JVer|1.0}}[[Image:http://extensions.joomla.org/images/jed/compat_15_legacy.png]] Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''opryknings point''' &lt;br /&gt;
|com_oprykningspoint_mc Cross Site Scripting Vulnerabilities {{JVer|1.5}} Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''trabalhe conosco'''&lt;br /&gt;
|com_trabalhe_conosco Cross Site Scripting Vulnerabilities {{JVer|1.5}} Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''DhForum'''&lt;br /&gt;
|com_dhforum SQL Injection Vulnerability. considered retired/EOL Dec. 27 {{JVer|1.0}}1.5 legacy&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== January 2010 Reported Vulnerable Extensions ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Please check with the extension publisher in case of any questions over the security of their product.'''&lt;br /&gt;
Report Vulnerable extensions either in the [[jforum:432]] security topic or the [http://forum.joomla.org/viewforum.php?f=470 extensions] topic clearly marked with the first word in the title being ''Vulnerable'' where the security moderators or JSST team will respond. &lt;br /&gt;
''This list is change protected, for updates or editing requests [http://forum.joomla.org/memberlist.php?mode=viewprofile&amp;amp;u=28000 Mandville] or [http://forum.joomla.org/memberlist.php?mode=viewprofile&amp;amp;u=87230 lafrance]&lt;br /&gt;
''&lt;br /&gt;
&lt;br /&gt;
[http://docs.joomla.org/Vulnerable_Extensions_List Back To Top]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  '''Extension'''&lt;br /&gt;
! class=&amp;quot;unsortable&amp;quot;| '''Details'''&lt;br /&gt;
!  '''Reference Link'''&lt;br /&gt;
!  '''Extension Update Link'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   |JvideoDirect&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/multimedia/video-players-a-gallery/9501 Jvideodirect] SQLi Jan 29&lt;br /&gt;
|&lt;br /&gt;
|[http://www.jvideodirect.com/ Update version 2.5]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   |'''JEvent search plugin'''&lt;br /&gt;
|Summary: JEvent search plugin for [http://extensions.joomla.org/extensions/calendars-a-events/events/95 JEvent] SQLi reported Jan 29&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | '''  [http://www.jevents.net/forum/viewtopic.php?f=17&amp;amp;t=3910#p15526 upgrade to 1.5.3b]'''&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   |'''Kunena'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/communication/forum/7256/details kunena] re reported suffering SQLi in version 1.5.9 Jan 29 Confirmation Required '''Now found to be malicious'''&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; | '''  [http://www.kunena.com/blog/19-developer-blog/51-kunena-157-security-release-now-available Versions 1.5.5 and below only]'''&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |'''JE Quiz'''&lt;br /&gt;
|Summary : http://extensions.joomla.org/extensions/contacts-and-feedback/quiz-a-surveys/11212 JeQuiz SQLi reported 29 Jan&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;&amp;quot;   |'''idoblog'''&lt;br /&gt;
|summary: exploitable due to open file permissions. 28 Jan&lt;br /&gt;
|Private Notification&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; | '''  [http://idojoomla.com/news.html build 35 released] '''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;    |'''ccnewsletter'''&lt;br /&gt;
|Summary [http://extensions.joomla.org/extensions/5112/details ccnewsletter Directory Traversal Vulnerability] Jan 28 &lt;br /&gt;
|Private Notification&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | ''' [http://www.chillcreations.com/en/blog/ccnewsletter-joomla-newsletter/ccnewsletter-106-security-release.html version 1.0.6 released 29 Jan]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;   |'''Virtuemart 1.1.4'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/e-commerce/shopping-cart/129 virtuemart] Input var order_status_id is vulnerable to SQLi NB Requires Higher Level access before exploiting. Jan 27&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; | '''  [http://forum.joomla.org/viewtopic.php?p=2027005#p2027005 developer patches]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   |'''JBDiary'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/calendars-a-events/events/11009 JBDiary] BLIND SQL Injection Vulnerabilities Jan 24 [http://www.jb-soft.nl/ http://www.jb-soft.nl/]&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;   | ''' [http://www.jb-soft.nl/index.php?option=com_content&amp;amp;view=article&amp;amp;id=64 Developer Update 27 Jan]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   |'''JbPublishDownFp'''&lt;br /&gt;
|Sumary: [http://extensions.joomla.org/extensions/news-production/timed-content/6496 JbPublishDownFp] SQL Injection Vulnerability Jan 24 [http://www.jb-soft.nl http://www.jb-soft.nl]&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |'''  [http://www.jb-soft.nl/index.php?option=com_content&amp;amp;view=article&amp;amp;id=64 Developer Update Jan 27]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''com_casino'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/sports-a-games/tips-a-betts com_casino]&lt;br /&gt;
SQL Injection Vulnerabilities Jan24&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   |'''Mochigames'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/search/mochigames com_Mochigames]&lt;br /&gt;
SQL Injection Vulnerabilities Jan24&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | ''' [http://www.yoflash.com/download.html mochigames_alpha052 Released]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |'''ContentBlogList'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/news-production/blog/10989 com_ContentBlogList] SQL Injection Vulnerability Jan 23&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |MailChimp for Joomla 1.5&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/bridges/mailing-a-newsletter-bridges/7836 MailChimp for Joomla 1.5]  jan 17&lt;br /&gt;
|Developer Statement&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |'''JoomlaXML'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/tools/design-tools/5020 JoomlaXML] malicious code insertion&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''JVClouds3D SWF module'''&lt;br /&gt;
|[http://joomlapro.ru/3djvclouds JVClouds3D SWF module] Cross Site Scripting . jan 14&lt;br /&gt;
|[http://xforce.iss.net/xforce/xfdb/55535 xforce]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''JVClouds3D'''&lt;br /&gt;
|[http://joomlapro.ru/3djvclouds JVClouds3D module] Cross Site Scripting . jan 14&lt;br /&gt;
|[http://xforce.iss.net/xforce/xfdb/55534 xforce]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |'''JA Showcase'''&lt;br /&gt;
|[http://www.joomlart.com/addons/components_and_modules/ja_showcase.html JA Showcase component] Directory Traversal jan 14&lt;br /&gt;
|[http://xforce.iss.net/xforce/xfdb/55512 xforce]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |'''jprojects'''&lt;br /&gt;
|Summary:   Unknown Author com_j-projects Blind SQL Injection Vulnerability. Jan 10 detail update&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |'''jEmbed-Embed Anything'''&lt;br /&gt;
|[http://www.joshprakash.com/index.php?option=com_docman&amp;amp;task=doc_details&amp;amp;gid=70 jEmbed-Embed Anything] A vulnerability has been discovered in the jEmbed-Embed Anything component for Joomla, which can be exploited by malicious people to conduct SQL injection attacks. Jan 10&lt;br /&gt;
|[http://secunia.com/advisories/38112 Secunia Advisory: SA38112] &lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | [http://extensions.joomla.org/extensions/3699/details Product considered retired]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;    |'''perchagallery '''&lt;br /&gt;
|Summary: perchagallery  [http://extensions.joomla.org/extensions/photos-a-images/photo-gallery/10350 com_perchagallery] SQL Injection Vulnerability  Jan 7&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | '''  [http://www.percha.com/index.php?option=com_phocadownload&amp;amp;view=file&amp;amp;id=22:1.5&amp;amp;Itemid=20 Developer Update 1.5b]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0;  color:black&amp;quot;   |  '''CARTwebERP'''&lt;br /&gt;
|Summary:  [http://extensions.joomla.org/extensions/bridges/e-commerce-bridges/8753 CARTwebERP] Local File Inclusion Vulnerability  Jan. 3&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | '''  [http://extensions.joomla.org/extensions/bridges/e-commerce-bridges/8753 1.56.76 (last update on Jan 11, 2010)]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |   '''JoomlaBibleStudy'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/miscellaneous/religion/3461 JoomlaBibleStudy] LFI Vulnerability  Jan. 3&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;   | '''[http://joomlabiblestudy.org/invisible-downloads/category/3-component.html Developer reported update]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |  '''com_bfsurvey_basic and pro'''&lt;br /&gt;
|Summary: [http://www.tamlyncreative.com.au/software/ BFsurvey] SQL Injection Vulnerability ,LFI Vulnerability   Jan. 3&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | '''  [http://www.tamlyncreative.com.au/software/forum/index.php?topic=641.0 Developer Update announcement]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''Alfresco'''&lt;br /&gt;
|Summary:  SQL Injection Vulnerability. Not believed to be Joomlatools extension Jan. 3&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''abbrev'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/directory-a-documentation/glossary-a-dictionary/4965 abbrev] Local File Inclusion Vulnerability Jan. 3&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''countries'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/miscellaneous/development/6553 countries] SQL Injection Vulnerability  Jan. 3&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   |  '''Dedicated Component com_tpjobs'''&lt;br /&gt;
|Summary: [http://www.templateplazza.com/ tpjobs] SQL Injection Vulnerability unable to locate files probably template plaza  Jan. 3&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;     | '''  [http://www.templateplazza.com/extensions-updates/tpjobs-component-update-v-1.1.html Developer Update] '''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''Component com_doqment'''&lt;br /&gt;
|SQL Injection Vulnerability Jan. 3&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''Component com_otzivi''' &lt;br /&gt;
|Blind SQL Injection Vulnerability  Jan. 3&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''aprice'''&lt;br /&gt;
|Summary: [http://adeptweb.info/component/option,com_aprice/Itemid,109/ com_aprice] Component 'analog' Parameter SQL Injection Vulnerability&lt;br /&gt;
|[http://www.securityfocus.com/bid/37575 Report]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |'''cartikads'''&lt;br /&gt;
|Summary: [http://www.cartikahosting.com com_cartikads] Remote File Upload Vulnerability &lt;br /&gt;
'''Mambo''' Open Source ads management component&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   | '''Docman seller''' &lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/e-commerce/subscriptions/5000 Document seller]  Input passed via the &amp;quot;id&amp;quot; parameter to index.php (when &amp;quot;option&amp;quot; is set to &amp;quot;com_dm_orders&amp;quot;, &amp;quot;task&amp;quot; is set to &amp;quot;order_form&amp;quot;, and &amp;quot;payment_method&amp;quot; is set to &amp;quot;Paypal&amp;quot;) is not properly sanitised before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.&lt;br /&gt;
|[http://secunia.com/advisories/38024/ secunia]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;   | [http://extensions.joomla.org/extensions/e-commerce/subscriptions/5000 Updated 10th Jan]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |  '''ozio gallery''' &lt;br /&gt;
|summary: [http://extensions.joomla.org/extensions/photos-a-images/photo-flash-gallery/4883 Ozio Gallery2] SQLi eploit &lt;br /&gt;
|[http://www.viruslist.com/en/advisories/37974 Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;   |[http://oziogallery.joomla.it/index.php?option=com_content&amp;amp;view=article&amp;amp;id=62%3Anuova-ozio-gallery-23-aggiornamento-di-sicurezza&amp;amp;catid=2%3Anotizie&amp;amp;Itemid=13&amp;amp;lang=en developer update Jan 11]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   | '''RD-Autos Free''' &lt;br /&gt;
|[http://extensions.joomla.org/extensions/vertical-markets/vehicles/5458 RD-Autos Free ] This version is now commercial not free&lt;br /&gt;
|Private advisory to JED Jan 11&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | ''' Product Retired and replaced'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''DailyMeals'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/vertical-markets/food-a-beverage/4764 dailymeals] Local File Inclusion  Vulnerability  Jan 02&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''RD-Autos Pro''' &lt;br /&gt;
|[http://extensions.joomla.org/extensions/vertical-markets/vehicles/6357 RD Autos Pro]&lt;br /&gt;
|Private advisory to JED Jan 11&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   | '''  Upgrade to  Latest version  be 2.0.2'''&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
[[Category:Security]]&lt;/div&gt;</summary>
		<author><name>CirTap</name></author>	</entry>

	<entry>
		<id>http://docs.joomla.org/Vulnerable_Extensions_List/Archive</id>
		<title>Vulnerable Extensions List/Archive</title>
		<link rel="alternate" type="text/html" href="http://docs.joomla.org/Vulnerable_Extensions_List/Archive"/>
				<updated>2011-07-15T11:19:25Z</updated>
		
		<summary type="html">&lt;p&gt;CirTap: Changed protection level for &amp;quot;Vulnerable Extensions List/Archive&amp;quot; ([edit=sysop] (indefinite) [move=sysop] (indefinite)) [cascading]&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Former Lists of vulnerable extensions.&lt;br /&gt;
&amp;lt;splist/&amp;gt;&lt;br /&gt;
[[Category:Security]]&lt;br /&gt;
[[Category:Security_FAQ]]&lt;/div&gt;</summary>
		<author><name>CirTap</name></author>	</entry>

	<entry>
		<id>http://docs.joomla.org/Vulnerable_Extensions_List/Archive</id>
		<title>Vulnerable Extensions List/Archive</title>
		<link rel="alternate" type="text/html" href="http://docs.joomla.org/Vulnerable_Extensions_List/Archive"/>
				<updated>2011-07-15T09:22:02Z</updated>
		
		<summary type="html">&lt;p&gt;CirTap: Protected &amp;quot;Vulnerable Extensions List/Archive&amp;quot; ([edit=sysop] (indefinite) [move=sysop] (indefinite))&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Former Lists of vulnerable extensions.&lt;br /&gt;
&amp;lt;splist/&amp;gt;&lt;br /&gt;
[[Category:Security]]&lt;br /&gt;
[[Category:Security_FAQ]]&lt;/div&gt;</summary>
		<author><name>CirTap</name></author>	</entry>

	<entry>
		<id>http://docs.joomla.org/Talk:Vulnerable_Extensions_List</id>
		<title>Talk:Vulnerable Extensions List</title>
		<link rel="alternate" type="text/html" href="http://docs.joomla.org/Talk:Vulnerable_Extensions_List"/>
				<updated>2011-07-15T09:20:42Z</updated>
		
		<summary type="html">&lt;p&gt;CirTap: moved Talk:Vulnerable Extensions List/Archive/2010-11 to Talk:Vulnerable Extensions List: back to where it belongs&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''ToDo'''&lt;br /&gt;
# Some links left to cleanup. &lt;br /&gt;
# Should this format be converted to a wiki template for easier editing?&lt;br /&gt;
# Should each item be it's own file?&lt;br /&gt;
# Links to old forum topics are broken. Is there a pattern we can use to map these to the new forum path/topics?&lt;br /&gt;
&lt;br /&gt;
== Are Vulnerabilities confirmed? ==&lt;br /&gt;
&lt;br /&gt;
I ask because, I cannot find any confirmation that a couple of these vulnerabilities are valid.&lt;br /&gt;
&lt;br /&gt;
Obviously, many of theses are correct, but it seems like some of this is just parroting, without installing the extension, and running a test.&lt;br /&gt;
&lt;br /&gt;
Should the unconfirmed vulnerabilities be flagged as such?&lt;/div&gt;</summary>
		<author><name>CirTap</name></author>	</entry>

	<entry>
		<id>http://docs.joomla.org/Vulnerable_Extensions_List</id>
		<title>Vulnerable Extensions List</title>
		<link rel="alternate" type="text/html" href="http://docs.joomla.org/Vulnerable_Extensions_List"/>
				<updated>2011-07-15T09:10:48Z</updated>
		
		<summary type="html">&lt;p&gt;CirTap: Archive subpages&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{RightTOC}}&lt;br /&gt;
'''Please check here also:'''&lt;br /&gt;
&amp;lt;splist/&amp;gt;&lt;br /&gt;
Please also check the [[Investigation of exploits|Extension Investigation List]].&lt;br /&gt;
&lt;br /&gt;
== Check and Report.  ==&lt;br /&gt;
'''Please check with the extension publisher in case of any questions over the security of their product.'''&lt;br /&gt;
Report Vulnerable extensions in the [[jforum:432|security forum]]  clearly marked with the first word in the title being ''Vulnerable'' where the security moderators or JSST team will respond. &lt;br /&gt;
This list is change protected,''' for additions or updates email''' ''vel @ joomla.org'' [http://forum.joomla.org/memberlist.php?mode=viewprofile&amp;amp;u=28000 Mandville] or [http://forum.joomla.org/memberlist.php?mode=viewprofile&amp;amp;u=87230 lafrance] are the main editors&lt;br /&gt;
*If you are seeing this page on any site other than [http://docs.joomla.org/Vulnerable_Extensions_List the Offical Joomla Documentation] you may be seeing an out of date version or experiencing [http://en.wikipedia.org/wiki/Plagiarism plagiary] and the links may not work properly&lt;br /&gt;
&lt;br /&gt;
== How to use this list ==&lt;br /&gt;
'''Items will be removed after a suitable period and not on resolution'''&lt;br /&gt;
All known vulnerable extensions are the listed in the first column. Any in &amp;lt;span style=&amp;quot;background:red; color:white&amp;quot;&amp;gt;a red box &amp;lt;/span&amp;gt;are where we have not been given a fix for. Alert Advisory details in the centre column . &lt;br /&gt;
Finally a link to the notice about any &amp;lt;span style=&amp;quot;background:#cef2e0; color:black&amp;quot;&amp;gt;update with link&amp;lt;/span&amp;gt; or &amp;lt;span style=&amp;quot;background:red; color:white&amp;quot;&amp;gt;'''Not Known''' &amp;lt;/span&amp;gt; where none is known.&lt;br /&gt;
&lt;br /&gt;
'''This list is compiled from found information and may not be an up to date accurate list''' ''We do '''NOT''' promise to test or validate these reports. We do '''NOT''' guarantee the quality or effectiveness of any updates reported to us or listed here.''&lt;br /&gt;
To sign up for the feed please [http://feeds.joomla.org/JoomlaSecurityVulnerableExtensions follow this link]&lt;br /&gt;
* We do not list BETA products, or extensions for J1.0.x&lt;br /&gt;
&lt;br /&gt;
== Developers - How to get yourself removed from the VEL ==&lt;br /&gt;
&lt;br /&gt;
Resolved items will be removed after a suitable period and not on resolution&lt;br /&gt;
&lt;br /&gt;
Please solve the issues and:&lt;br /&gt;
&lt;br /&gt;
* '''If JED listed''' &lt;br /&gt;
&lt;br /&gt;
To have your extension republished, please follow these steps:&lt;br /&gt;
&lt;br /&gt;
1- Solve the issues.&lt;br /&gt;
&lt;br /&gt;
2- Attach the new zip file at your actual JED listing.&lt;br /&gt;
&lt;br /&gt;
3- Change the extension version at JED listing.&lt;br /&gt;
&lt;br /&gt;
4- Make sure to include a notice in the JED description to the fact that the new release is a &amp;quot;Security Release&amp;quot; and those who use the extension should upgrade immediately.&lt;br /&gt;
&lt;br /&gt;
5- Create a [http://bit.ly/velunlist JED listing owner ticket] to the JED with a notice and ask that your listing be republished. Include the full details of yournew version number and security notice page&lt;br /&gt;
&lt;br /&gt;
6- Email the VEL team with a notice of resolution, the latest version number '''and''' a link to the security release statement on your website&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
VEL email can be found above and the JED support link is in your notice of &amp;quot;unpublication&amp;quot; [http://extensions.joomla.org/component/maqmahelpdesk/ and here] &lt;br /&gt;
&lt;br /&gt;
* '''If not JED listed.''' &lt;br /&gt;
Inform us by '''email''' with a notice of resolution, the latest version number '''and''' a link to the security release statement on your website.&lt;br /&gt;
&lt;br /&gt;
== February 2010 and onwards Reported Vulnerable Extensions ==&lt;br /&gt;
&amp;lt;startFeed /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Please check with the extension publisher in case of any questions over the security of their product.'''&lt;br /&gt;
Report Vulnerable extensions either in the [[jforum:432]] security topic clearly marked with the first word in the title being ''Vulnerable Report'' where the security moderators or JSST team will respond or via email to the VEL team. For a guide to the [http://docs.joomla.org/Vulnerable_Extensions_List_0210#Codes_used codes]&lt;br /&gt;
*If you are seeing this page on any site other than [http://docs.joomla.org/Vulnerable_Extensions_List the Offical Joomla Documentation] you may be seeing an out of date version or experiencing [http://en.wikipedia.org/wiki/Plagiarism plagiary] and the links may not work properly&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  '''Extension'''&lt;br /&gt;
! class=&amp;quot;unsortable&amp;quot;| '''Details'''&lt;br /&gt;
!  '''Date Added'''&lt;br /&gt;
! class=&amp;quot;unsortable&amp;quot; |'''Extension Update Link &amp;amp; Date'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  Sobi   ==&lt;br /&gt;
|SQLI - &lt;br /&gt;
|130711&lt;br /&gt;
|[http://www.sigsiu.net/changelog developer fix and update statement]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  fabrik   ==&lt;br /&gt;
|sqli &lt;br /&gt;
|120711&lt;br /&gt;
|[http://fabrikar.com/downloads/details/36/89 Developers Update statement 2.1]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
==  xmap   ==&lt;br /&gt;
|sqli 1.2.11 &lt;br /&gt;
|120711&lt;br /&gt;
|upgrade to 1.2.12&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
== Atomic Gallery     ==&lt;br /&gt;
|Creates 777 folders [http://www.atomicon.nl/atomicongallery Atomic gallery] &lt;br /&gt;
|110711&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
==  myApi   ==&lt;br /&gt;
|ID [http://extensions.joomla.org/component/mtree/social-web/facebook-integration/11624 Contains &amp;quot;Call-Home&amp;quot; function. Sends private user information to developer.] &lt;br /&gt;
|020711&lt;br /&gt;
|[http://www.myapi.co.uk/ Developer states Use version 1.3.4.1]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  mdigg   ==&lt;br /&gt;
|SQL I (not listed in JED)&lt;br /&gt;
|020711&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  Calc Builder   ==&lt;br /&gt;
|sqli + ID&lt;br /&gt;
|180611&lt;br /&gt;
| [http://components.moonsoft.es/downloadcalcbuilder  dev security release 0.0.2]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
== Cool Debate    ==&lt;br /&gt;
|Cool Debate 1.03 LFI&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==     ==&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  Scriptegrator Plugin 1.5.5==&lt;br /&gt;
|LFI&lt;br /&gt;
|140611&lt;br /&gt;
| [http://www.greatjoomla.com/news/index.html  Update - Core Design Scriptegrator plugin 2.0.9 &amp;amp;] 1.5.6&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  Joomnik Gallery   ==&lt;br /&gt;
|SQLi&lt;br /&gt;
|&lt;br /&gt;
|[http://joomlacode.org/gf/project/joomnik/ developer update to 0.9.1]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  JMS fileseller   ==&lt;br /&gt;
|LFI &lt;br /&gt;
|0611&lt;br /&gt;
|[http://joommasters.com/commercial-extensions/components/jms-fileseller.html developer upgrade announcement to v1.1]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  sh404SEF   ==&lt;br /&gt;
|low-level XSS security issue&lt;br /&gt;
|300511&lt;br /&gt;
|[http://dev.anything-digital.com/Forum/Announcements/11147-sh404SEF-2.2.6-now-available-for-Joomla-1.5/ Dev upgrade statement to 2.2.6]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  JE Story submit    ==&lt;br /&gt;
|LFI/RFI &lt;br /&gt;
|&lt;br /&gt;
|[http://joomlaextensions.co.in/extensions/modules/je-content-menu.html?page=shop.product_details&amp;amp;flypage=flypage.tpl&amp;amp;product_id=77&amp;amp;category_id=13&amp;amp;vmcchk=1 developer states Version 1.8]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==   FCKeditor   ==&lt;br /&gt;
|File Upload Vulnerability&lt;br /&gt;
|230511&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
== KeyCaptcha    ==&lt;br /&gt;
|Private report under investigation&lt;br /&gt;
|190511&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  Ask A Question AddOn v1.1   ==&lt;br /&gt;
|SQLi&lt;br /&gt;
|160511&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Global Flash Gallery     ==&lt;br /&gt;
|flash-gallery.com xss &lt;br /&gt;
|130511&lt;br /&gt;
|[http://flash-gallery.com/help/joomla-extension/faq/security-update-0.5.0/ dev release 0.5.0 statement]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== com_google     ==&lt;br /&gt;
|LFI [http://freejoomlacomponent.appspot.com/ com_google]&lt;br /&gt;
|080511&lt;br /&gt;
|[http://freejoomlacomponent.appspot.com/securityrelease.html devs update to 1.5.1]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  docman   ==&lt;br /&gt;
|com-docman Input Validation Error &lt;br /&gt;
|160511&lt;br /&gt;
|[http://forum.joomla.org/viewtopic.php?p=2502904#p2502904 devs resolution statement, report for old version]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  Newsletter Subscriber    ==&lt;br /&gt;
|XSS &lt;br /&gt;
|120511&lt;br /&gt;
|[http://mavrosxristoforos.com/joomla-extensions/free/newsletter-subscriber Deveopler update]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  Akeeba   ==&lt;br /&gt;
|akkeba backup and joomlapack&lt;br /&gt;
|170411&lt;br /&gt;
|[https://www.akeebabackup.com/home/item/1091-akeeba-backup-3-2-7.html dev update to 3.2.7]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  Facebook Graph Connect   ==&lt;br /&gt;
|SID. call home device with user credentials&lt;br /&gt;
|120411&lt;br /&gt;
|[http://www.sikkimonline.info/security-notice dev update notice]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== booklibrary    ==&lt;br /&gt;
|SQLi ordasoft booklibrary&lt;br /&gt;
|180311&lt;br /&gt;
|[http://ordasoft.com/Book-Library/security-upgrade-instructions-for-book-library.html developer upgrade instructions]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
== semantic    ==&lt;br /&gt;
|com semantic http://www.scms.es/joomla creates hidden admin users &lt;br /&gt;
|150311&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
==  JOMSOCIAL 2.0.x 2.1.x   ==&lt;br /&gt;
|SID, open folders&lt;br /&gt;
|120311&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  flexicontent   ==&lt;br /&gt;
|forced 777, malicious files &lt;br /&gt;
|250311&lt;br /&gt;
|[http://www.flexicontent.org/home/item/192-flexicontent-154-is-finally-out.html devs resolve statement], [http://www.flexicontent.org/downloads/latest-version.html Changelog]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
== jLabs Google Analytics Counter     ==&lt;br /&gt;
|jLabs Google Analytics Counter  SID&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
==  xcloner   ==&lt;br /&gt;
|Unspecified&lt;br /&gt;
|260211&lt;br /&gt;
|[http://www.xcloner.com/xcloner-news/important-security-upgrade/ dev announcement of security release]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== smartformer    ==&lt;br /&gt;
|RFI&lt;br /&gt;
|230211 (repeat of 041110)&lt;br /&gt;
|[http://www.itoris.com/joomla-form-builder-smartformer.html v2.4.1 security fix for Joomla 1.5.x]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== xmap 1.2.10    ==&lt;br /&gt;
|Malicious payload in zip&lt;br /&gt;
|230211&lt;br /&gt;
|[http://joomla.vargas.co.cr/en/news/4-xmap/95-security-notice developer resolution notic]e Clean version available from [http://joomlacode.org/gf/project/xmap/frs/ joomlacode] &lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==   Frontend-User-Access 3.4.1  ==&lt;br /&gt;
|Frontend-User-Access 3.4.1 from http://www.pages-and-items.com LFI&lt;br /&gt;
|030211&lt;br /&gt;
|update to [http://extensions.joomla.org/extensions/access-a-security/frontend-access-control/6874 Frontend-User-Access 3.4.2]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  com properties 7134   ==&lt;br /&gt;
| http://com-property.com/ malicious files in script&lt;br /&gt;
|&lt;br /&gt;
|[http://joomlacode.org/gf/project/property/frs/?action=FrsReleaseBrowse&amp;amp;frs_package_id=5815 Dev update statement]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  B2 Portfolio ==&lt;br /&gt;
|B2 portfolio 1.0 SQLi pulseextensions.com&lt;br /&gt;
|250111&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  allcinevid   ==&lt;br /&gt;
|SQLI http://extensions.joomla.org/extensions/multimedia/multimedia-players/video-players-a-gallery/15367&lt;br /&gt;
|220111&lt;br /&gt;
|[http://www.joomtraders.com/our-blog/allcinevid-1.0-sql-injection.html Developers resolution notice]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
== People Component    ==&lt;br /&gt;
|People component http://www.ptt-solution.com/vmchk/people-component.html sqli&lt;br /&gt;
|150111&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==   J!Dump v1.1.2  ==&lt;br /&gt;
| LFI in J!Dump v1.1.2 and before&lt;br /&gt;
|060111&lt;br /&gt;
|The extension is fixed in &lt;br /&gt;
[http://joomlacode.org/gf/project/jdump/frs  version 1.1.3]  070111&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==   xmovie 1.0  ==&lt;br /&gt;
|xmovie 1.0 LFi&lt;br /&gt;
|010111&lt;br /&gt;
|[http://www.optikool.com/news/xmovie-news/45-xmovie-11-udpate v1.1 is a security release.] &lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  Easy File Uploader    ==&lt;br /&gt;
|LFI - http://extensions.joomla.org/extensions/core-enhancements/file-management/11909&lt;br /&gt;
|090111&lt;br /&gt;
| Fixed MIME type tamper vulnerability http://michaelgilkes.info/joomla-plugin-easy-file-uploader 2011-01-10&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  akeebabackup admin tools   ==&lt;br /&gt;
|xss&lt;br /&gt;
|181210&lt;br /&gt;
|http://www.akeebabackup.com/home/item/929-security-release-admin-tools-1-1.html devs update statement&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== aicontactsafe    ==&lt;br /&gt;
|XSS for versions 2.0.13 and below&lt;br /&gt;
|161210&lt;br /&gt;
|[http://www.algisinfo.com/joomla/aicontactsafe-change-log.html dev release 2.0.14]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  JRadio    ==&lt;br /&gt;
|JRadio LFI/SID&lt;br /&gt;
|161210&lt;br /&gt;
|http://www.fxwebdesign.nl/index.php?option=com_content&amp;amp;view=article&amp;amp;id=20&amp;amp;Itemid=56 developer fix statement&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  JE Auto   ==&lt;br /&gt;
|JE Auto 1.0 SQL I&lt;br /&gt;
|091210&lt;br /&gt;
|[http://www.joomlaextensions.co.in/extensions/components/je-auto.html developers bug fix statement]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  jxtended comments   ==&lt;br /&gt;
|xss &lt;br /&gt;
|081210&lt;br /&gt;
|[http://jxtended.com/blog/releases/375-jxtended-comments-131-stable-released.html dev notice] update to 1.3.1&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  sh404SEF   ==&lt;br /&gt;
|sqlI&lt;br /&gt;
|301110&lt;br /&gt;
|[http://dev.anything-digital.com/Blog/sh404SEF/Urgent-security-releases-now-available-for-all-version-of-sh404SEF.html dev post of resolution] &lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  JE Ajax Event Calendar   ==&lt;br /&gt;
|SQL I (relist)&lt;br /&gt;
|251110&lt;br /&gt;
|[http://joomlaextensions.co.in/extensions/components/je-ajax-event-calender.html Dev states resolved,] &lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  Jimtawl    ==&lt;br /&gt;
|Jimtawl LFI &lt;br /&gt;
|251110&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  mosets tree    ==&lt;br /&gt;
|mosets tree various &lt;br /&gt;
|181110&lt;br /&gt;
|dev release 2.1.8 http://forum.mosets.com/showthread.php?t=17064&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==   Maian Media SILVER  ==&lt;br /&gt;
|Maian Media SQLi&lt;br /&gt;
|151110&lt;br /&gt;
|Developer states unproven in free edition, paid/SILVER version is being upgraded. [http://www.aretimes.com/index.php?option=com_content&amp;amp;view=category&amp;amp;layout=blog&amp;amp;id=40&amp;amp;Itemid=113 dev article]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  alfurqan  ==&lt;br /&gt;
|alfurqan 1.5 sqli&lt;br /&gt;
|151110&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  ccboard   ==&lt;br /&gt;
|[http://extensions.joomla.org/extensions/communication/forum/6823 ccboard XSS and SQLi]&lt;br /&gt;
|131110&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==   ProDesk v 1.5  ==&lt;br /&gt;
|LFI &lt;br /&gt;
|091110&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  JQuarks 4 survey 1.0.0   ==&lt;br /&gt;
|SQLi&lt;br /&gt;
|091110&lt;br /&gt;
| [http://www.iptechinside.com/labs/projects/list_files/jquarks-for-surveys developer statement updated to version 1.0.1] 101110&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== RSform! 1.0.5    ==&lt;br /&gt;
|Multiple vulnerabilities - LFI, SQLi&lt;br /&gt;
|061110&lt;br /&gt;
| [http://www.rsjoomla.com/customer-support/documentations/12-general-overview-of-the-component/46-rsform-changelog.html developer announcement of security release]to 1.0.6 091110&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== ccinvoices    ==&lt;br /&gt;
|SQLi for [http://www.chillcreations.com/ ccinvoices]&lt;br /&gt;
|051110&lt;br /&gt;
|Developer Upgrade release to ccInvoices_110RC3 061110&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  sponsorwall   ==&lt;br /&gt;
|SQL injection pulseextensions.com&lt;br /&gt;
|011110&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==  Flip wall   ==&lt;br /&gt;
|SQL injection pulseextensions.com&lt;br /&gt;
|011110&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== K2 joomlaworks    ==&lt;br /&gt;
| http://getk2.org/ k2 xss&lt;br /&gt;
|&lt;br /&gt;
|[http://getk2.org/ version 2.4.1]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Mosets Tree 2.1.5     ==&lt;br /&gt;
|Mosets Tree http://www.mosets.com/tree/  2.1.5 LFI&lt;br /&gt;
|&lt;br /&gt;
|[http://forum.mosets.com/forumdisplay.php?f=2 developer relase statement and change log]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
== Freestyle FAQ 1.5.6     ==&lt;br /&gt;
|http://freestyle-joomla.com/fssdownloads/viewcategory/2 Freestyle FAQ 1.5.6 ‎SQL Injection&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==   JE FAQ Pro  ==&lt;br /&gt;
|[http://www.jextn.com/ Je faq pro] various reports&lt;br /&gt;
|090910&lt;br /&gt;
|[http://www.jextn.com/joomla-faq-component-extensions-downloads Developer update notice]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==   iJoomla Magazine 3.0.1  ==&lt;br /&gt;
|iJoomla Magazine 3.0.1 RFI&lt;br /&gt;
|090910&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  Clantools   ==&lt;br /&gt;
| &lt;br /&gt;
|http://www.joomla-clantools.de/downloads/doc_download/7-clantools-123.html clantool sqli&lt;br /&gt;
|090910&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  jphone   ==&lt;br /&gt;
|jphone LFI&lt;br /&gt;
|090910&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
== Gantry Framework    ==&lt;br /&gt;
|SQli injection&lt;br /&gt;
|050910&lt;br /&gt;
|[http://www.gantry-framework.org/news Update to 3.0.11]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  PicSell    ==&lt;br /&gt;
|[http://vm.xmlswf.com/index.php?option=com_content&amp;amp;view=article&amp;amp;id=104&amp;amp;Itemid=131Picsell LFD, 777]&lt;br /&gt;
|020910&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  JE FAQ Pro   ==&lt;br /&gt;
|[http://www.jextn.com/joomla-faq-component-extensions-downloads/ SID]&lt;br /&gt;
|020910&lt;br /&gt;
|[http://www.jextn.com/joomla-faq-component-extensions-downloads Developer update notice]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==   Zoom Portfolio   ==&lt;br /&gt;
|SID&lt;br /&gt;
|020910&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==   zina   ==&lt;br /&gt;
|[http://www.pancake.org/zina/ SQL Injection]&lt;br /&gt;
|020910&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  Team's   ==&lt;br /&gt;
|[http://www.joomlamo.com Teams extension] SQL Injection &lt;br /&gt;
|120810&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  Amblog    ==&lt;br /&gt;
|[http://robitbt.hu/jm/index.php?option=com_amdownloader&amp;amp;task=showfiles&amp;amp;pathid=8 Amblog] SQLi&lt;br /&gt;
|120810&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==     ==&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  Graffiti Wall   ==&lt;br /&gt;
|[http://extensions.joomla.org/extensions/extension-specific/jomsocial-extensions/13263 Graffiti Wall] for [http://www.joomplace.com/forum/jomsocial-plugins/jomsocial-plugins/graffiti-wall-permissions-777.html jomsocial silent 777]&lt;br /&gt;
|310710&lt;br /&gt;
|[http://extensions.joomla.org/extensions/extension-specific/jomsocial-extensions/13263 Dev statement 1.1 - is security release]. Folder permission was set by default as 777 that is unsecure.&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  Spielothek   ==&lt;br /&gt;
|http://extensions.joomla.org/extensions/sports-a-games/games/11017 http://www.spielban.de/ silent 0777, unknown folder creation&lt;br /&gt;
|290710&lt;br /&gt;
|Dev states version 1.7.1 resolves issues 020810&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==   Aardvertiser  ==&lt;br /&gt;
|http://extensions.joomla.org/extensions/ads-a-affiliates/classified-ads/9454 silent 0777&lt;br /&gt;
|290710&lt;br /&gt;
|[http://sourceforge.net/projects/aardvertiser/forums/forum/989030/topic/3788365 dev announces silent 0777 fixed in Version 2.1 290710]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  FW Real Estate Light    ==&lt;br /&gt;
|http://extensions.joomla.org/extensions/vertical-markets/real-estate/13376 http://www.fastw3b.net/fw-real-estate-light.html silent 777&lt;br /&gt;
|290710&lt;br /&gt;
|[http://www.fastw3b.net/fw-real-estate-light.html version 1.1 reported as fixed 777 issue]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
==     ==&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
== jDownloads    ==&lt;br /&gt;
|http://www.jdownloads.com/ and http://extensions.joomla.org/extensions/directory-a-documentation/downloads/2849 silent 0777 setting&lt;br /&gt;
|2807110&lt;br /&gt;
|1.7.4 RC3 Build 771 update on Jul 29 to remove 0777&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  TTVideo   ==&lt;br /&gt;
|[http://www.toughtomato.com TTVideo 1.0 Joomla] SQL Injection Vulnerability&lt;br /&gt;
|270710&lt;br /&gt;
|[http://www.toughtomato.com/resources/downloads/joomla-1.5/components/ttvideo/ dev updated the component to prevent this]. 280710&lt;br /&gt;
Users are no longer able to download the previous version.&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  frei-chat2.0   ==&lt;br /&gt;
|http://code.google.com/p/frei-chat/downloads/list xss vulnerability &lt;br /&gt;
|230710&lt;br /&gt;
|[http://code.google.com/p/frei-chat/downloads/list Dev announcement to fix] 2.1.2 for FreiChat [Those having CB installed]AND 1.2.2 for FreiChatPure [Extension Independent] 240710&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  QContacts    ==&lt;br /&gt;
|http://extensions.joomla.org/extensions/contacts-and-feedback/contact-details/4811 '''Version: 1.0.4 reported, current version 1.0.6'''&lt;br /&gt;
|220710&lt;br /&gt;
|Devleoper states [http://www.latenight-coding.com/news/joomla/supposed-vulnerability-qcontacts-104.html unproven report and no POC]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
== Jomtube    ==&lt;br /&gt;
|http://www.jomtube.com/ SID&lt;br /&gt;
|220710&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  mysms   ==&lt;br /&gt;
|http://www.willcodejoomlaforfood.de/ Upload Vulnerability &lt;br /&gt;
|july 10,2010&lt;br /&gt;
|290710 [http://www.willcodejoomlaforfood.de/ released the version 1.5.12.] &lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
== Rapid Recipe    ==&lt;br /&gt;
|http://www.rapid-source.com Persistent XSS Vulnerability last known fix version 1.7.2 &lt;br /&gt;
|july 10,2010&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==   Health &amp;amp; Fitness Stats   ==&lt;br /&gt;
|http://joomla-extensions.instantiate.co.uk/jcomponents/healthstats Persistent XSS Vulnerability july 10,2010 &lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==  staticxt   ==&lt;br /&gt;
|http://extensions.joomla.org/extensions/edition/custom-code-in-content/2184  no version number provided&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
==   EasyBlog  ==&lt;br /&gt;
|http://stackideas.com/products/easyblog.html xss (new report) july 10,2010&lt;br /&gt;
|&lt;br /&gt;
|[http://extensions.joomla.org/extensions/news-production/blog/12630 developer reported fix available on site ]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==   redshop light   ==&lt;br /&gt;
|http://redcomponent.com/redshop http://extensions.joomla.org/extensions/e-commerce/shopping-cart/13184 silent 777 and sqli&lt;br /&gt;
|110710&lt;br /&gt;
|[http://redcomponent.com/forum/72-redshop-light/11261-redshop-light-rc2-released-security-release Developer reported fix and upgrade to RC2]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==   quickfaq  ==&lt;br /&gt;
|http://www.schlu.net sqli&lt;br /&gt;
|090710&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==    Minify4Joomla  ==&lt;br /&gt;
|http://waltercedric.com/ LFI and xss&lt;br /&gt;
|090710&lt;br /&gt;
|No longer available to download&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==   IXXO Cart   ==&lt;br /&gt;
|http://www.php-shop-system.com/ SQLi LFI XSS Vulnerability&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
== Music Manager    ==&lt;br /&gt;
|LFI [http://danieljamesscott.org/software/4-joomla-extensions/4-music-manager.html music manager]&lt;br /&gt;
|090710&lt;br /&gt;
|[http://danieljamesscott.org/software/4-joomla-extensions/4-music-manager.html Version 0.13 released]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  PaymentsPlus   ==&lt;br /&gt;
|http://paymentsplus.com.au/ 2.1.5 Blind SQL Injection Vulnerability&lt;br /&gt;
|090710 &lt;br /&gt;
|current version 2.20, 2.1.5 not listed on dev site&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  ArtForms   ==&lt;br /&gt;
|http://joomlacode.org/gf/project/jartforms/ ArtForms 2.1b7.2 RC2 Multiple Remote Vulnerabilities&lt;br /&gt;
|090710&lt;br /&gt;
| Old beta extension &lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==    NeoRecruit  ==&lt;br /&gt;
|neojoomla.com SQL Injection &lt;br /&gt;
| neorecruit vers 1.4 060710&lt;br /&gt;
|[http://www.neojoomla.com/index.php?lang=en dev statement of fix in 1.4.1 and safe 2.0.5] &lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  autartimonial   ==&lt;br /&gt;
|autartica.be Sqli Vulnerability&lt;br /&gt;
|060710&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==   Jobs Pro  ==&lt;br /&gt;
|instantphp.com/ Sqli&lt;br /&gt;
|060710&lt;br /&gt;
|[http://www.instantphp.com/news/40-new-releases/153-jobs-133-is-published.html devs] announcement of fix 130710&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
==  JPodium   ==&lt;br /&gt;
|http://www.jpodium.de/ SQL Injection &lt;br /&gt;
|060710&lt;br /&gt;
|[http://www.jpodium.de/index.php?option=com_content&amp;amp;view=article&amp;amp;id=135:jpodium-not-vulnerable-to-sql-injection&amp;amp;catid=2:newsrotator Devs statement as to not proven]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  Front-End Article Manager System   ==&lt;br /&gt;
|http://b-elektro.no/ Upload Vulnerability&lt;br /&gt;
|040710&lt;br /&gt;
|[http://b-elektro.no/index.php dev states resolved]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
== addressbook    ==&lt;br /&gt;
|http://b-elektro.no/ Upload Vulnerability&lt;br /&gt;
|040710&lt;br /&gt;
|[http://b-elektro.no/index.php dev states resolved] &lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
==   NijnaMonials  ==&lt;br /&gt;
|http://ninjaforge.com/ Sqli Vulnerability&lt;br /&gt;
|040710&lt;br /&gt;
|070410 Discovered to be malicious/false report see [http://nekkidninjas.com/index.php/2010/07/05/there-is-no-sql-injection-vulnerability- devs notice]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
== Phoca Gallery    ==&lt;br /&gt;
|SQL I  (wrong download location in report)&lt;br /&gt;
|040710&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;| deemed malicious report&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
== socialads    ==&lt;br /&gt;
|techjoomla.com/ Xss Vulnerability &lt;br /&gt;
|040710&lt;br /&gt;
|[http://techjoomla.com/joomla-extension-news/socialads-v101-security-update-to-fix-xss-vulnerability-out.html Developers resolved statement]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
== eventcal 1.6.4    ==&lt;br /&gt;
|http://joomlacode.org/gf/project/eventcal/frs/ SQL I  last update 2006-12-31 on joomlacode&lt;br /&gt;
|040710&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
== myblog controller    ==&lt;br /&gt;
|LFI  &lt;br /&gt;
http://www.azrul.com/ &lt;br /&gt;
|010710&lt;br /&gt;
|[http://www.azrul.com/  MyBlog 3.0.332] &lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  joomanager    ==&lt;br /&gt;
|SQli Vulnerability&lt;br /&gt;
http://www.joomanager.com&lt;br /&gt;
|010710&lt;br /&gt;
|[http://www.joomanager.com/component/content/article/3-newsflash/60-joomanager-v13-stable-and-sef-plugins-released.html developer release statement] 260311&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  gamesbox   ==&lt;br /&gt;
|SQL Injection Vulnerability&lt;br /&gt;
http://www.jooforge.com/en/download/commercial/extensions/39-gamesbox&lt;br /&gt;
|010710&lt;br /&gt;
|upgrade to     1.0.10&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==   wmtpic  ==&lt;br /&gt;
|www.webmaster-tips.net various&lt;br /&gt;
|010710&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
== date converter    ==&lt;br /&gt;
|http://sourceforge.net/projects/date-converter/ sqli&lt;br /&gt;
|010710&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
== Remository    ==&lt;br /&gt;
|http://remository.com/ LFI (proc)&lt;br /&gt;
|010710&lt;br /&gt;
|Developer states not proven and possibly malicious. Unable to reproduce without proc/environ security. 260710&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==   RokBridge 1.0rc12   ==&lt;br /&gt;
|http://extensions.joomla.org/extensions/communication/forum-bridges/9012 SDI&lt;br /&gt;
|090810&lt;br /&gt;
|[http://www.rockettheme.com/extensions-updates/834-rokbridge-10rc13-released RokBridge has been updated to version 1.0rc13.] 120810&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
== real estate    ==&lt;br /&gt;
|http://www.opensourcetechnologies.com/demos/real-estate.html RFI&lt;br /&gt;
|210610&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  jomsocial   ==&lt;br /&gt;
|Version: 1.6.288 Multiple XSS&lt;br /&gt;
|210610&lt;br /&gt;
|[http://www.jomsocial.com/blog/security-patch-for-jomsocial-16x.html 1.6.291 released] 220610&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  DOCman    ==&lt;br /&gt;
|DOCman 1.5.7 DOCman 1.4.0 none specific exploit&lt;br /&gt;
|210610&lt;br /&gt;
|[http://blog.joomlatools.eu/2010/06/docman-security-announcement.html developer announcement]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
== eportfolio    ==&lt;br /&gt;
|http://www.joomplace.com/e-portfolio/e-portfolio-description.html Upload  Vulnerability&lt;br /&gt;
|200610&lt;br /&gt;
|Developer [http://www.joomplace.com/e-portfolio/e-portfolio-description.html announcement ] 270810&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  cinema   ==&lt;br /&gt;
|SQL injection&lt;br /&gt;
|190610&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==   Jreservation  ==&lt;br /&gt;
|http://jforjoomla.com/ SQLi Vulnerability&lt;br /&gt;
|190610&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  Super Messenger   ==&lt;br /&gt;
|axxis.gr xss &lt;br /&gt;
|190610&lt;br /&gt;
|[http://axxis.gr/forum/viewtopic.php?f=6&amp;amp;t=641 developer release statement 1.4.6]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==   joomdocs  ==&lt;br /&gt;
|http://joomclan.com/index.php/JoomDocs/ xss vulnerability&lt;br /&gt;
|190610&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  RSComments 1.0.0   ==&lt;br /&gt;
|Persistent XSS NOTE: ONLY executes in backend!&lt;br /&gt;
|190610&lt;br /&gt;
|[http://www.rsjoomla.com/customer-support/documentations/96--general-overview-of-the-component/393-changelog.html Developer update announcement] 210610&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==   Live Chat    ==&lt;br /&gt;
|http://www.joompolitan.com/livechat.html Multiple Remote Vulnerabilities &lt;br /&gt;
|190610&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
== Turtushout 0.11    ==&lt;br /&gt;
| http://www.turtus.org.ua/files?func=fileinfo&amp;amp;id=13 SQL Injection (again)&lt;br /&gt;
|190610&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  BF Survey Pro Free   ==&lt;br /&gt;
|BF Survey Pro Free SQL Injection Exploit &lt;br /&gt;
|190610&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  MisterEstate   ==&lt;br /&gt;
|http://www.misterestate.com/ Blind SQL Injection Exploit &lt;br /&gt;
|190610&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  RSMonials    ==&lt;br /&gt;
|http://www.rswebsols.com/downloads/category/14-download-rsmonials-all?download=23%3Adownload-rsmonials-component XSS Exploit&lt;br /&gt;
|190610&lt;br /&gt;
|Believed to be 1.5.1 version&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==  RSComments 1.0.0   ==&lt;br /&gt;
|RS Comments 1.0.0 Multiple XSS Vulnerabilities http://www.rsjoomla.com (relisted)&lt;br /&gt;
|180610&lt;br /&gt;
|[http://www.rsjoomla.com/customer-support/documentations/96--general-overview-of-the-component/393-changelog.html Developer update announcement] 210610&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  Answers v2.3beta   ==&lt;br /&gt;
|Multiple Vulnerabilities http://extensions.joomla.org/extensions/communication/forum/12652&lt;br /&gt;
|180610&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  Gallery XML 1.1   ==&lt;br /&gt;
|Multiple Vulnerabilities&lt;br /&gt;
http://extensions.joomla.org/extensions/photos-a-images/photo-gallery/12504&lt;br /&gt;
|180610&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  JFaq 1.2   ==&lt;br /&gt;
|JFaq 1.2 Multiple Vulnerabilities&lt;br /&gt;
|180610&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  Listbingo 1.3   ==&lt;br /&gt;
|Multiple Vulnerabilities&lt;br /&gt;
http://extensions.joomla.org/extensions/ads-a-affiliates/classified-ads/12062&lt;br /&gt;
|180610&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
== PowerMail Pro    ==&lt;br /&gt;
| PowerMail Pro Local File Inclusion Vulnerability&lt;br /&gt;
|&lt;br /&gt;
|[http://powermail4joomla.com/forum/showthread.php?tid=163 Dev upadte statement] 151010&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
== Alpha User Points    ==&lt;br /&gt;
|www.alphaplug.com LFI&lt;br /&gt;
|180610&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  Magic Updater   ==&lt;br /&gt;
|http://software.realtyna.com/ RFI&lt;br /&gt;
|170610&lt;br /&gt;
|[http://software.realtyna.com/component/content/article/64-security-patch-for-magic-updater-and-translator.html] developer update statement&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==   recruitmentmanager  ==&lt;br /&gt;
|http://recruitment.focusdev.co.uk Upload Vulnerability&lt;br /&gt;
|130610&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  Info Line (MT_ILine)    ==&lt;br /&gt;
|http://extensions.joomla.org/extensions/news-display/news-tickers-a-scrollers/8425 reports of shell scripts in download file&lt;br /&gt;
|120610&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  Search Log   ==&lt;br /&gt;
|http://www.kanich.net/radio/site/searchlog/searchlog-download SQLi&lt;br /&gt;
|080610&lt;br /&gt;
|[http://www.kanich.net/radio/site/searchlog/searchlog-download Developer cited update to version 3.1.1 100710]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
==  iJoobi   ==&lt;br /&gt;
|jtickets, jsubscription SQL Injection Vulnerability, &lt;br /&gt;
jstore SQL Injection Vulnerability, jnewsletter SQL Injection, jmarket SQL Injection Vulnerability, jcommunity SQL Injection, jsubscription SQL Injection,   &lt;br /&gt;
|090610&lt;br /&gt;
|developer states unproven&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  Ads manager  Annonce   ==&lt;br /&gt;
|http://joomla.clubnautiquemarine.fr/ &lt;br /&gt;
Upload Vulnerability&lt;br /&gt;
| 05/06/10&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  lead article    ==&lt;br /&gt;
|http://www.leadya.co.il/ SQLi&lt;br /&gt;
|050610&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  djartgallery   ==&lt;br /&gt;
|http://www.design-joomla.eu Multiple Vul&lt;br /&gt;
|05/06/10&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
== Gallery 2 Bridge    ==&lt;br /&gt;
|[http://trac.4theweb.nl/g2bridge g2bridge] LFI vulnerability&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  jsjobs   ==&lt;br /&gt;
|[http://www.joomsky.com jsjobs] SQL Injection Vulnerability&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
==     ==&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==   JE Poll  ==&lt;br /&gt;
|http://slideshow.joomlaextensions.co.in/ SQL Injection Vulnerability&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  MyCar   ==&lt;br /&gt;
|http://www.unisoft.me/extensions/ sqli ID&lt;br /&gt;
|&lt;br /&gt;
|[http://www.unisoft.me/mycar/index.php?option=com_smallchat&amp;amp;Itemid=5 Dev announcement update to 1.1]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  MediQnA   ==&lt;br /&gt;
|MediQnA LFI vulnerability version : v1.1&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==   JE Job  ==&lt;br /&gt;
|http://joomlaextensions.co.in/ LFI SQLi&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  BF Quiz   ==&lt;br /&gt;
|SQL Injection Exploit Version(s) = 1.3.0&lt;br /&gt;
|&lt;br /&gt;
|[http://www.tamlyncreative.com.au/software/forum/index.php?topic=729.0 Developer update to BF Quiz v1.3.1]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
==     ==&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==   Ozio Gallery 2  ==&lt;br /&gt;
|DT and open email relay&lt;br /&gt;
|280510&lt;br /&gt;
|[http://oziogallery.joomla.it/index.php?option=com_content&amp;amp;view=article&amp;amp;id=65:rilasciata-la-versione-ozio-gallery-25&amp;amp;catid=2:notizie&amp;amp;Itemid=13&amp;amp;lang=en Developer update and security release] 010610&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  SectionEx   ==&lt;br /&gt;
|Stack Ideas section Ex LFI&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  ActiveHelper LiveHelp    ==&lt;br /&gt;
|XSS in [http://extensions.joomla.org/extensions/communication/chat/12492 LiveHelp] &lt;br /&gt;
|200510&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
==  RS Comments   ==&lt;br /&gt;
|XSS Vulnerability &lt;br /&gt;
|&lt;br /&gt;
|[http://www.rsjoomla.com/customer-support/documentations/96--general-overview-of-the-component/393-changelog.html - fix posted 210510]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
==  BCA RSS Feed   ==&lt;br /&gt;
|LFI and other vulnerabilities&lt;br /&gt;
|&lt;br /&gt;
|Upgrade to [http://ninjaforge.com/index.php?option=com_ninjacentral&amp;amp;page=show_package&amp;amp;id=74&amp;amp;Itemid=236 Ninja RSS Syndicator 1.0.9 or later]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
== SimpleDownload    ==&lt;br /&gt;
|http://extensions.joomla.org/extensions/directory-a-documentation/downloads/10717 various exploits&lt;br /&gt;
|160510&lt;br /&gt;
|updated version (version 0.9.6)&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
==  JE Quotation Form   ==&lt;br /&gt;
|http://joomlaextensions.co.in/free-download/doc_download/11-je-quotation-form.html  LFI&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  konsultasi   ==&lt;br /&gt;
|SQL Injection Vulnerability&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
== Aardvertiser    ==&lt;br /&gt;
|Local File Inclusion Vulnerability	&lt;br /&gt;
http://extensions.joomla.org/extensions/ads-a-affiliates/classified-ads/9454&lt;br /&gt;
|&lt;br /&gt;
|see [http://docs.joomla.org/Vulnerable_Extensions_List#Aardvertiser resolved notice 040810]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |&lt;br /&gt;
&lt;br /&gt;
==  Seber Cart    ==&lt;br /&gt;
|Local File Disclosure Vulnerability&lt;br /&gt;
|&lt;br /&gt;
|[http://www.sebercart.com/index.php?option=com_content&amp;amp;view=article&amp;amp;id=158 Developer Update 140510]&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  FDione Form Wizard   ==&lt;br /&gt;
|lfi vulnerability	&lt;br /&gt;
|140510 200510&lt;br /&gt;
|[http://dionesoft.com Update to Dione Form Wizard (v. 1.0.4)].&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==   Custom PHP Pages  ==&lt;br /&gt;
|http://extensions.joomla.org/extensions/edition/custom-code-in-content/5057 LFI Vulnerability		&lt;br /&gt;
|&lt;br /&gt;
|[http://fijiwebdesign.com Developer declares not vulnerable 140510]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |&lt;br /&gt;
&lt;br /&gt;
==  Camp26 Visitor    ==&lt;br /&gt;
|RFI www.camp26.biz&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==    iJoomla News Portal  ==&lt;br /&gt;
|RFI SID&lt;br /&gt;
|&lt;br /&gt;
|[http://www.ijoomla.com/forum/index.php/topic,4480.0.html Update to 1.5.10]&lt;br /&gt;
|-&lt;br /&gt;
|  &lt;br /&gt;
==  article Factory Manager   ==&lt;br /&gt;
|RFI &amp;amp; Input Validation Error http://www.thefactory.ro/shop/joomla-components/article-manager.html&lt;br /&gt;
|may 2010&lt;br /&gt;
|can not reproduce and unproven, http://www.thefactory.ro&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  Table JX Component    ==&lt;br /&gt;
|http://www.toolsjx.com/ Table JX Component XSS&lt;br /&gt;
|060510 - update 130510&lt;br /&gt;
|Version: 1.5.5 considered unsafe, [http://www.toolsjx.com update to 1.5.7]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |&lt;br /&gt;
&lt;br /&gt;
==   JE Property  ==&lt;br /&gt;
|JE Property Finder Upload Vulnerability&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |&lt;br /&gt;
&lt;br /&gt;
==   Noticeboard  ==&lt;br /&gt;
|Noticeboard for Joomla &amp;quot;controller&amp;quot; Local File Inclusion Vulnerability&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |&lt;br /&gt;
&lt;br /&gt;
==SmartSite     ==&lt;br /&gt;
|SmartSite com_smartsite Local File Inclusion Vulnerability &lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   |&lt;br /&gt;
&lt;br /&gt;
==  ABC    ==&lt;br /&gt;
|ABC SQL Injection Vulnerability&lt;br /&gt;
|&lt;br /&gt;
|reported as updated to JED 290410&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |&lt;br /&gt;
&lt;br /&gt;
==  htmlcoderhelper graphics   ==&lt;br /&gt;
|htmlcoderhelper graphics v1.0.6 LFI Vulnerability&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |&lt;br /&gt;
&lt;br /&gt;
== Ultimate Portfolio    ==&lt;br /&gt;
|Ultimate Portfolio  Local File Inclusion Vulnerability&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   |&lt;br /&gt;
&lt;br /&gt;
==  huruhelpdesk   ==&lt;br /&gt;
|http://www.huruhelpdesk.net sqli injection &lt;br /&gt;
|&lt;br /&gt;
|[http://www.huruhelpdesk.net/forums/8-announcements/392--sql-injection-reveals-user-md5-password-hash Reported fix]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |&lt;br /&gt;
&lt;br /&gt;
==  Archery Scores   ==&lt;br /&gt;
| [http://lispeltuut.org/ Archery Scores (com_archeryscores) v1.0.6 LFI Vulnerability]&lt;br /&gt;
&lt;br /&gt;
|210410&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |&lt;br /&gt;
&lt;br /&gt;
==  ZiMB Manager   ==&lt;br /&gt;
|Joomla Component ZiMB Manager Local File Inclusion Vulnerability&lt;br /&gt;
|210410&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |&lt;br /&gt;
&lt;br /&gt;
==  Matamko   ==&lt;br /&gt;
|Matamko Local File Inclusion Vulnerability&lt;br /&gt;
|210410&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |&lt;br /&gt;
&lt;br /&gt;
==  Multiple Root   ==&lt;br /&gt;
|Multiple Root Local File Inclusion Vulnerability http://joomlacomponent.inetlanka.com/&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |&lt;br /&gt;
&lt;br /&gt;
==  Multiple Map   ==&lt;br /&gt;
|Multiple Map Local File Inclusion Vulnerability joomlacomponent.inetlanka.com&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |&lt;br /&gt;
&lt;br /&gt;
==   Contact Us Draw Root Map  ==&lt;br /&gt;
|Draw Root Map Local File Inclusion Vulnerability joomlacomponent.inetlanka.com&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |&lt;br /&gt;
&lt;br /&gt;
==  iF surfALERT   ==&lt;br /&gt;
|[http://www.inertialfate.za.net/ iF surfALERT] Local File Inclusion Vulnerability&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |&lt;br /&gt;
&lt;br /&gt;
==   GBU FACEBOOK  ==&lt;br /&gt;
|GBU FACEBOOK SQL injection vulnerability http://www.gbugrafici.nl/gbufacebook/&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |&lt;br /&gt;
&lt;br /&gt;
==   jnewspaper  ==&lt;br /&gt;
|jnewspaper (cid) SQL Injection Vulnerability&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  JTM Reseller   ==&lt;br /&gt;
|TM Reseller SQL injection vulnerability&lt;br /&gt;
|&lt;br /&gt;
|[http://jtmreseller.com/ Developer Update] &lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   |&lt;br /&gt;
&lt;br /&gt;
==  media Mall Factory   ==&lt;br /&gt;
|SQLi&lt;br /&gt;
|200410&lt;br /&gt;
| [http://www.thefactory.ro/contact-us/product-update-request.html Solution: update to 1.0.5] &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==   Gadget Factory  ==&lt;br /&gt;
|LFi&lt;br /&gt;
|200410&lt;br /&gt;
|[http://www.thefactory.ro/contact-us/product-update-request.html Solution: update to 1.5.1]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  Deluxe Blog Factory   ==&lt;br /&gt;
|SQLi&lt;br /&gt;
|200410&lt;br /&gt;
|[http://www.thefactory.ro/contact-us/product-update-request.html update to 1.1.2]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
==     ==&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |&lt;br /&gt;
== MT Fire Eagle ==&lt;br /&gt;
&lt;br /&gt;
|LFI http://joomlacode.org/gf/project/jfireeagle/frs/ http://www.moto-treks.com&lt;br /&gt;
| 190410&lt;br /&gt;
| product considered retired and to be replaced by dev&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
==  com properties   ==&lt;br /&gt;
| http://com-property.com/ SQL I&lt;br /&gt;
|&lt;br /&gt;
|[http://www.com-property.com/images/fbfiles/files/properties-20100413.txt developer announced fix]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  Sweetykeeper   ==&lt;br /&gt;
|Sweetykeeper Local File Inclusion Vulnerability  http://www.joomlacorner.com/&lt;br /&gt;
|120410&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  jvehicles   ==&lt;br /&gt;
|SQL Injection http://jvehicles.com&lt;br /&gt;
|120410&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  worldrates   ==&lt;br /&gt;
|http://dev.pucit.edu.pk/&lt;br /&gt;
|120410&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  cvmaker   ==&lt;br /&gt;
|http://dev.pucit.edu.pk/&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  advertising   ==&lt;br /&gt;
|http://dev.pucit.edu.pk/&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==   horoscope  ==&lt;br /&gt;
|http://dev.pucit.edu.pk/&lt;br /&gt;
|120410&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==   webtv  ==&lt;br /&gt;
|http://dev.pucit.edu.pk/&lt;br /&gt;
|120410&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  diary   ==&lt;br /&gt;
|http://dev.pucit.edu.pk/&lt;br /&gt;
|120410&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==   Multi-Venue Restaurant Menu Manager (MVRMM)  ==&lt;br /&gt;
|http://www.focusdev.co.uk/ &lt;br /&gt;
|120410 &lt;br /&gt;
||[http://extensions.joomla.org/extensions/vertical-markets/food-a-beverage/10015 Version 1.5.2 Stable Update 4]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  Memory Book   ==&lt;br /&gt;
|http://dev.pucit.edu.pk/&lt;br /&gt;
|120410&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==   TRAVELbook  ==&lt;br /&gt;
| http://www.demo-page.de/&lt;br /&gt;
|120410&lt;br /&gt;
|[http://www.demo-page.de/de/erweiterungen-mehr-inhalte/travelbook/download.html developers resolution notice 1.0.2]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
== AlphaUserPoints    ==&lt;br /&gt;
|&lt;br /&gt;
|[http://www.alphaplug.com/index.php/downloads.html?func=fileinfo&amp;amp;id=31 developer upgrade]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  JprojectMan   ==&lt;br /&gt;
|LFI http://extensions.joomla.org/extensions/communities-a-groupware/project-a-task-management/5676&lt;br /&gt;
|110410&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==   CKForms  ==&lt;br /&gt;
|1.3.4 release - Important LFI security fix [http://joomlacode.org/gf/project/ckforms/news/?action=NewsThreadView&amp;amp;id=2814 ]&lt;br /&gt;
|07-04-10 &lt;br /&gt;
|[http://ckforms.cookex.eu/download/download.php upgrade]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==   econtentsite  ==&lt;br /&gt;
|LFI&lt;br /&gt;
|040410&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==    Jvehicles ==&lt;br /&gt;
|ID&lt;br /&gt;
|040410&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
==     ==&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  smestorage   ==&lt;br /&gt;
|[http://www.smestorage.com SMEStorage] LFI&lt;br /&gt;
&lt;br /&gt;
|Updated 29 March 10&lt;br /&gt;
|[http://gelembjuk.com/index.php?option=com_content&amp;amp;view=section&amp;amp;layout=blog&amp;amp;id=1&amp;amp;Itemid=55 developer fix] to 1.1&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  JE Tooltip   ==&lt;br /&gt;
|[http://joomlaextensions.co.in/formcreator/ JE Tooltip] LFI&lt;br /&gt;
|Updated 23 March &lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  Gift Exchange Beta   ==&lt;br /&gt;
|[http://extensions.joomla.org/extensions/communities-a-groupware/membership/11680 Gift exchange] SQLi&lt;br /&gt;
|Updated 23 March &lt;br /&gt;
|[http://socialables.com/28-Jomsocial/Gift-Exchange/flypage.tpl.html upgrade beta 1.0.1]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==  RokDownloads  ==&lt;br /&gt;
|[[http://extensions.joomla.org/extensions/directory-a-documentation/downloads/7967 LFI]] &lt;br /&gt;
|15 march 2010&lt;br /&gt;
||upgrade to [http://www.rockettheme.com/extensions-updates/638-rokdownloads-10-released version 1.0]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==    gigcalender   ==&lt;br /&gt;
&lt;br /&gt;
|SQLi [http://extensions.joomla.org/extensions/calendars-a-events/events/97)http://extensions.joomla.org/extensions/calendars-a-events/events/97 gigcalender]&lt;br /&gt;
|13 march 2010&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
==    heza content   ==&lt;br /&gt;
|SQLi [http://extensions.joomla.org/extensions/structure-a-navigation/sections-a-categories/10427)http://extensions.joomla.org/extensions/structure-a-navigation/sections-a-categories/10427  heza content]&lt;br /&gt;
|13 march 2010&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==   juliaportfolio   ==&lt;br /&gt;
|LFI [http://extensions.joomla.org/extensions/directory-&amp;amp;-documentation/portfolio/8519/details juliaportfolio]&lt;br /&gt;
|13 march 2010&lt;br /&gt;
|[http://www.treidorinte.ro/joomla-extensions/19-joomla-components/467-juliaportfolio-security-upgrade-required withdrawal and update notice]&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  Flash Magazine Deluxe   ==&lt;br /&gt;
|SQL Injection Vulnerability.&lt;br /&gt;
|Feb 25&lt;br /&gt;
|'''[http://www.joomplace.com/flash-magazine-deluxe/flash-magazine-deluxe-description.html Developer Update Version 2.0.11 09/03/10]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  SqlReport   ==&lt;br /&gt;
|Sqlreport has a sql/RFI exploit. awaiting confirmation on exact developer.&lt;br /&gt;
|Feb 20&lt;br /&gt;
|'''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  Scriptegrator   ==&lt;br /&gt;
|Core Design [http://www.greatjoomla.com/extensions/plugins/core-design-scriptegrator-plugin.html Scriptegrator] RFI exploit&lt;br /&gt;
|Feb 20&lt;br /&gt;
|[http://www.greatjoomla.com/extensions/plugins/core-design-scriptegrator-plugin.html Dev Upgrade announcement]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  AllVideos 3.1  ==&lt;br /&gt;
|&lt;br /&gt;
A vulnerability discovered in versions 3.0. and 3.1 of the plugin can be exploited by malicious people to disclose potentially sensitive information. For security reasons we will not be providing further details to safeguard users of affected versions. http://www.joomlaworks.gr/content/view/77/34/]|&lt;br /&gt;
|17 Feb&lt;br /&gt;
| [http://joomlaworks.googlecode.com/files/plg_jw_allvideos-v3.3_j1.5.zip Version 3.3 release 18th]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  RW Cards   ==&lt;br /&gt;
| [http://extensions.joomla.org/extensions/3430/details RW Card] LFI and ID exploit [http://www.weberr.de/ Dev Site]&lt;br /&gt;
|180210&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |'''  [http://www.weberr.de/index.php/forum.html?func=view&amp;amp;catid=5&amp;amp;id=1939&amp;amp;limit=6 developer update]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Yelp ==&lt;br /&gt;
| SQLi - Unable to locate developer. Possibly a custom extension.&lt;br /&gt;
|Feb 01 &lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  '''Autartitarot'''   ==&lt;br /&gt;
|Directory Traversal. Back end access required&lt;br /&gt;
| Feb 05&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; | ''' Please upgrade to [http://www.autartica.be/en/autartitarot version 1.0.4]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==  communitypolls   ==&lt;br /&gt;
|LFI - [http://www.corejoomla.com/ community polls] &lt;br /&gt;
|Feb 17&lt;br /&gt;
||upgrade to [http://www.corejoomla.com/ version 1.5.3]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
==     ==&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;endFeed /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''This list is change protected, for updates or additions [http://forum.joomla.org/memberlist.php?mode=viewprofile&amp;amp;u=28000 Mandville] or [http://forum.joomla.org/memberlist.php?mode=viewprofile&amp;amp;u=87230 lafrance]&lt;br /&gt;
''&lt;br /&gt;
&lt;br /&gt;
== Codes used ==&lt;br /&gt;
SQLi - SQL injection [http://en.wikipedia.org/wiki/Code_injection#SQL_injection wikipedia]&lt;br /&gt;
&lt;br /&gt;
LFI - Local File Inclusion [http://www.scribd.com/doc/6498408/Remote-and-Local-File-Inclusion-Explained scribd]&lt;br /&gt;
&lt;br /&gt;
RFI - Remote file inclusion [http://en.wikipedia.org/wiki/Remote_File_Inclusion wikipedia]&lt;br /&gt;
&lt;br /&gt;
DT - Directory Traversal [http://en.wikipedia.org/wiki/Directory_traversal wikipedia]&lt;br /&gt;
&lt;br /&gt;
ID = Information Disclosure: account information or sensitive information publicly viewable&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Future Actions &amp;amp; WIP ==&lt;br /&gt;
&lt;br /&gt;
[http://feeds.joomla.org/JoomlaSecurityVulnerableExtensions RSS feed] completed&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
to feed VEL direct to twitter&lt;br /&gt;
&lt;br /&gt;
== Notes ==&lt;br /&gt;
The RSS feed is currently fed by item entry order and not by date fixed. &lt;br /&gt;
List as discussed in  [[jtopic:455746]] by [http://forum.joomla.org/memberlist.php?mode=viewprofile&amp;amp;u=67439 PhilD] editing by [http://forum.joomla.org/memberlist.php?mode=viewprofile&amp;amp;u=28000 Mandville]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
[[Category:Security]]&lt;br /&gt;
[[Category:Security_FAQ]]&lt;br /&gt;
[[Category:Component Management]]&lt;br /&gt;
----&lt;/div&gt;</summary>
		<author><name>CirTap</name></author>	</entry>

	<entry>
		<id>http://docs.joomla.org/Archived_vel</id>
		<title>Archived vel</title>
		<link rel="alternate" type="text/html" href="http://docs.joomla.org/Archived_vel"/>
				<updated>2011-07-15T09:07:31Z</updated>
		
		<summary type="html">&lt;p&gt;CirTap: moved Archived vel to Vulnerable Extensions List/Archive/2009-10: poluting Main namespace&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{RightTOC}}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  '''Extension'''&lt;br /&gt;
! class=&amp;quot;unsortable&amp;quot;| '''Details'''&lt;br /&gt;
!  '''Reference Link'''&lt;br /&gt;
!  '''Extension Update Link'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''com_ajaxchat'''&lt;br /&gt;
|  Summary: PHP remote file inclusion vulnerability in Fiji Web Design Ajax Chat ('''com_ajaxchat''') component 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[mosConfig_absolute_path] parameter to tests/ajcuser.php.New version release December 22,2009&lt;br /&gt;
Published: october 28 2009&lt;br /&gt;
|  [[NIST:CVE-2009-3822|CVE-2009-3822]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | [http://extensions.joomla.org/extensions/communication/chat/10767 update v 1.1]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''com_booklibrary'''&lt;br /&gt;
|  PHP remote file inclusion vulnerability in doc/releasenote.php in the BookLibrary ('''com_booklibrary''') component 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter, a different vector than [[NIST:CVE-2009-2637|CVE-2009-2637]]. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 10/28/2009&lt;br /&gt;
CVSS Severity: 7.5 (HIGH)&lt;br /&gt;
|  [[NIST:CVE-2009-3817|CVE-2009-3817]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''[http://ordasoft.com/Download/Joomla1.0-extensions/Joomla1.0-components/View-category.html developer site updates]'''&lt;br /&gt;
|-&lt;br /&gt;
|   style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''com_foobla_suggestions'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the foobla Suggestions ('''com_foobla_suggestions''') component 1.5.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the idea_id parameter to index.php.&lt;br /&gt;
Published: 10/11/2009&lt;br /&gt;
CVSS Severity: 7.5 (HIGH)&lt;br /&gt;
|  [[NIST:CVE-2009-3669|CVE-2009-3669]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | [http://foobla.com/news/latest/fixed-foobla-suggestions-for-joomla-idea_id-sql-injection-vulnerability.html developer reported upgrade]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_djcatalog'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the DJ-Catalog ('''com_djcatalog''') component for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a showItem action and (2) cid parameter in a show action to index.php.&lt;br /&gt;
Published: 10/11/2009&lt;br /&gt;
CVSS Severity: 6.8 (MEDIUM)&lt;br /&gt;
|  [[NIST:CVE-2009-3661|CVE-2009-3661]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''com_cbresumebuilder'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the JoomlaCache CB Resume Builder (''''''com_cbresumebuilder''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the group_id parameter in a group_members action to index.php.&lt;br /&gt;
Published: 10/09/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3645|CVE-2009-3645]] &lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |'''[http://www.joomlacache.com/commercial-extensions/security-update.html Developer Update]'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  |  '''com_soundset'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Soundset ('''com_soundset''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter to index.php.&lt;br /&gt;
Published: 10/09/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3644|CVE-2009-3644]]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  |  '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  |'''com_sportfusion'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Kinfusion SportFusion ('''com_sportfusion''') component 0.2.2 through 0.2.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid[0] parameter in a teamdetail action to index.php.&lt;br /&gt;
Published: 09/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3491|CVE-2009-3491]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  |'''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_icrmbasic'''&lt;br /&gt;
|  Summary: A certain interface in the iCRM Basic ('''com_icrmbasic''') component 1.4.2.31 for Joomla! does not require administrative authentication, which has unspecified impact and remote attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 09/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3481|CVE-2009-3481]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_mytube'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the MyRemote Video Gallery ('''com_mytube''') component 1.0 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter in a videos action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3446|CVE-2009-3446]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_fastball'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Fastball ('''com_fastball''') component 1.1.0 through 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the league parameter to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3443|CVE-2009-3443]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | [http://www.fastballproductions.com   latest version] 1.2.1 &lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_facebook'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the JoomlaFacebook ('''com_facebook''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a student action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3438|CVE-2009-3438]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_tupinambis'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Tupinambis ('''com_tupinambis''') component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the proyecto parameter in a verproyecto action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3434|CVE-2009-3434]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''com_idoblog'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the IDoBlog ('''com_idoblog''') component 1.1 build 30 for Joomla! allows remote attackers to execute arbitrary SQL commands via the userid parameter in a profile action to index.php, a different vector than [[NIST:CVE-2008-2627|CVE-2008-2627]].&lt;br /&gt;
Published: 09/25/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3417|CVE-2009-3417]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot; |'''[http://idojoomla.com/download.html/ '''New Version v 1.1''' (build 32)]'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_hbssearch'''&lt;br /&gt;
|  Summary: Cross-site scripting ('''XSS''') vulnerability in the Hotel Booking Reservation System ('''aka HBS or com_hbssearch''') component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the adult parameter in a showhoteldetails action to index.php.&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 4.3 ('''MEDIUM''')&lt;br /&gt;
|  [[NIST:CVE-2009-3368|CVE-2009-3368]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_hbssearch'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System ('''aka HBS or com_hbssearch''') component for Joomla! allow remote attackers to execute arbitrary SQL commands via the ('''1''') h_id, ('''2''') id, and ('''3''') rid parameters to longDesc.php, and the h_id parameter to ('''4''') detail.php, ('''5''') detail1.php, ('''6''') detail2.php, ('''7''') detail3.php, ('''8''') detail4.php, ('''9''') detail5.php, ('''10''') detail6.php, ('''11''') detail7.php, and ('''12''') detail8.php, different vectors than [[NIST:CVE-2008-5865|CVE-2008-5865]], [[NIST:CVE-2008-5874|CVE-2008-5874]], and [[NIST:CVE-2008-5875|CVE-2008-5875]].&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3357|CVE-2009-3357]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''com_alphauserpoints'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in frontend/assets/ajax/checkusername.php in the AlphaUserPoints ('''com_alphauserpoints''') component 1.5.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the username2points parameter.&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3342|CVE-2009-3342]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |'''[http://www.alphaplug.com/index.php/news/142-alphauserpoints-153-released.html 1.5.3]'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''TurtuShout'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the TurtuShout component 0.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Name field.&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3335|CVE-2009-3335]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jinc'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Lhacky! Extensions Cave Joomla! Integrated Newsletters Component ('''aka JINC or com_jinc''') component 0.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a messages action to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3334|CVE-2009-3334]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''com_jbudgetsmagic'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the JBudgetsMagic ('''com_jbudgetsmagic''') component 0.3.2 through 0.4.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the bid parameter in a mybudget action to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3332|CVE-2009-3332]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | '''[http://sopinet.com/jbudgetsmagic/index.php?option=com_remository&amp;amp;Itemid=5&amp;amp;lang=en Update to 0.4.1]'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_surveymanager'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Focusplus Developments Survey Manager ('''com_surveymanager''') component 1.5.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the stype parameter in an editsurvey action to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3325|CVE-2009-3325]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_album'''&lt;br /&gt;
|  Summary: Directory traversal vulnerability in the Roland Breedveld Album ('''com_album''') component 1.14 for Joomla! allows remote attackers to access arbitrary directories and have unspecified other impact via a .. ('''dot dot''') in the target parameter to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3318|CVE-2009-3318]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;   | '''com_jreservation'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the [http://extensions.joomla.org/extensions/vertical-markets/booking-a-reservation/9798 JReservation] ('''com_jreservation''') component 1.0 and 1.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a propertycpanel action to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3316|CVE-2009-3316]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot; |  [http://www.jforjoomla.com Updated 28th] Jan fixed 13th Nov&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''IXXO Cart Standalone'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in IXXO Cart Standalone before 3.9.6.1, and the IXXO Cart component for Joomla! 1.0.x, allows remote attackers to execute arbitrary SQL commands via the parent parameter.&lt;br /&gt;
Published: 09/16/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3215|CVE-2009-3215]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_digifolio'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the DigiFolio ('''com_digifolio''') component 1.52 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a project action to index.php.&lt;br /&gt;
Published: 09/15/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3193|CVE-2009-3193]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_aclassf'''&lt;br /&gt;
|  Summary: Cross-site scripting ('''XSS''') vulnerability in '''gmap.php''' in the Almond Classifieds ('''com_aclassf''') component 7.5 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the addr parameter.&lt;br /&gt;
Published: 09/10/2009&lt;br /&gt;
CVSS Severity: 4.3 ('''MEDIUM''')&lt;br /&gt;
|  [[NIST:CVE-2009-3155|CVE-2009-3155]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;   | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''com_aclassf'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Almond Classifieds ('''com_aclassf''') component 7.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the replid parameter in a manw_repl add_form action to index.php, a different vector than [[NIST:CVE-2009-2567|CVE-2009-2567]].&lt;br /&gt;
Published: 09/10/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3154|CVE-2009-3154]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | [http://www.almondsoft.com/alcl.html Developer latest component]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jabode'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in Jabode horoscope extension ('''com_jabode''') for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a sign task to index.php.&lt;br /&gt;
Published: 09/08/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
&lt;br /&gt;
|  [[NIST:CVE-2008-7169|CVE-2008-7169]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_gameserver'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Game Server ('''com_gameserver''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a gamepanel action to index.php.&lt;br /&gt;
Published: 09/03/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3063|CVE-2009-3063]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_artportal'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Artetics.com Art Portal ('''com_artportal''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the portalid parameter to index.php.&lt;br /&gt;
Published: 09/03/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3054|CVE-2009-3054]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:#cef2e0; color:black&amp;quot; | '''com_agora'''&lt;br /&gt;
|  Summary: Directory traversal vulnerability in the Agora ('''com_agora''') component 3.0.0b for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the action parameter to the avatars page, reachable through index.php.&lt;br /&gt;
Published: 09/03/2009&lt;br /&gt;
CVSS Severity: 6.8 ('''MEDIUM''')&lt;br /&gt;
|  [[NIST:CVE-2009-3053|CVE-2009-3053]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot; |'''[http://jvitals.com/index.php?option=com_rokdownloads&amp;amp;view=file&amp;amp;Itemid=108&amp;amp;id=282:agora-3-0 3.0.7]'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_simpleshop'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Simple Shop Galore ('''com_simpleshop''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the section parameter in a section action to index.php, a different vulnerability than [[NIST:CVE-2008-2568|CVE-2008-2568]]. NOTE: this issue was disclosed by an unreliable researcher, so the details might be incorrect.&lt;br /&gt;
Published: 08/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-7033|CVE-2008-7033]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_groups'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Permis ('''com_groups''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a list action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 08/17/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-2789|CVE-2009-2789]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:#cef2e0; color:black&amp;quot; | '''com_content'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the content component ('''com_content''') 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a blogcategory action to index.php.&lt;br /&gt;
Published: 08/10/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6923|CVE-2008-6923]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |'''[http://developer.joomla.org/security/news/305-20091103-core-front-end-editor-issue-.html Resolution]'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Live Chat ('''com_livechat''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the last parameter to getChatRoom.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6883|CVE-2008-6883]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: Live Chat ('''com_livechat''') component 1.0 for Joomla! allows remote attackers to use the xmlhttp.php script as an open HTTP proxy to hide network scanning activities or scan internal networks via a GET request with a full URL in the query string.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6882|CVE-2008-6882]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the Live Chat ('''com_livechat''') component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the last parameter to ('''1''') getChat.php, ('''2''') getChatRoom.php, and ('''3''') getSavedChatRooms.php.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6881|CVE-2008-6881]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''JUMI'''&lt;br /&gt;
|  There is a backdoor in JUMI that installs itself when JUMI is installed on your web site. It sends your credentials to a website, and sets up a back door for remote code execution.&lt;br /&gt;
Please remove JUMI2.0.5 immediately. &lt;br /&gt;
It will be simple enough to remove the compromised code from this download, but you need to do &lt;br /&gt;
a full security audit on your site as well as you have been compromised. Added November 2009&lt;br /&gt;
|  [http://code.google.com/p/jumi/updates/list Report]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |[http://code.google.com/p/jumi/updates/list Jumi Update]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''com_photoblog'''&lt;br /&gt;
|  Input Validation Error Added November 2009&lt;br /&gt;
|  [http://www.securityfocus.com/bid/36809/ 36809]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |[http://webguerilla.net/downloads/3-components-for-joomla-1 webguerilla Photoblog alpha 3b]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jshop'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the JShop ('''com_jshop''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a product action to index.php.&lt;br /&gt;
Published: 11/02/2009&lt;br /&gt;
CVSS Severity: 7.5 '''(HIGH)''' &lt;br /&gt;
|  [[NIST:CVE-2009-3835|CVE-2009-3835]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot; |'''BF Survey Pro'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the '''BF Survey Pro''' v1.2.5 or lower  (fixed in version 1.2.6). '''BF Survey Basic v1.0''' (fixed in version 1.1). '''BF Quiz v1.1.1''' (fixed in version 1.2 or greater) Added November 2009&lt;br /&gt;
|  [http://www.tamlyncreative.com.au/software/forum/index.php?topic=357.0 tamlyncreative.com.au]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |[http://www.tamlyncreative.com.au/software/forum/index.php?topic=357.0 update]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot; |'''Joo!BB 0.9.1 '''&lt;br /&gt;
|  Summary: Persistent XSS/MySQL Injection vulnerabilities in Joo!BB 0.9.1 Added November 2009&lt;br /&gt;
|  [http://www.joobb.org/community/board/topic/700-MultipleXSSSQLInjectionVulnerabilities.html joob.org]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot; |[http://www.joobb.org/downloads/components.html update]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''sh404sef '''&lt;br /&gt;
|  Summary: sh404sef URI XSS Vulnerability  Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/sh404sef-uri-xss-vulnerability.html jeffchannell.com]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |[http://extensions.siliana.com/en/2009060876/sh404SEF-and-url-rewriting/Interim-release-of-sh404sef-for-Joomla-1.5.x.html update]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''AWD Wall 1.5''' &lt;br /&gt;
|  Summary '''AWD Wall 1.5''' Blind SQL Injection Vulnerability.The Joomla component AWD Wall 1.5 suffers from an SQL Injection vulnerability in its handling of the 'cbuser' parameter.Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/awd-wall-15-blind-sql-injection-vulnerability.html Notice]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | '''[http://www.awdsolution.com/template_demo/testsite/index.php?option=com_content&amp;amp;view=article&amp;amp;id=48&amp;amp;Itemid=72 developer update]'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''EasyBook 2.0.0rc4'''&lt;br /&gt;
|  Summary: The Joomla component '''EasyBook 2.0.0rc4''' suffers from multiple persistent XSS vulnerabilities. One seems fairly critical, while the others would take some incredible creativity to actively exploit. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/easybook-200rc4-multiple-xss-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''F!BB 1.5.96''' &lt;br /&gt;
|  Summary: The Joomla component '''F!BB 1.5.96 RC''' suffers from multiple persistent XSS vulnerabilities, as well SQL Injection in its user search feature. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/fbb-1596-rc-multiple-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Testimonial Ku 2.0 Admin Panel'''&lt;br /&gt;
|  Summary: The Joomla component '''Testimonial Ku 2.0''' is vulnerable to persistent XSS in the administrator panel. A malicious user can submit a testimonial containing &amp;lt;script&amp;gt; tags with absolutely no quotes and inject that script into the administrator panel through any of the available inputs except &amp;quot;email&amp;quot;. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/testimonial-ku-20-admin-panel-persistent-xss.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''MS Comment 0.8.0b'''&lt;br /&gt;
|  Summary '''MS Comment 0.8.0b for Joomla''', a commenting plugin, suffers from an multiple vulnerabilities. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/ms-comment-080b-multiple-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |  '''!JoomlaComment 4.0 beta1'''&lt;br /&gt;
|  Summary: '''!JoomlaComment 4.0 beta1''', a commenting plugin, suffers from multiple XSS vulnerabilities. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/joomlacomment-40-beta1-multiple-xss-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | '''  [http://compojoom.com/blog/8-news/121-joomlacomment-40-rc1-released Developer Notice 4.0 rc1]''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''WebAmoeba Ticket System 3.0.0'''&lt;br /&gt;
|  Summary:  '''WebAmoeba Ticket System 3.0.0''', a Joomla help desk component. The vulnerability is with the BBCode library used to parse BBCode tags, as it does not strip javascript: urls from [url] tags. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/webamoeba-ticket-system-300-bbcode-xss.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |'''Kunena 1.5.x''' &lt;br /&gt;
|Summary: This is an important security release and users are urged to update immediately. Five security issues and an Internet Explorer 8 table bug have been resolved in this release. This release also contains many other important bug fixes. Added 18 November 2009&lt;br /&gt;
|[http://www.kunena.com/blog/19-developer-blog/51-kunena-157-security-release-now-available Advisory]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |[http://www.kunena.com/blog/19-developer-blog/52-kunena-158-service-release-now-available Latest 1.5.8 Version]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_siirler'''&lt;br /&gt;
|  Summary:  SQL injection vulnerability in the '''Q-Proje Siirler Bileseni (com_siirler)''' component 1.2 RC for Joomla! allows remote attackers to execute arbitrary SQL commands via the sid parameter in an sdetay action to index.php. Added 18 November 2009&lt;br /&gt;
|  [[NIST:CVE-2009-3972 | CVE-2009-3972]]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''jTips (com_jtips)'''&lt;br /&gt;
|SUmmary:SQL injection vulnerability in the '''jTips (com_jtips)''' component 1.0.7 and 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the season parameter in a ladder action to index.php. Added 18 November 2009&lt;br /&gt;
| [[NIST:CVE-2009-3971 |CVE-2009-3971]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''NinjaMonials'''&lt;br /&gt;
| Summary: SQL injection vulnerability in the '''NinjaMonials (com_ninjacentral)''' component 1.1.0 for '''Joomla 1.0.x''' ! allows remote attackers to execute arbitrary SQL commands via the testimID parameter in a display action to index.php. Added 18 November 2009&lt;br /&gt;
|  [[NIST:CVE-2009-3964 | CVE-2009-3964]]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |'''  [http://ninjaforge.com/index.php?option=com_ninjacentral&amp;amp;page=show_package&amp;amp;id=14&amp;amp;Itemid=235 developer patch Ver 1.2]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   | '''webee 1.1.1 &amp;amp;1.2'''&lt;br /&gt;
|Summary: '''webee 1.1.1,''' a Joomla commenting plugin, suffers from multiple vulnerabilities. '''webee has been updated to 1.2''' as of 12 November 2009 and''' still suffers''' from SQL Injection. XSS was not tested in 1.2. Added 19 November 2009&lt;br /&gt;
| [http://jeffchannell.com/Joomla/webee-111-multiple-vulnerabilities.html jeffchannell.com]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | ''' [http://extensions.joomla.org/extensions/contacts-and-feedback/articles-comments/10155 developer update ver2.0]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''iF Portfolio Nexus'''&lt;br /&gt;
|Summary: The '''iF Portfolio Nexus component for Joomla!''' is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements using the id parameter, which could allow the attacker to view, add, modify or delete information in the back-end database. Nov 18, 2009&lt;br /&gt;
|[http://secunia.com/advisories/37408/ secunia.com 37408/]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; |[http://www.inertialfate.za.net/help/forums/topic?id=10&amp;amp;p=3#p172 iF Portfolio Nexus v1.1.1 released]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''JoomClip'''&lt;br /&gt;
|Summary: The '''JoomClip component for Joomla!''' is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements to the index.php script using the cat parameter, which could allow the attacker to view, add, modify or delete information in the back-end database.  Nov 18, 2009&lt;br /&gt;
|[http://secunia.com/advisories/37400/ secunia.com 37400/]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''Joomla XML'''&lt;br /&gt;
|Summary: Joomla! before 1.5.15 allows remote attackers to read an extension's XML file, and thereby obtain the extension's version number, via a direct request.&lt;br /&gt;
Published: 11/16/2009&lt;br /&gt;
|[[NIST:CVE-2009-3946 | CVE-2009-3946]] &lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |'''[http://developer.joomla.org/security/news/306-20091103-core-xml-file-read-issue.html Resolution]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Mygallery Remote SQL Injection Vulnerability''' &lt;br /&gt;
|Summary: Joomla Component mygallery ( farbinform_krell) Remote SQL Injection Vulnerability Added 27 Nov 2009 {{JVer|1.5}} NB: This could be an error in our database as the only one we could find was for wordpress.If anyone know of one for joomla please let us know..(poss joomlicious.com CM)&lt;br /&gt;
|[http://www.exploit-db.com] &lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Extreme Google Calendar'''&lt;br /&gt;
|Summary: '''com_gcalendar 1.1.2''' (gcid) Remote SQL Injection Vulnerability&lt;br /&gt;
Remote SQL Injection were identified in Google Calendar Component [http://extensions.joomla.org/extensions/calendars-a-events/calendars/4188 Extension Link] Added 27 Nov 2009 &lt;br /&gt;
|[http://www.exploit-db.com reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''LyftenBloggie'''&lt;br /&gt;
| Summary: [http://www.lyften.com/products/lyftenbloggie.html LyftenBloggie] Component &amp;quot;author&amp;quot; SQL Injection Vulnerability LyftenBloggie 1.x Added 27 Nov 2009&lt;br /&gt;
|[http://secunia.com/advisories/product/28005/	 SA37499]&lt;br /&gt;
| [http://jeffchannell.com/Joomla/lyften-bloggie-sql-injection-fix.html Un official fix]. Developer fix not release at 30 Nov 09 ''' [http://www.lyften.com/products/lyftenbloggie/extensions/download/id-20.html 1.0.4a (last update on Dec 28, 2009)]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''Sermon speaker'''&lt;br /&gt;
|Summary: [http://joomlacode.org/gf/project/sermon_speaker sermon speaker] sql vulnerability and password reset vulnerability version 3.2 and below&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |[http://joomlacode.org/gf/project/sermon_speaker/forum/?action=ForumBrowse&amp;amp;forum_id=7897&amp;amp;_forum_action=ForumMessageBrowse&amp;amp;thread_id=15219 Developer fix] 30 Nov 2009&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | [http://joomlacode.org/gf/project/musicgallery/ MusicGallery]&lt;br /&gt;
|Summary: [http://joomlacode.org/gf/project/musicgallery/ Component MusicGallery] SQL Injection Vulnerability 30 November {{JVer|1.5}}&lt;br /&gt;
|[[NIST:CVE-2009-4217 | CVE-2009-4217]]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; | [http://joomlacode.org/gf/project/musicgallery/ developer]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== December 2009 Compiled Reports ==&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  '''Extension'''&lt;br /&gt;
! class=&amp;quot;unsortable&amp;quot;| '''Details'''&lt;br /&gt;
!  '''Reference Link'''&lt;br /&gt;
!  '''Extension Update Link'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Omilen Photo Gallery'''&lt;br /&gt;
|Summary: Directory traversal vulnerability in the [http://extensions.joomla.org/extensions/photos-&amp;amp;-images/photo-flash-gallery/6373/details Omilen Photo Gallery] (com_omphotogallery) component Beta 0.5 for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the controller parameter to index.php.&lt;br /&gt;
Published: 12/04/2009&lt;br /&gt;
|[[NIST:CVE-2009-4202 | CVE-2009-4202]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Seminar'''&lt;br /&gt;
|Summary: SQL injection vulnerability in the [http://seminar.vollmar.ws/ Seminar] (com_seminar) component 1.28 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a View_seminar action to index.php.&lt;br /&gt;
Published: 12/04/2009&lt;br /&gt;
|[[NIST:CVE-2009-4200 | CVE-2009-4200]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''Mambo Resident'''&lt;br /&gt;
|Summary: Multiple SQL injection vulnerabilities in the Mambo Resident (aka Mos Res or com_mosres) component 1.0f for Mambo and Joomla!, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) property_uid parameter in a viewproperty action to index.php and the (2) regID parameter in a showregion action to index.php. Mambo Resident component for v4.5.2 '''may only be for 1.0.xx versions of J!'''&lt;br /&gt;
Published: 12/04/2009&lt;br /&gt;
|[[NIST:CVE-2009-4199 | CVE-2009-4199]]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; |[http://www.jomres.net/ Replacement Extension 08 dec 09]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''ProofReader''' &lt;br /&gt;
|Summary: Multiple cross-site scripting (XSS) vulnerabilities in index.php in the ProofReader (com_proofreader) component 1.0 RC9 and earlier for Joomla! allow remote attackers to inject arbitrary web script or HTML via the URI, which is not properly handled in (1) 404 or (2) error pages. Published: 12/02/2009 CVSS Severity: 4.3 (MEDIUM)&lt;br /&gt;
| [[NIST:CVE-2009-4157 | CVE-2009-4157]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''Laoneo Google Calendar GCalendar'''&lt;br /&gt;
|Summary: SQL injection vulnerability in the [http://g4j.laoneo.net/content/extensions/download/cat_view/20-joomla-15x/21-gcalendar.html Google Calendar GCalendar] (com_gcalendar) component 1.1.2, 2.1.4, and possibly earlier versions for Joomla! allows remote attackers to execute arbitrary SQL commands via the gcid parameter. NOTE: some of these details are obtained from third party information. Published: 11/29/2009 CVSS Severity: 7.5 (HIGH) Note: There is already a listing for GCalendar 1.1.2&lt;br /&gt;
|[[NIST:CVE-2009-4099 | CVE-2009-4099]]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;   | [http://g4j.laoneo.net/content/extensions/download/doc_details/28-gcalendar-suite-215.html Latest version GCalendar Suite 2.1.5]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''D4J eZine'''&lt;br /&gt;
|Summary: PHP remote file inclusion vulnerability in class/php/d4m_ajax_pagenav.php in the D4J eZine (com_ezine) component 2.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS mosConfig_absolute_path parameter. Published: 11/29/2009 CVSS Severity: 7.5 (HIGH)&lt;br /&gt;
|[[NIST:CVE-2009-4094 | CVE-2009-4094]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''Quick News'''&lt;br /&gt;
| Summary: The Joomla [http://joomlacode.org/gf/project/quicknews/ Quick News component] suffers from a remote SQL injection vulnerability. added 1st Dec 09&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''Joaktree component'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/miscellaneous/genealogy/9842 Joaktree] Vulnerability : SQL injection/ added 1st Dec 09&lt;br /&gt;
|[http://securityreason.com/exploitalert/7508 7508]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | '''  [http://naastniels.nl/index.php/en/joaktree/downloads version 1.1 update]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''mojoblog'''&lt;br /&gt;
|Summary [http://www.joomlify.com/files/mojoblog/ MojoBlog] Multiple Remote File Include Vulnerability added 1st Dec 09 {{JVer|1.5}}&lt;br /&gt;
|[http://securityreason.com/exploitalert/7509 7509]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''YJ Whois''' &lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/external-contents/domain-search/5774 YJ Whois] '''Low security risk''',and fixesMalicious users may inject JavaScript, VBScript, ActiveX, HTML or Flash into a vulnerable application to fool a user in order to gather data from them. An attacker can steal the session cookie and take over the account. Files affected is , modules/mod_yj_whois.php added 3 December 09&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; |[http://www.youjoomla.com/xss-security-patch-for-yj-whois.html Developer Notice and fix 03 dec 09]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; | '''yt_color YOOOtheme'''&lt;br /&gt;
|Summary: [http://www.yootheme.com/ YT_color yootheme] Malicious users may inject JavaScript, VBScript, ActiveX, HTML or Flash into a vulnerable application to fool a user in order to gather data from them. An attacker can steal the session cookie and take over the account. added 5 dec 09&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | '''  [http://www.yootheme.com/member-area/downloads/item/templates-15/xss-and-php-53-patches All members without an active membership can download the template patches here].'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''TP Whois''' &lt;br /&gt;
|summary: [http://www.templateplazza.com/view-details/tpwhois/183-component-tp-whois-for-joomla-1.5.x.html TP Whois ] Malicious users may inject JavaScript, VBScript, ActiveX, HTML or Flash into a vulnerable application to fool a user in order to gather data from them. An attacker can steal the session cookie and take over the account. Added 3 december {{JVer|1.5}}&lt;br /&gt;
|[http://www.exploit-db.com Refrence]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''com_job'''&lt;br /&gt;
|Summary: Component com_job ( showMoreUse) SQL injection vulnerability  Added 9th Dec&lt;br /&gt;
|[http://xforce.iss.net/xforce/xfdb/54626 Reference]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |  '''JQuarks''' &lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/contacts-and-feedback/quiz-a-surveys/10590 JQuarks] SQL injection vulnerability {{JVer|1.5}} added 8th dec 09&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | [http://www.iptechinside.com/labs/projects/list_files/jquarks Developer Update ]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''Mamboleto Component 2.0 RC3'''&lt;br /&gt;
|Summary: [http://www.fernandosoares.com.br/index.php?option=com_docman&amp;amp;task=cat_view&amp;amp;gid=28&amp;amp;Itemid=28 Mamboleto Component 2.0 RC3]SQL injection vulnerability {{JVer|1.5}} added 12 December&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |  ''' JS JOBS'''&lt;br /&gt;
|Summary [http://www.joomshark.com/index.php?option=com_content&amp;amp;view=article&amp;amp;id=4&amp;amp;Itemid=8 JS JOBS] Joomla Component com_jsjobs 1.0.5.6 SQL Injection Vulnerabilities {{JVer|1.5}} added 12 December&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | '''  [http://www.joomsky.com/index.php?option=com_rokdownloads&amp;amp;view=folder&amp;amp;Itemid=3&amp;amp;id=2:components Developer update 1.0.5.7]''' &lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |  '''corePHP JPhoto'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/photos-a-images/photo-gallery/10365 'corePHP' JPhoto]SQL injection vulnerability {{JVer|1.5}} added 12 December&lt;br /&gt;
|[http://secunia.com/advisories/37676/ Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | '''  [http://www.corephp.com/blog/uber-fast-jphoto-security-release/ Developer Upgrade]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;    | '''com_virtuemart'''&lt;br /&gt;
|Summary: &amp;quot;com_virtuemart&amp;quot; http://virtuemart.net/  '''Version : 1.0''' Vulnerability : SQL injection added Date : 07- dec -09 {{JVer|1.5}}&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |[http://virtuemart.net/ latest version]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | ''' Kide Shoutbox'''&lt;br /&gt;
&lt;br /&gt;
|Summary: The Kide Shoutbox (com_kide) component 0.4.6 for Joomla! does not properly perform authentication, which allows remote attackers to post messages with an arbitrary account name via an insertar action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Added: December 08&lt;br /&gt;
|[[NIST:CVE-2009-4232 | CVE-2009-4232]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | ''' JoomPortfolio Component'''&lt;br /&gt;
|Summary: [http://www.joomplace.com/joomportfolio/joomportfolio.html JoomPortfolio] Input passed via the &amp;quot;secid&amp;quot; parameter to index.php (when &amp;quot;option&amp;quot; is set to &amp;quot;com_joomportfolio&amp;quot; and &amp;quot;task&amp;quot; is set to &amp;quot;showcat&amp;quot;) is not properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.The vulnerability is reported in version 1.0.0. Other versions may also be affected. Added: December 18 {{JVer|1.5}}&lt;br /&gt;
|[http://secunia.com/advisories/37838/ Reporting Site]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''City Portal (templates?)'''&lt;br /&gt;
|Summary:   City Portal Blind SQL Injection Vulnerability added: 2009-12-18&lt;br /&gt;
|[http://www.exploit-db.com Reference] Possibly this [http://www.youjoomla.com/jclick-city-portal-joomla-template.html tempate]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''Event Manager'''&lt;br /&gt;
|Summary:  [http://www.jforjoomla.com/Joomla-Components/event-manager-15-component.html Event Manager] Blind SQL Injection Vulnerability EDB-ID: 10549&lt;br /&gt;
added: 2009-12-18&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | com_zcalendar&lt;br /&gt;
|Summary:  com_zcalendar Blind SQL-injection Vulnerability&lt;br /&gt;
EDB-ID: 10548 added: 2009-12-18&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''com_acmisc'''&lt;br /&gt;
|Summary:  com_acmisc SQL injection added: 2009-12-18&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''com_digistore'''&lt;br /&gt;
|Summary:  com_digistore SQL injection EDB-ID: 10546 added: 2009-12-18  {{JVer|1.5}}&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | '''  [http://www.ijoomla.com/ijoomla-digistore/ijoomla-digistore/ijoomla-digistore-change-log/ Update change log] '''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''com_jbook'''&lt;br /&gt;
|Summary:   com_jbook Blind SQL-injection EDB-ID: 10545 added: 2009-12-18 {{JVer|1.0}}&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |  '''com_personel'''&lt;br /&gt;
|Summary: com_personel component for Joomla! is vulnerable to SQL injection.&lt;br /&gt;
|[http://xforce.iss.net/xforce/xfdb/54903 iss.net reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |  '''JEEMA Article Collection'''&lt;br /&gt;
|Summary: [http://www.forum.jeema.net/component/content/article/4-jeema-article-collection-component/13-about-jeema-article-collection.html JEEMA Article Collection] Input passed via the &amp;quot;catid&amp;quot; parameter to index.php (when &amp;quot;option&amp;quot; is set to &amp;quot;com_jeemaarticlecollection&amp;quot; and &amp;quot;view&amp;quot; is set to &amp;quot;longlook&amp;quot;) is not properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. version 1.0.0.1 {{JVer|1.5}} added 22 dec 09&lt;br /&gt;
| [http://secunia.com/advisories/37865/ secunia]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;    | [http://www.jeema.net/downloads/free-joomla-extensions/joomla-components/12-jeema-joomla-article-collection.htm fixed the same in the version v102.]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |  '''HotBrackets Tournament Brackets '''&lt;br /&gt;
|Summary: The [http://extensions.joomla.org/extensions/sports-a-games/sports/10746 HotBrackets Tournament Brackets] component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. {{JVer|1.5}} added 22 dec &lt;br /&gt;
|[http://www.securityfocus.com/bid/37439/ Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''Car Manager'''&lt;br /&gt;
|Summary: http://webformatique.com/ com_carman Cross Site Scripting Vulnerability added 24 december 09{{JVer|1.5}}&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot; |'''Schools component'''&lt;br /&gt;
|Summary: The 'com_schools' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.&lt;br /&gt;
|[http://www.securityfocus.com/bid/37469 Reference] added 24 dec 09&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''webcamxp'''&lt;br /&gt;
|[http://extensions.joomla.org/extensions/communication/video-conference/4490 com_webcamxp] Cross Site Scripting Vulnerabilities  Last version 2008 {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''beeheard'''&lt;br /&gt;
|[http://extensions.joomla.org/extensions/contacts-and-feedback/testimonials-a-suggestions/10283 beeheard]  Blind SQL injection Vulnerability {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | '''  [http://beeheard.cmstactics.com/change-log Version 1.4.2] 04 Jan'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''jm-recommend'''&lt;br /&gt;
|jm-recommendCross Site Scripting Vulnerabilities. unable to locate on jed. {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | facileforms&lt;br /&gt;
| com_facileforms Cross Site Scripting Vulnerabilities. unable to locate on jed. Product considered retired.  {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''adagency'''&lt;br /&gt;
| [http://www.ijoomla.com/ijoomla-ad-agency/ijoomla-ad-agency/index/ adagency ]Vulnerabilities {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |  '''com_intuit'''&lt;br /&gt;
|[http://www.san-diego-web-designer.com/new-file-download/item/root/aboutimage-igateway-for-joomla.html com_intuit]Local File Inclusion Vulnerability {{JVer|1.5}} Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | '''  [http://www.securityfocus.com/bid/37494/discuss Retired]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''MemoryBook'''&lt;br /&gt;
|[http://extensions.joomla.org/extensions/calendars-a-events/birthdays-a-historic-events/10868 MemoryBook 1.2]  Multiple Vulnerabilities. requires: magic quotes OFF, user account {{JVer|1.5}} Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''qpersonel'''&lt;br /&gt;
|[http://extensions.joomla.org/extensions/directory-a-documentation/thematic-directory/7049 qpersonel ] Cross Site Scripting Vulnerabilities {{JVer|1.0}}[[Image:http://extensions.joomla.org/images/jed/compat_15_legacy.png]] Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''opryknings point''' &lt;br /&gt;
|com_oprykningspoint_mc Cross Site Scripting Vulnerabilities {{JVer|1.5}} Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''trabalhe conosco'''&lt;br /&gt;
|com_trabalhe_conosco Cross Site Scripting Vulnerabilities {{JVer|1.5}} Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''DhForum'''&lt;br /&gt;
|com_dhforum SQL Injection Vulnerability. considered retired/EOL Dec. 27 {{JVer|1.0}}1.5 legacy&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |'''com_morfeoshow'''&lt;br /&gt;
|[http://extensions.joomla.org/extensions/photos-a-images/photo-gallery-add-ons/9810 morfeoshow] this was a false report &lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''  false report'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''Run Digital Download rd-download''' &lt;br /&gt;
|[http://extensions.joomla.org/extensions/directory-a-documentation/downloads/7838 RD Download] Local File Disclosure Vulnerability  {{JVer|1.5}} Dec. 30 Version affected not disclosed.&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | [http://extensions.joomla.org/extensions/directory-a-documentation/downloads/7838 Version 0.9 relased] &lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|}&lt;br /&gt;
== November 2009 Compiled Vulnerability Reports. RESOLVED ONLY  ==&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
Items are not in any particular order.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  '''Extension'''&lt;br /&gt;
! class=&amp;quot;unsortable&amp;quot;| '''Details'''&lt;br /&gt;
!  '''Reference Link'''&lt;br /&gt;
!  '''Extension Update Link'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_djcatalog'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the DJ-Catalog ('''com_djcatalog''') component for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a showItem action and (2) cid parameter in a show action to index.php.&lt;br /&gt;
Published: 10/11/2009&lt;br /&gt;
CVSS Severity: 6.8 (MEDIUM)&lt;br /&gt;
|  [[NIST:CVE-2009-3661|CVE-2009-3661]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  |  '''com_soundset'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Soundset ('''com_soundset''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter to index.php.&lt;br /&gt;
Published: 10/09/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3644|CVE-2009-3644]]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  |  '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  |'''com_sportfusion'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Kinfusion SportFusion ('''com_sportfusion''') component 0.2.2 through 0.2.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid[0] parameter in a teamdetail action to index.php.&lt;br /&gt;
Published: 09/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3491|CVE-2009-3491]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  |'''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_icrmbasic'''&lt;br /&gt;
|  Summary: A certain interface in the iCRM Basic ('''com_icrmbasic''') component 1.4.2.31 for Joomla! does not require administrative authentication, which has unspecified impact and remote attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 09/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3481|CVE-2009-3481]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_mytube'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the MyRemote Video Gallery ('''com_mytube''') component 1.0 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter in a videos action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3446|CVE-2009-3446]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|   '''com_facebook'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the JoomlaFacebook ('''com_facebook''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a student action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3438|CVE-2009-3438]]&lt;br /&gt;
|   [http://extensions.joomla.org/extensions/4446/details JED entry.] [http://forge.joomla.org/gf/project/joomla-facebook/ Download site] Developer states reports not proven 24/07/10&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_tupinambis'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Tupinambis ('''com_tupinambis''') component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the proyecto parameter in a verproyecto action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3434|CVE-2009-3434]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_hbssearch'''&lt;br /&gt;
|  Summary: Cross-site scripting ('''XSS''') vulnerability in the Hotel Booking Reservation System ('''aka HBS or com_hbssearch''') component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the adult parameter in a showhoteldetails action to index.php.&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 4.3 ('''MEDIUM''')&lt;br /&gt;
|  [[NIST:CVE-2009-3368|CVE-2009-3368]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_hbssearch'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System ('''aka HBS or com_hbssearch''') component for Joomla! allow remote attackers to execute arbitrary SQL commands via the ('''1''') h_id, ('''2''') id, and ('''3''') rid parameters to longDesc.php, and the h_id parameter to ('''4''') detail.php, ('''5''') detail1.php, ('''6''') detail2.php, ('''7''') detail3.php, ('''8''') detail4.php, ('''9''') detail5.php, ('''10''') detail6.php, ('''11''') detail7.php, and ('''12''') detail8.php, different vectors than [[NIST:CVE-2008-5865|CVE-2008-5865]], [[NIST:CVE-2008-5874|CVE-2008-5874]], and [[NIST:CVE-2008-5875|CVE-2008-5875]].&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3357|CVE-2009-3357]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''TurtuShout'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the TurtuShout component 0.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Name field.&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3335|CVE-2009-3335]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jinc'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Lhacky! Extensions Cave Joomla! Integrated Newsletters Component ('''aka JINC or com_jinc''') component 0.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a messages action to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3334|CVE-2009-3334]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_surveymanager'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Focusplus Developments Survey Manager ('''com_surveymanager''') component 1.5.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the stype parameter in an editsurvey action to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3325|CVE-2009-3325]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_album'''&lt;br /&gt;
|  Summary: Directory traversal vulnerability in the Roland Breedveld Album ('''com_album''') component 1.14 for Joomla! allows remote attackers to access arbitrary directories and have unspecified other impact via a .. ('''dot dot''') in the target parameter to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3318|CVE-2009-3318]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''IXXO Cart Standalone'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in IXXO Cart Standalone before 3.9.6.1, and the IXXO Cart component for Joomla! 1.0.x, allows remote attackers to execute arbitrary SQL commands via the parent parameter.&lt;br /&gt;
Published: 09/16/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3215|CVE-2009-3215]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_digifolio'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the DigiFolio ('''com_digifolio''') component 1.52 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a project action to index.php.&lt;br /&gt;
Published: 09/15/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3193|CVE-2009-3193]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_aclassf'''&lt;br /&gt;
|  Summary: Cross-site scripting ('''XSS''') vulnerability in '''gmap.php''' in the Almond Classifieds ('''com_aclassf''') component 7.5 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the addr parameter.&lt;br /&gt;
Published: 09/10/2009&lt;br /&gt;
CVSS Severity: 4.3 ('''MEDIUM''')&lt;br /&gt;
|  [[NIST:CVE-2009-3155|CVE-2009-3155]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;   | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jabode'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in Jabode horoscope extension ('''com_jabode''') for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a sign task to index.php.&lt;br /&gt;
Published: 09/08/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
&lt;br /&gt;
|  [[NIST:CVE-2008-7169|CVE-2008-7169]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_gameserver'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Game Server ('''com_gameserver''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a gamepanel action to index.php.&lt;br /&gt;
Published: 09/03/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3063|CVE-2009-3063]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_artportal'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Artetics.com Art Portal ('''com_artportal''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the portalid parameter to index.php.&lt;br /&gt;
Published: 09/03/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3054|CVE-2009-3054]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_simpleshop'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Simple Shop Galore ('''com_simpleshop''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the section parameter in a section action to index.php, a different vulnerability than [[NIST:CVE-2008-2568|CVE-2008-2568]]. NOTE: this issue was disclosed by an unreliable researcher, so the details might be incorrect.&lt;br /&gt;
Published: 08/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-7033|CVE-2008-7033]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_groups'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Permis ('''com_groups''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a list action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 08/17/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-2789|CVE-2009-2789]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Live Chat ('''com_livechat''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the last parameter to getChatRoom.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6883|CVE-2008-6883]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: Live Chat ('''com_livechat''') component 1.0 for Joomla! allows remote attackers to use the xmlhttp.php script as an open HTTP proxy to hide network scanning activities or scan internal networks via a GET request with a full URL in the query string.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6882|CVE-2008-6882]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the Live Chat ('''com_livechat''') component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the last parameter to ('''1''') getChat.php, ('''2''') getChatRoom.php, and ('''3''') getSavedChatRooms.php.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6881|CVE-2008-6881]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jshop'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the JShop ('''com_jshop''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a product action to index.php.&lt;br /&gt;
Published: 11/02/2009&lt;br /&gt;
CVSS Severity: 7.5 '''(HIGH)''' &lt;br /&gt;
|  [[NIST:CVE-2009-3835|CVE-2009-3835]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;| '''EasyBook 2.0.0rc4'''&lt;br /&gt;
|  Summary: The Joomla component '''EasyBook 2.0.0rc4''' suffers from multiple persistent XSS vulnerabilities. One seems fairly critical, while the others would take some incredible creativity to actively exploit. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/easybook-200rc4-multiple-xss-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:#cef2e0; color:black&amp;quot;| '''  &lt;br /&gt;
[http://www.kubik-rubik.de/joomla-hilfe/komponente-easybook-reloaded-joomla easybook reloaded released]&lt;br /&gt;
'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''F!BB 1.5.96''' &lt;br /&gt;
|  Summary: The Joomla component '''F!BB 1.5.96 RC''' suffers from multiple persistent XSS vulnerabilities, as well SQL Injection in its user search feature. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/fbb-1596-rc-multiple-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Testimonial Ku 2.0 Admin Panel'''&lt;br /&gt;
|  Summary: The Joomla component '''Testimonial Ku 2.0''' is vulnerable to persistent XSS in the administrator panel. A malicious user can submit a testimonial containing &amp;lt;script&amp;gt; tags with absolutely no quotes and inject that script into the administrator panel through any of the available inputs except &amp;quot;email&amp;quot;. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/testimonial-ku-20-admin-panel-persistent-xss.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''MS Comment 0.8.0b'''&lt;br /&gt;
|  Summary '''MS Comment 0.8.0b for Joomla''', a commenting plugin, suffers from an multiple vulnerabilities. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/ms-comment-080b-multiple-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''WebAmoeba Ticket System 3.0.0'''&lt;br /&gt;
|  Summary:  '''WebAmoeba Ticket System 3.0.0''', a Joomla help desk component. The vulnerability is with the BBCode library used to parse BBCode tags, as it does not strip javascript: urls from [url] tags. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/webamoeba-ticket-system-300-bbcode-xss.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_siirler'''&lt;br /&gt;
|  Summary:  SQL injection vulnerability in the '''Q-Proje Siirler Bileseni (com_siirler)''' component 1.2 RC for Joomla! allows remote attackers to execute arbitrary SQL commands via the sid parameter in an sdetay action to index.php. Added 18 November 2009&lt;br /&gt;
|  [[NIST:CVE-2009-3972 | CVE-2009-3972]]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''jTips (com_jtips)'''&lt;br /&gt;
|SUmmary:SQL injection vulnerability in the '''jTips (com_jtips)''' component 1.0.7 and 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the season parameter in a ladder action to index.php. Added 18 November 2009&lt;br /&gt;
| [[NIST:CVE-2009-3971 |CVE-2009-3971]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''JoomClip'''&lt;br /&gt;
|Summary: The '''JoomClip component for Joomla!''' is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements to the index.php script using the cat parameter, which could allow the attacker to view, add, modify or delete information in the back-end database.  Nov 18, 2009&lt;br /&gt;
|[http://secunia.com/advisories/37400/ secunia.com 37400/]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Mygallery Remote SQL Injection Vulnerability''' &lt;br /&gt;
|Summary: Joomla Component mygallery ( farbinform_krell) Remote SQL Injection Vulnerability Added 27 Nov 2009 {{JVer|1.5}} NB: This could be an error in our database as the only one we could find was for wordpress.If anyone know of one for joomla please let us know..(poss joomlicious.com CM)&lt;br /&gt;
|[http://www.exploit-db.com] &lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Extreme Google Calendar'''&lt;br /&gt;
|Summary: '''com_gcalendar 1.1.2''' (gcid) Remote SQL Injection Vulnerability&lt;br /&gt;
Remote SQL Injection were identified in Google Calendar Component [http://extensions.joomla.org/extensions/calendars-a-events/calendars/4188 Extension Link] Added 27 Nov 2009 &lt;br /&gt;
|[http://www.exploit-db.com reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''LyftenBloggie'''&lt;br /&gt;
| Summary: [http://www.lyften.com/products/lyftenbloggie.html LyftenBloggie] Component &amp;quot;author&amp;quot; SQL Injection Vulnerability LyftenBloggie 1.x Added 27 Nov 2009&lt;br /&gt;
|[http://secunia.com/advisories/product/28005/	 SA37499]&lt;br /&gt;
| [http://jeffchannell.com/Joomla/lyften-bloggie-sql-injection-fix.html Un official fix]. Developer fix not release at 30 Nov 09 ''' [http://www.lyften.com/products/lyftenbloggie/extensions/download/id-20.html 1.0.4a (last update on Dec 28, 2009)]'''&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== November 2009 Compiled Vulnerability Reports. ==&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
Items are not in any particular order.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  '''Extension'''&lt;br /&gt;
! class=&amp;quot;unsortable&amp;quot;| '''Details'''&lt;br /&gt;
!  '''Reference Link'''&lt;br /&gt;
!  '''Extension Update Link'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_djcatalog'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the DJ-Catalog ('''com_djcatalog''') component for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a showItem action and (2) cid parameter in a show action to index.php.&lt;br /&gt;
Published: 10/11/2009&lt;br /&gt;
CVSS Severity: 6.8 (MEDIUM)&lt;br /&gt;
|  [[NIST:CVE-2009-3661|CVE-2009-3661]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  |  '''com_soundset'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Soundset ('''com_soundset''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter to index.php.&lt;br /&gt;
Published: 10/09/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3644|CVE-2009-3644]]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  |  '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  |'''com_sportfusion'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Kinfusion SportFusion ('''com_sportfusion''') component 0.2.2 through 0.2.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid[0] parameter in a teamdetail action to index.php.&lt;br /&gt;
Published: 09/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3491|CVE-2009-3491]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  |'''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_icrmbasic'''&lt;br /&gt;
|  Summary: A certain interface in the iCRM Basic ('''com_icrmbasic''') component 1.4.2.31 for Joomla! does not require administrative authentication, which has unspecified impact and remote attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 09/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3481|CVE-2009-3481]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_mytube'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the MyRemote Video Gallery ('''com_mytube''') component 1.0 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter in a videos action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3446|CVE-2009-3446]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|   '''com_facebook'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the JoomlaFacebook ('''com_facebook''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a student action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3438|CVE-2009-3438]]&lt;br /&gt;
|   [http://extensions.joomla.org/extensions/4446/details JED entry.] [http://forge.joomla.org/gf/project/joomla-facebook/ Download site] Developer states reports not proven 24/07/10&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_tupinambis'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Tupinambis ('''com_tupinambis''') component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the proyecto parameter in a verproyecto action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3434|CVE-2009-3434]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_hbssearch'''&lt;br /&gt;
|  Summary: Cross-site scripting ('''XSS''') vulnerability in the Hotel Booking Reservation System ('''aka HBS or com_hbssearch''') component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the adult parameter in a showhoteldetails action to index.php.&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 4.3 ('''MEDIUM''')&lt;br /&gt;
|  [[NIST:CVE-2009-3368|CVE-2009-3368]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_hbssearch'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System ('''aka HBS or com_hbssearch''') component for Joomla! allow remote attackers to execute arbitrary SQL commands via the ('''1''') h_id, ('''2''') id, and ('''3''') rid parameters to longDesc.php, and the h_id parameter to ('''4''') detail.php, ('''5''') detail1.php, ('''6''') detail2.php, ('''7''') detail3.php, ('''8''') detail4.php, ('''9''') detail5.php, ('''10''') detail6.php, ('''11''') detail7.php, and ('''12''') detail8.php, different vectors than [[NIST:CVE-2008-5865|CVE-2008-5865]], [[NIST:CVE-2008-5874|CVE-2008-5874]], and [[NIST:CVE-2008-5875|CVE-2008-5875]].&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3357|CVE-2009-3357]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''TurtuShout'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the TurtuShout component 0.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Name field.&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3335|CVE-2009-3335]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jinc'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Lhacky! Extensions Cave Joomla! Integrated Newsletters Component ('''aka JINC or com_jinc''') component 0.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a messages action to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3334|CVE-2009-3334]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_surveymanager'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Focusplus Developments Survey Manager ('''com_surveymanager''') component 1.5.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the stype parameter in an editsurvey action to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3325|CVE-2009-3325]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_album'''&lt;br /&gt;
|  Summary: Directory traversal vulnerability in the Roland Breedveld Album ('''com_album''') component 1.14 for Joomla! allows remote attackers to access arbitrary directories and have unspecified other impact via a .. ('''dot dot''') in the target parameter to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3318|CVE-2009-3318]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''IXXO Cart Standalone'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in IXXO Cart Standalone before 3.9.6.1, and the IXXO Cart component for Joomla! 1.0.x, allows remote attackers to execute arbitrary SQL commands via the parent parameter.&lt;br /&gt;
Published: 09/16/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3215|CVE-2009-3215]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_digifolio'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the DigiFolio ('''com_digifolio''') component 1.52 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a project action to index.php.&lt;br /&gt;
Published: 09/15/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3193|CVE-2009-3193]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_aclassf'''&lt;br /&gt;
|  Summary: Cross-site scripting ('''XSS''') vulnerability in '''gmap.php''' in the Almond Classifieds ('''com_aclassf''') component 7.5 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the addr parameter.&lt;br /&gt;
Published: 09/10/2009&lt;br /&gt;
CVSS Severity: 4.3 ('''MEDIUM''')&lt;br /&gt;
|  [[NIST:CVE-2009-3155|CVE-2009-3155]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;   | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jabode'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in Jabode horoscope extension ('''com_jabode''') for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a sign task to index.php.&lt;br /&gt;
Published: 09/08/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
&lt;br /&gt;
|  [[NIST:CVE-2008-7169|CVE-2008-7169]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_gameserver'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Game Server ('''com_gameserver''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a gamepanel action to index.php.&lt;br /&gt;
Published: 09/03/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3063|CVE-2009-3063]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_artportal'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Artetics.com Art Portal ('''com_artportal''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the portalid parameter to index.php.&lt;br /&gt;
Published: 09/03/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3054|CVE-2009-3054]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_simpleshop'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Simple Shop Galore ('''com_simpleshop''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the section parameter in a section action to index.php, a different vulnerability than [[NIST:CVE-2008-2568|CVE-2008-2568]]. NOTE: this issue was disclosed by an unreliable researcher, so the details might be incorrect.&lt;br /&gt;
Published: 08/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-7033|CVE-2008-7033]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_groups'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Permis ('''com_groups''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a list action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 08/17/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-2789|CVE-2009-2789]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Live Chat ('''com_livechat''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the last parameter to getChatRoom.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6883|CVE-2008-6883]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: Live Chat ('''com_livechat''') component 1.0 for Joomla! allows remote attackers to use the xmlhttp.php script as an open HTTP proxy to hide network scanning activities or scan internal networks via a GET request with a full URL in the query string.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6882|CVE-2008-6882]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the Live Chat ('''com_livechat''') component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the last parameter to ('''1''') getChat.php, ('''2''') getChatRoom.php, and ('''3''') getSavedChatRooms.php.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6881|CVE-2008-6881]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jshop'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the JShop ('''com_jshop''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a product action to index.php.&lt;br /&gt;
Published: 11/02/2009&lt;br /&gt;
CVSS Severity: 7.5 '''(HIGH)''' &lt;br /&gt;
|  [[NIST:CVE-2009-3835|CVE-2009-3835]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;| '''EasyBook 2.0.0rc4'''&lt;br /&gt;
|  Summary: The Joomla component '''EasyBook 2.0.0rc4''' suffers from multiple persistent XSS vulnerabilities. One seems fairly critical, while the others would take some incredible creativity to actively exploit. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/easybook-200rc4-multiple-xss-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:#cef2e0; color:black&amp;quot;| '''  &lt;br /&gt;
[http://www.kubik-rubik.de/joomla-hilfe/komponente-easybook-reloaded-joomla easybook reloaded released]&lt;br /&gt;
'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''F!BB 1.5.96''' &lt;br /&gt;
|  Summary: The Joomla component '''F!BB 1.5.96 RC''' suffers from multiple persistent XSS vulnerabilities, as well SQL Injection in its user search feature. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/fbb-1596-rc-multiple-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Testimonial Ku 2.0 Admin Panel'''&lt;br /&gt;
|  Summary: The Joomla component '''Testimonial Ku 2.0''' is vulnerable to persistent XSS in the administrator panel. A malicious user can submit a testimonial containing &amp;lt;script&amp;gt; tags with absolutely no quotes and inject that script into the administrator panel through any of the available inputs except &amp;quot;email&amp;quot;. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/testimonial-ku-20-admin-panel-persistent-xss.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''MS Comment 0.8.0b'''&lt;br /&gt;
|  Summary '''MS Comment 0.8.0b for Joomla''', a commenting plugin, suffers from an multiple vulnerabilities. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/ms-comment-080b-multiple-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''WebAmoeba Ticket System 3.0.0'''&lt;br /&gt;
|  Summary:  '''WebAmoeba Ticket System 3.0.0''', a Joomla help desk component. The vulnerability is with the BBCode library used to parse BBCode tags, as it does not strip javascript: urls from [url] tags. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/webamoeba-ticket-system-300-bbcode-xss.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_siirler'''&lt;br /&gt;
|  Summary:  SQL injection vulnerability in the '''Q-Proje Siirler Bileseni (com_siirler)''' component 1.2 RC for Joomla! allows remote attackers to execute arbitrary SQL commands via the sid parameter in an sdetay action to index.php. Added 18 November 2009&lt;br /&gt;
|  [[NIST:CVE-2009-3972 | CVE-2009-3972]]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''jTips (com_jtips)'''&lt;br /&gt;
|SUmmary:SQL injection vulnerability in the '''jTips (com_jtips)''' component 1.0.7 and 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the season parameter in a ladder action to index.php. Added 18 November 2009&lt;br /&gt;
| [[NIST:CVE-2009-3971 |CVE-2009-3971]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''JoomClip'''&lt;br /&gt;
|Summary: The '''JoomClip component for Joomla!''' is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements to the index.php script using the cat parameter, which could allow the attacker to view, add, modify or delete information in the back-end database.  Nov 18, 2009&lt;br /&gt;
|[http://secunia.com/advisories/37400/ secunia.com 37400/]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Mygallery Remote SQL Injection Vulnerability''' &lt;br /&gt;
|Summary: Joomla Component mygallery ( farbinform_krell) Remote SQL Injection Vulnerability Added 27 Nov 2009 {{JVer|1.5}} NB: This could be an error in our database as the only one we could find was for wordpress.If anyone know of one for joomla please let us know..(poss joomlicious.com CM)&lt;br /&gt;
|[http://www.exploit-db.com] &lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Extreme Google Calendar'''&lt;br /&gt;
|Summary: '''com_gcalendar 1.1.2''' (gcid) Remote SQL Injection Vulnerability&lt;br /&gt;
Remote SQL Injection were identified in Google Calendar Component [http://extensions.joomla.org/extensions/calendars-a-events/calendars/4188 Extension Link] Added 27 Nov 2009 &lt;br /&gt;
|[http://www.exploit-db.com reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''LyftenBloggie'''&lt;br /&gt;
| Summary: [http://www.lyften.com/products/lyftenbloggie.html LyftenBloggie] Component &amp;quot;author&amp;quot; SQL Injection Vulnerability LyftenBloggie 1.x Added 27 Nov 2009&lt;br /&gt;
|[http://secunia.com/advisories/product/28005/	 SA37499]&lt;br /&gt;
| [http://jeffchannell.com/Joomla/lyften-bloggie-sql-injection-fix.html Un official fix]. Developer fix not release at 30 Nov 09 ''' [http://www.lyften.com/products/lyftenbloggie/extensions/download/id-20.html 1.0.4a (last update on Dec 28, 2009)]'''&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== December 2009 Compiled Reports ==&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  '''Extension'''&lt;br /&gt;
! class=&amp;quot;unsortable&amp;quot;| '''Details'''&lt;br /&gt;
!  '''Reference Link'''&lt;br /&gt;
!  '''Extension Update Link'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Omilen Photo Gallery'''&lt;br /&gt;
|Summary: Directory traversal vulnerability in the [http://extensions.joomla.org/extensions/photos-&amp;amp;-images/photo-flash-gallery/6373/details Omilen Photo Gallery] (com_omphotogallery) component Beta 0.5 for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the controller parameter to index.php.&lt;br /&gt;
Published: 12/04/2009&lt;br /&gt;
|[[NIST:CVE-2009-4202 | CVE-2009-4202]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   | '''Seminar'''&lt;br /&gt;
|Summary: SQL injection vulnerability in the [http://seminar.vollmar.ws/ Seminar] (com_seminar) component 1.28 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a View_seminar action to index.php.&lt;br /&gt;
Published: 12/04/2009&lt;br /&gt;
|[[NIST:CVE-2009-4200 | CVE-2009-4200]]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   | '''  released V1.29, released'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''ProofReader''' &lt;br /&gt;
|Summary: Multiple cross-site scripting (XSS) vulnerabilities in index.php in the ProofReader (com_proofreader) component 1.0 RC9 and earlier for Joomla! allow remote attackers to inject arbitrary web script or HTML via the URI, which is not properly handled in (1) 404 or (2) error pages. Published: 12/02/2009 CVSS Severity: 4.3 (MEDIUM)&lt;br /&gt;
| [[NIST:CVE-2009-4157 | CVE-2009-4157]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''D4J eZine'''&lt;br /&gt;
|Summary: PHP remote file inclusion vulnerability in class/php/d4m_ajax_pagenav.php in the D4J eZine (com_ezine) component 2.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS mosConfig_absolute_path parameter. Published: 11/29/2009 CVSS Severity: 7.5 (HIGH)&lt;br /&gt;
|[[NIST:CVE-2009-4094 | CVE-2009-4094]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''Quick News'''&lt;br /&gt;
| Summary: The Joomla [http://joomlacode.org/gf/project/quicknews/ Quick News component] suffers from a remote SQL injection vulnerability. added 1st Dec 09&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''mojoblog'''&lt;br /&gt;
|Summary [http://www.joomlify.com/files/mojoblog/ MojoBlog] Multiple Remote File Include Vulnerability added 1st Dec 09 {{JVer|1.5}}&lt;br /&gt;
|[http://securityreason.com/exploitalert/7509 7509]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''TP Whois''' &lt;br /&gt;
|summary: [http://www.templateplazza.com/view-details/tpwhois/183-component-tp-whois-for-joomla-1.5.x.html TP Whois ] Malicious users may inject JavaScript, VBScript, ActiveX, HTML or Flash into a vulnerable application to fool a user in order to gather data from them. An attacker can steal the session cookie and take over the account. Added 3 december {{JVer|1.5}}&lt;br /&gt;
|[http://www.exploit-db.com Refrence]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''com_job'''&lt;br /&gt;
|Summary: Component com_job ( showMoreUse) SQL injection vulnerability  Added 9th Dec&lt;br /&gt;
|[http://xforce.iss.net/xforce/xfdb/54626 Reference]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''Mamboleto Component 2.0 RC3'''&lt;br /&gt;
|Summary: [http://www.fernandosoares.com.br/index.php?option=com_docman&amp;amp;task=cat_view&amp;amp;gid=28&amp;amp;Itemid=28 Mamboleto Component 2.0 RC3]SQL injection vulnerability {{JVer|1.5}} added 12 December&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | ''' Kide Shoutbox'''&lt;br /&gt;
|Summary: The Kide Shoutbox (com_kide) component 0.4.6 for Joomla! does not properly perform authentication, which allows remote attackers to post messages with an arbitrary account name via an insertar action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Added: December 08&lt;br /&gt;
|[[NIST:CVE-2009-4232 | CVE-2009-4232]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | ''' JoomPortfolio Component'''&lt;br /&gt;
|Summary: [http://www.joomplace.com/joomportfolio/joomportfolio.html JoomPortfolio] Input passed via the &amp;quot;secid&amp;quot; parameter to index.php (when &amp;quot;option&amp;quot; is set to &amp;quot;com_joomportfolio&amp;quot; and &amp;quot;task&amp;quot; is set to &amp;quot;showcat&amp;quot;) is not properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.The vulnerability is reported in version 1.0.0. Other versions may also be affected. Added: December 18 {{JVer|1.5}}&lt;br /&gt;
|[http://secunia.com/advisories/37838/ Reporting Site]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''City Portal (templates?)'''&lt;br /&gt;
|Summary:   City Portal Blind SQL Injection Vulnerability added: 2009-12-18&lt;br /&gt;
|[http://www.exploit-db.com Reference] Possibly this [http://www.youjoomla.com/jclick-city-portal-joomla-template.html tempate]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''Event Manager'''&lt;br /&gt;
|Summary:  [http://www.jforjoomla.com/Joomla-Components/event-manager-15-component.html Event Manager] Blind SQL Injection Vulnerability EDB-ID: 10549&lt;br /&gt;
added: 2009-12-18&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | com_zcalendar&lt;br /&gt;
|Summary:  com_zcalendar Blind SQL-injection Vulnerability&lt;br /&gt;
EDB-ID: 10548 added: 2009-12-18&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''com_acmisc'''&lt;br /&gt;
|Summary:  com_acmisc SQL injection added: 2009-12-18&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''com_jbook'''&lt;br /&gt;
|Summary:   com_jbook Blind SQL-injection EDB-ID: 10545 added: 2009-12-18 {{JVer|1.0}}&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |  '''com_personel'''&lt;br /&gt;
|Summary: com_personel component for Joomla! is vulnerable to SQL injection.&lt;br /&gt;
|[http://xforce.iss.net/xforce/xfdb/54903 iss.net reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |  '''HotBrackets Tournament Brackets '''&lt;br /&gt;
|Summary: The [http://extensions.joomla.org/extensions/sports-a-games/sports/10746 HotBrackets Tournament Brackets] component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. {{JVer|1.5}} added 22 dec &lt;br /&gt;
|[http://www.securityfocus.com/bid/37439/ Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''Car Manager'''&lt;br /&gt;
|Summary: http://webformatique.com/ com_carman Cross Site Scripting Vulnerability added 24 december 09{{JVer|1.5}}&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot; |'''Schools component'''&lt;br /&gt;
|Summary: The 'com_schools' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.&lt;br /&gt;
|[http://www.securityfocus.com/bid/37469 Reference] added 24 dec 09&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''webcamxp'''&lt;br /&gt;
|[http://extensions.joomla.org/extensions/communication/video-conference/4490 com_webcamxp] Cross Site Scripting Vulnerabilities  Last version 2008 {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''jm-recommend'''&lt;br /&gt;
|jm-recommendCross Site Scripting Vulnerabilities. unable to locate on jed. {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | facileforms&lt;br /&gt;
| com_facileforms Cross Site Scripting Vulnerabilities. unable to locate on jed. Product considered retired.  {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''adagency'''&lt;br /&gt;
| [http://www.ijoomla.com/ijoomla-ad-agency/ijoomla-ad-agency/index/ adagency ]Vulnerabilities {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |  '''com_intuit'''&lt;br /&gt;
|[http://www.san-diego-web-designer.com/new-file-download/item/root/aboutimage-igateway-for-joomla.html com_intuit]Local File Inclusion Vulnerability {{JVer|1.5}} Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | '''  [http://www.securityfocus.com/bid/37494/discuss Retired]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''MemoryBook'''&lt;br /&gt;
|[http://extensions.joomla.org/extensions/calendars-a-events/birthdays-a-historic-events/10868 MemoryBook 1.2]  Multiple Vulnerabilities. requires: magic quotes OFF, user account {{JVer|1.5}} Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''qpersonel'''&lt;br /&gt;
|[http://extensions.joomla.org/extensions/directory-a-documentation/thematic-directory/7049 qpersonel ] Cross Site Scripting Vulnerabilities {{JVer|1.0}}[[Image:http://extensions.joomla.org/images/jed/compat_15_legacy.png]] Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''opryknings point''' &lt;br /&gt;
|com_oprykningspoint_mc Cross Site Scripting Vulnerabilities {{JVer|1.5}} Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''trabalhe conosco'''&lt;br /&gt;
|com_trabalhe_conosco Cross Site Scripting Vulnerabilities {{JVer|1.5}} Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''DhForum'''&lt;br /&gt;
|com_dhforum SQL Injection Vulnerability. considered retired/EOL Dec. 27 {{JVer|1.0}}1.5 legacy&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== January 2010 Reported Vulnerable Extensions ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Please check with the extension publisher in case of any questions over the security of their product.'''&lt;br /&gt;
Report Vulnerable extensions either in the [[jforum:432]] security topic or the [http://forum.joomla.org/viewforum.php?f=470 extensions] topic clearly marked with the first word in the title being ''Vulnerable'' where the security moderators or JSST team will respond. &lt;br /&gt;
''This list is change protected, for updates or editing requests [http://forum.joomla.org/memberlist.php?mode=viewprofile&amp;amp;u=28000 Mandville] or [http://forum.joomla.org/memberlist.php?mode=viewprofile&amp;amp;u=87230 lafrance]&lt;br /&gt;
''&lt;br /&gt;
&lt;br /&gt;
[http://docs.joomla.org/Vulnerable_Extensions_List Back To Top]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  '''Extension'''&lt;br /&gt;
! class=&amp;quot;unsortable&amp;quot;| '''Details'''&lt;br /&gt;
!  '''Reference Link'''&lt;br /&gt;
!  '''Extension Update Link'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   |JvideoDirect&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/multimedia/video-players-a-gallery/9501 Jvideodirect] SQLi Jan 29&lt;br /&gt;
|&lt;br /&gt;
|[http://www.jvideodirect.com/ Update version 2.5]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   |'''JEvent search plugin'''&lt;br /&gt;
|Summary: JEvent search plugin for [http://extensions.joomla.org/extensions/calendars-a-events/events/95 JEvent] SQLi reported Jan 29&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | '''  [http://www.jevents.net/forum/viewtopic.php?f=17&amp;amp;t=3910#p15526 upgrade to 1.5.3b]'''&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   |'''Kunena'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/communication/forum/7256/details kunena] re reported suffering SQLi in version 1.5.9 Jan 29 Confirmation Required '''Now found to be malicious'''&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; | '''  [http://www.kunena.com/blog/19-developer-blog/51-kunena-157-security-release-now-available Versions 1.5.5 and below only]'''&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |'''JE Quiz'''&lt;br /&gt;
|Summary : http://extensions.joomla.org/extensions/contacts-and-feedback/quiz-a-surveys/11212 JeQuiz SQLi reported 29 Jan&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;&amp;quot;   |'''idoblog'''&lt;br /&gt;
|summary: exploitable due to open file permissions. 28 Jan&lt;br /&gt;
|Private Notification&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; | '''  [http://idojoomla.com/news.html build 35 released] '''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;    |'''ccnewsletter'''&lt;br /&gt;
|Summary [http://extensions.joomla.org/extensions/5112/details ccnewsletter Directory Traversal Vulnerability] Jan 28 &lt;br /&gt;
|Private Notification&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | ''' [http://www.chillcreations.com/en/blog/ccnewsletter-joomla-newsletter/ccnewsletter-106-security-release.html version 1.0.6 released 29 Jan]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;   |'''Virtuemart 1.1.4'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/e-commerce/shopping-cart/129 virtuemart] Input var order_status_id is vulnerable to SQLi NB Requires Higher Level access before exploiting. Jan 27&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; | '''  [http://forum.joomla.org/viewtopic.php?p=2027005#p2027005 developer patches]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   |'''JBDiary'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/calendars-a-events/events/11009 JBDiary] BLIND SQL Injection Vulnerabilities Jan 24 [http://www.jb-soft.nl/ http://www.jb-soft.nl/]&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;   | ''' [http://www.jb-soft.nl/index.php?option=com_content&amp;amp;view=article&amp;amp;id=64 Developer Update 27 Jan]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   |'''JbPublishDownFp'''&lt;br /&gt;
|Sumary: [http://extensions.joomla.org/extensions/news-production/timed-content/6496 JbPublishDownFp] SQL Injection Vulnerability Jan 24 [http://www.jb-soft.nl http://www.jb-soft.nl]&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |'''  [http://www.jb-soft.nl/index.php?option=com_content&amp;amp;view=article&amp;amp;id=64 Developer Update Jan 27]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''com_casino'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/sports-a-games/tips-a-betts com_casino]&lt;br /&gt;
SQL Injection Vulnerabilities Jan24&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   |'''Mochigames'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/search/mochigames com_Mochigames]&lt;br /&gt;
SQL Injection Vulnerabilities Jan24&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | ''' [http://www.yoflash.com/download.html mochigames_alpha052 Released]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |'''ContentBlogList'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/news-production/blog/10989 com_ContentBlogList] SQL Injection Vulnerability Jan 23&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |MailChimp for Joomla 1.5&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/bridges/mailing-a-newsletter-bridges/7836 MailChimp for Joomla 1.5]  jan 17&lt;br /&gt;
|Developer Statement&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |'''JoomlaXML'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/tools/design-tools/5020 JoomlaXML] malicious code insertion&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''JVClouds3D SWF module'''&lt;br /&gt;
|[http://joomlapro.ru/3djvclouds JVClouds3D SWF module] Cross Site Scripting . jan 14&lt;br /&gt;
|[http://xforce.iss.net/xforce/xfdb/55535 xforce]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''JVClouds3D'''&lt;br /&gt;
|[http://joomlapro.ru/3djvclouds JVClouds3D module] Cross Site Scripting . jan 14&lt;br /&gt;
|[http://xforce.iss.net/xforce/xfdb/55534 xforce]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |'''JA Showcase'''&lt;br /&gt;
|[http://www.joomlart.com/addons/components_and_modules/ja_showcase.html JA Showcase component] Directory Traversal jan 14&lt;br /&gt;
|[http://xforce.iss.net/xforce/xfdb/55512 xforce]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |'''jprojects'''&lt;br /&gt;
|Summary:   Unknown Author com_j-projects Blind SQL Injection Vulnerability. Jan 10 detail update&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;   |'''jEmbed-Embed Anything'''&lt;br /&gt;
|[http://www.joshprakash.com/index.php?option=com_docman&amp;amp;task=doc_details&amp;amp;gid=70 jEmbed-Embed Anything] A vulnerability has been discovered in the jEmbed-Embed Anything component for Joomla, which can be exploited by malicious people to conduct SQL injection attacks. Jan 10&lt;br /&gt;
|[http://secunia.com/advisories/38112 Secunia Advisory: SA38112] &lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | [http://extensions.joomla.org/extensions/3699/details Product considered retired]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;    |'''perchagallery '''&lt;br /&gt;
|Summary: perchagallery  [http://extensions.joomla.org/extensions/photos-a-images/photo-gallery/10350 com_perchagallery] SQL Injection Vulnerability  Jan 7&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | '''  [http://www.percha.com/index.php?option=com_phocadownload&amp;amp;view=file&amp;amp;id=22:1.5&amp;amp;Itemid=20 Developer Update 1.5b]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0;  color:black&amp;quot;   |  '''CARTwebERP'''&lt;br /&gt;
|Summary:  [http://extensions.joomla.org/extensions/bridges/e-commerce-bridges/8753 CARTwebERP] Local File Inclusion Vulnerability  Jan. 3&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | '''  [http://extensions.joomla.org/extensions/bridges/e-commerce-bridges/8753 1.56.76 (last update on Jan 11, 2010)]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |   '''JoomlaBibleStudy'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/miscellaneous/religion/3461 JoomlaBibleStudy] LFI Vulnerability  Jan. 3&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;   | '''[http://joomlabiblestudy.org/invisible-downloads/category/3-component.html Developer reported update]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |  '''com_bfsurvey_basic and pro'''&lt;br /&gt;
|Summary: [http://www.tamlyncreative.com.au/software/ BFsurvey] SQL Injection Vulnerability ,LFI Vulnerability   Jan. 3&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | '''  [http://www.tamlyncreative.com.au/software/forum/index.php?topic=641.0 Developer Update announcement]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''Alfresco'''&lt;br /&gt;
|Summary:  SQL Injection Vulnerability. Not believed to be Joomlatools extension Jan. 3&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''abbrev'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/directory-a-documentation/glossary-a-dictionary/4965 abbrev] Local File Inclusion Vulnerability Jan. 3&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''countries'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/miscellaneous/development/6553 countries] SQL Injection Vulnerability  Jan. 3&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   |  '''Dedicated Component com_tpjobs'''&lt;br /&gt;
|Summary: [http://www.templateplazza.com/ tpjobs] SQL Injection Vulnerability unable to locate files probably template plaza  Jan. 3&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;     | '''  [http://www.templateplazza.com/extensions-updates/tpjobs-component-update-v-1.1.html Developer Update] '''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''Component com_doqment'''&lt;br /&gt;
|SQL Injection Vulnerability Jan. 3&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''Component com_otzivi''' &lt;br /&gt;
|Blind SQL Injection Vulnerability  Jan. 3&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''aprice'''&lt;br /&gt;
|Summary: [http://adeptweb.info/component/option,com_aprice/Itemid,109/ com_aprice] Component 'analog' Parameter SQL Injection Vulnerability&lt;br /&gt;
|[http://www.securityfocus.com/bid/37575 Report]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |'''cartikads'''&lt;br /&gt;
|Summary: [http://www.cartikahosting.com com_cartikads] Remote File Upload Vulnerability &lt;br /&gt;
'''Mambo''' Open Source ads management component&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   | '''Docman seller''' &lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/e-commerce/subscriptions/5000 Document seller]  Input passed via the &amp;quot;id&amp;quot; parameter to index.php (when &amp;quot;option&amp;quot; is set to &amp;quot;com_dm_orders&amp;quot;, &amp;quot;task&amp;quot; is set to &amp;quot;order_form&amp;quot;, and &amp;quot;payment_method&amp;quot; is set to &amp;quot;Paypal&amp;quot;) is not properly sanitised before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.&lt;br /&gt;
|[http://secunia.com/advisories/38024/ secunia]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;   | [http://extensions.joomla.org/extensions/e-commerce/subscriptions/5000 Updated 10th Jan]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |  '''ozio gallery''' &lt;br /&gt;
|summary: [http://extensions.joomla.org/extensions/photos-a-images/photo-flash-gallery/4883 Ozio Gallery2] SQLi eploit &lt;br /&gt;
|[http://www.viruslist.com/en/advisories/37974 Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;   |[http://oziogallery.joomla.it/index.php?option=com_content&amp;amp;view=article&amp;amp;id=62%3Anuova-ozio-gallery-23-aggiornamento-di-sicurezza&amp;amp;catid=2%3Anotizie&amp;amp;Itemid=13&amp;amp;lang=en developer update Jan 11]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   | '''RD-Autos Free''' &lt;br /&gt;
|[http://extensions.joomla.org/extensions/vertical-markets/vehicles/5458 RD-Autos Free ] This version is now commercial not free&lt;br /&gt;
|Private advisory to JED Jan 11&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | ''' Product Retired and replaced'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''DailyMeals'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/vertical-markets/food-a-beverage/4764 dailymeals] Local File Inclusion  Vulnerability  Jan 02&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''RD-Autos Pro''' &lt;br /&gt;
|[http://extensions.joomla.org/extensions/vertical-markets/vehicles/6357 RD Autos Pro]&lt;br /&gt;
|Private advisory to JED Jan 11&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   | '''  Upgrade to  Latest version  be 2.0.2'''&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
[[Category:Security]]&lt;/div&gt;</summary>
		<author><name>CirTap</name></author>	</entry>

	<entry>
		<id>http://docs.joomla.org/Archived_vel</id>
		<title>Archived vel</title>
		<link rel="alternate" type="text/html" href="http://docs.joomla.org/Archived_vel"/>
				<updated>2011-07-15T09:05:07Z</updated>
		
		<summary type="html">&lt;p&gt;CirTap: /* January 2010 Reported Vulnerable Extensions */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{RightTOC}}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  '''Extension'''&lt;br /&gt;
! class=&amp;quot;unsortable&amp;quot;| '''Details'''&lt;br /&gt;
!  '''Reference Link'''&lt;br /&gt;
!  '''Extension Update Link'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''com_ajaxchat'''&lt;br /&gt;
|  Summary: PHP remote file inclusion vulnerability in Fiji Web Design Ajax Chat ('''com_ajaxchat''') component 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[mosConfig_absolute_path] parameter to tests/ajcuser.php.New version release December 22,2009&lt;br /&gt;
Published: october 28 2009&lt;br /&gt;
|  [[NIST:CVE-2009-3822|CVE-2009-3822]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | [http://extensions.joomla.org/extensions/communication/chat/10767 update v 1.1]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''com_booklibrary'''&lt;br /&gt;
|  PHP remote file inclusion vulnerability in doc/releasenote.php in the BookLibrary ('''com_booklibrary''') component 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter, a different vector than [[NIST:CVE-2009-2637|CVE-2009-2637]]. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 10/28/2009&lt;br /&gt;
CVSS Severity: 7.5 (HIGH)&lt;br /&gt;
|  [[NIST:CVE-2009-3817|CVE-2009-3817]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''[http://ordasoft.com/Download/Joomla1.0-extensions/Joomla1.0-components/View-category.html developer site updates]'''&lt;br /&gt;
|-&lt;br /&gt;
|   style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''com_foobla_suggestions'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the foobla Suggestions ('''com_foobla_suggestions''') component 1.5.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the idea_id parameter to index.php.&lt;br /&gt;
Published: 10/11/2009&lt;br /&gt;
CVSS Severity: 7.5 (HIGH)&lt;br /&gt;
|  [[NIST:CVE-2009-3669|CVE-2009-3669]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | [http://foobla.com/news/latest/fixed-foobla-suggestions-for-joomla-idea_id-sql-injection-vulnerability.html developer reported upgrade]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_djcatalog'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the DJ-Catalog ('''com_djcatalog''') component for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a showItem action and (2) cid parameter in a show action to index.php.&lt;br /&gt;
Published: 10/11/2009&lt;br /&gt;
CVSS Severity: 6.8 (MEDIUM)&lt;br /&gt;
|  [[NIST:CVE-2009-3661|CVE-2009-3661]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''com_cbresumebuilder'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the JoomlaCache CB Resume Builder (''''''com_cbresumebuilder''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the group_id parameter in a group_members action to index.php.&lt;br /&gt;
Published: 10/09/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3645|CVE-2009-3645]] &lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |'''[http://www.joomlacache.com/commercial-extensions/security-update.html Developer Update]'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  |  '''com_soundset'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Soundset ('''com_soundset''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter to index.php.&lt;br /&gt;
Published: 10/09/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3644|CVE-2009-3644]]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  |  '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  |'''com_sportfusion'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Kinfusion SportFusion ('''com_sportfusion''') component 0.2.2 through 0.2.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid[0] parameter in a teamdetail action to index.php.&lt;br /&gt;
Published: 09/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3491|CVE-2009-3491]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  |'''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_icrmbasic'''&lt;br /&gt;
|  Summary: A certain interface in the iCRM Basic ('''com_icrmbasic''') component 1.4.2.31 for Joomla! does not require administrative authentication, which has unspecified impact and remote attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 09/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3481|CVE-2009-3481]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_mytube'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the MyRemote Video Gallery ('''com_mytube''') component 1.0 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter in a videos action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3446|CVE-2009-3446]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_fastball'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Fastball ('''com_fastball''') component 1.1.0 through 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the league parameter to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3443|CVE-2009-3443]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | [http://www.fastballproductions.com   latest version] 1.2.1 &lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_facebook'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the JoomlaFacebook ('''com_facebook''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a student action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3438|CVE-2009-3438]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_tupinambis'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Tupinambis ('''com_tupinambis''') component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the proyecto parameter in a verproyecto action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3434|CVE-2009-3434]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''com_idoblog'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the IDoBlog ('''com_idoblog''') component 1.1 build 30 for Joomla! allows remote attackers to execute arbitrary SQL commands via the userid parameter in a profile action to index.php, a different vector than [[NIST:CVE-2008-2627|CVE-2008-2627]].&lt;br /&gt;
Published: 09/25/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3417|CVE-2009-3417]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot; |'''[http://idojoomla.com/download.html/ '''New Version v 1.1''' (build 32)]'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_hbssearch'''&lt;br /&gt;
|  Summary: Cross-site scripting ('''XSS''') vulnerability in the Hotel Booking Reservation System ('''aka HBS or com_hbssearch''') component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the adult parameter in a showhoteldetails action to index.php.&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 4.3 ('''MEDIUM''')&lt;br /&gt;
|  [[NIST:CVE-2009-3368|CVE-2009-3368]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_hbssearch'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System ('''aka HBS or com_hbssearch''') component for Joomla! allow remote attackers to execute arbitrary SQL commands via the ('''1''') h_id, ('''2''') id, and ('''3''') rid parameters to longDesc.php, and the h_id parameter to ('''4''') detail.php, ('''5''') detail1.php, ('''6''') detail2.php, ('''7''') detail3.php, ('''8''') detail4.php, ('''9''') detail5.php, ('''10''') detail6.php, ('''11''') detail7.php, and ('''12''') detail8.php, different vectors than [[NIST:CVE-2008-5865|CVE-2008-5865]], [[NIST:CVE-2008-5874|CVE-2008-5874]], and [[NIST:CVE-2008-5875|CVE-2008-5875]].&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3357|CVE-2009-3357]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''com_alphauserpoints'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in frontend/assets/ajax/checkusername.php in the AlphaUserPoints ('''com_alphauserpoints''') component 1.5.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the username2points parameter.&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3342|CVE-2009-3342]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |'''[http://www.alphaplug.com/index.php/news/142-alphauserpoints-153-released.html 1.5.3]'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''TurtuShout'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the TurtuShout component 0.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Name field.&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3335|CVE-2009-3335]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jinc'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Lhacky! Extensions Cave Joomla! Integrated Newsletters Component ('''aka JINC or com_jinc''') component 0.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a messages action to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3334|CVE-2009-3334]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''com_jbudgetsmagic'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the JBudgetsMagic ('''com_jbudgetsmagic''') component 0.3.2 through 0.4.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the bid parameter in a mybudget action to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3332|CVE-2009-3332]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | '''[http://sopinet.com/jbudgetsmagic/index.php?option=com_remository&amp;amp;Itemid=5&amp;amp;lang=en Update to 0.4.1]'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_surveymanager'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Focusplus Developments Survey Manager ('''com_surveymanager''') component 1.5.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the stype parameter in an editsurvey action to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3325|CVE-2009-3325]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_album'''&lt;br /&gt;
|  Summary: Directory traversal vulnerability in the Roland Breedveld Album ('''com_album''') component 1.14 for Joomla! allows remote attackers to access arbitrary directories and have unspecified other impact via a .. ('''dot dot''') in the target parameter to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3318|CVE-2009-3318]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;   | '''com_jreservation'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the [http://extensions.joomla.org/extensions/vertical-markets/booking-a-reservation/9798 JReservation] ('''com_jreservation''') component 1.0 and 1.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a propertycpanel action to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3316|CVE-2009-3316]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot; |  [http://www.jforjoomla.com Updated 28th] Jan fixed 13th Nov&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''IXXO Cart Standalone'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in IXXO Cart Standalone before 3.9.6.1, and the IXXO Cart component for Joomla! 1.0.x, allows remote attackers to execute arbitrary SQL commands via the parent parameter.&lt;br /&gt;
Published: 09/16/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3215|CVE-2009-3215]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_digifolio'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the DigiFolio ('''com_digifolio''') component 1.52 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a project action to index.php.&lt;br /&gt;
Published: 09/15/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3193|CVE-2009-3193]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_aclassf'''&lt;br /&gt;
|  Summary: Cross-site scripting ('''XSS''') vulnerability in '''gmap.php''' in the Almond Classifieds ('''com_aclassf''') component 7.5 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the addr parameter.&lt;br /&gt;
Published: 09/10/2009&lt;br /&gt;
CVSS Severity: 4.3 ('''MEDIUM''')&lt;br /&gt;
|  [[NIST:CVE-2009-3155|CVE-2009-3155]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;   | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''com_aclassf'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Almond Classifieds ('''com_aclassf''') component 7.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the replid parameter in a manw_repl add_form action to index.php, a different vector than [[NIST:CVE-2009-2567|CVE-2009-2567]].&lt;br /&gt;
Published: 09/10/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3154|CVE-2009-3154]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | [http://www.almondsoft.com/alcl.html Developer latest component]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jabode'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in Jabode horoscope extension ('''com_jabode''') for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a sign task to index.php.&lt;br /&gt;
Published: 09/08/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
&lt;br /&gt;
|  [[NIST:CVE-2008-7169|CVE-2008-7169]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_gameserver'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Game Server ('''com_gameserver''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a gamepanel action to index.php.&lt;br /&gt;
Published: 09/03/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3063|CVE-2009-3063]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_artportal'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Artetics.com Art Portal ('''com_artportal''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the portalid parameter to index.php.&lt;br /&gt;
Published: 09/03/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3054|CVE-2009-3054]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:#cef2e0; color:black&amp;quot; | '''com_agora'''&lt;br /&gt;
|  Summary: Directory traversal vulnerability in the Agora ('''com_agora''') component 3.0.0b for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the action parameter to the avatars page, reachable through index.php.&lt;br /&gt;
Published: 09/03/2009&lt;br /&gt;
CVSS Severity: 6.8 ('''MEDIUM''')&lt;br /&gt;
|  [[NIST:CVE-2009-3053|CVE-2009-3053]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot; |'''[http://jvitals.com/index.php?option=com_rokdownloads&amp;amp;view=file&amp;amp;Itemid=108&amp;amp;id=282:agora-3-0 3.0.7]'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_simpleshop'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Simple Shop Galore ('''com_simpleshop''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the section parameter in a section action to index.php, a different vulnerability than [[NIST:CVE-2008-2568|CVE-2008-2568]]. NOTE: this issue was disclosed by an unreliable researcher, so the details might be incorrect.&lt;br /&gt;
Published: 08/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-7033|CVE-2008-7033]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_groups'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Permis ('''com_groups''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a list action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 08/17/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-2789|CVE-2009-2789]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:#cef2e0; color:black&amp;quot; | '''com_content'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the content component ('''com_content''') 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a blogcategory action to index.php.&lt;br /&gt;
Published: 08/10/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6923|CVE-2008-6923]]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |'''[http://developer.joomla.org/security/news/305-20091103-core-front-end-editor-issue-.html Resolution]'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Live Chat ('''com_livechat''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the last parameter to getChatRoom.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6883|CVE-2008-6883]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: Live Chat ('''com_livechat''') component 1.0 for Joomla! allows remote attackers to use the xmlhttp.php script as an open HTTP proxy to hide network scanning activities or scan internal networks via a GET request with a full URL in the query string.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6882|CVE-2008-6882]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_livechat'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the Live Chat ('''com_livechat''') component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the last parameter to ('''1''') getChat.php, ('''2''') getChatRoom.php, and ('''3''') getSavedChatRooms.php.&lt;br /&gt;
Published: 07/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2008-6881|CVE-2008-6881]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''JUMI'''&lt;br /&gt;
|  There is a backdoor in JUMI that installs itself when JUMI is installed on your web site. It sends your credentials to a website, and sets up a back door for remote code execution.&lt;br /&gt;
Please remove JUMI2.0.5 immediately. &lt;br /&gt;
It will be simple enough to remove the compromised code from this download, but you need to do &lt;br /&gt;
a full security audit on your site as well as you have been compromised. Added November 2009&lt;br /&gt;
|  [http://code.google.com/p/jumi/updates/list Report]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |[http://code.google.com/p/jumi/updates/list Jumi Update]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''com_photoblog'''&lt;br /&gt;
|  Input Validation Error Added November 2009&lt;br /&gt;
|  [http://www.securityfocus.com/bid/36809/ 36809]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |[http://webguerilla.net/downloads/3-components-for-joomla-1 webguerilla Photoblog alpha 3b]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jshop'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the JShop ('''com_jshop''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a product action to index.php.&lt;br /&gt;
Published: 11/02/2009&lt;br /&gt;
CVSS Severity: 7.5 '''(HIGH)''' &lt;br /&gt;
|  [[NIST:CVE-2009-3835|CVE-2009-3835]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot; |'''BF Survey Pro'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the '''BF Survey Pro''' v1.2.5 or lower  (fixed in version 1.2.6). '''BF Survey Basic v1.0''' (fixed in version 1.1). '''BF Quiz v1.1.1''' (fixed in version 1.2 or greater) Added November 2009&lt;br /&gt;
|  [http://www.tamlyncreative.com.au/software/forum/index.php?topic=357.0 tamlyncreative.com.au]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |[http://www.tamlyncreative.com.au/software/forum/index.php?topic=357.0 update]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot; |'''Joo!BB 0.9.1 '''&lt;br /&gt;
|  Summary: Persistent XSS/MySQL Injection vulnerabilities in Joo!BB 0.9.1 Added November 2009&lt;br /&gt;
|  [http://www.joobb.org/community/board/topic/700-MultipleXSSSQLInjectionVulnerabilities.html joob.org]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot; |[http://www.joobb.org/downloads/components.html update]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''sh404sef '''&lt;br /&gt;
|  Summary: sh404sef URI XSS Vulnerability  Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/sh404sef-uri-xss-vulnerability.html jeffchannell.com]&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |[http://extensions.siliana.com/en/2009060876/sh404SEF-and-url-rewriting/Interim-release-of-sh404sef-for-Joomla-1.5.x.html update]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''AWD Wall 1.5''' &lt;br /&gt;
|  Summary '''AWD Wall 1.5''' Blind SQL Injection Vulnerability.The Joomla component AWD Wall 1.5 suffers from an SQL Injection vulnerability in its handling of the 'cbuser' parameter.Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/awd-wall-15-blind-sql-injection-vulnerability.html Notice]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | '''[http://www.awdsolution.com/template_demo/testsite/index.php?option=com_content&amp;amp;view=article&amp;amp;id=48&amp;amp;Itemid=72 developer update]'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''EasyBook 2.0.0rc4'''&lt;br /&gt;
|  Summary: The Joomla component '''EasyBook 2.0.0rc4''' suffers from multiple persistent XSS vulnerabilities. One seems fairly critical, while the others would take some incredible creativity to actively exploit. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/easybook-200rc4-multiple-xss-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''F!BB 1.5.96''' &lt;br /&gt;
|  Summary: The Joomla component '''F!BB 1.5.96 RC''' suffers from multiple persistent XSS vulnerabilities, as well SQL Injection in its user search feature. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/fbb-1596-rc-multiple-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Testimonial Ku 2.0 Admin Panel'''&lt;br /&gt;
|  Summary: The Joomla component '''Testimonial Ku 2.0''' is vulnerable to persistent XSS in the administrator panel. A malicious user can submit a testimonial containing &amp;lt;script&amp;gt; tags with absolutely no quotes and inject that script into the administrator panel through any of the available inputs except &amp;quot;email&amp;quot;. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/testimonial-ku-20-admin-panel-persistent-xss.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''MS Comment 0.8.0b'''&lt;br /&gt;
|  Summary '''MS Comment 0.8.0b for Joomla''', a commenting plugin, suffers from an multiple vulnerabilities. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/ms-comment-080b-multiple-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |  '''!JoomlaComment 4.0 beta1'''&lt;br /&gt;
|  Summary: '''!JoomlaComment 4.0 beta1''', a commenting plugin, suffers from multiple XSS vulnerabilities. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/joomlacomment-40-beta1-multiple-xss-vulnerabilities.html Alert]&lt;br /&gt;
| style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | '''  [http://compojoom.com/blog/8-news/121-joomlacomment-40-rc1-released Developer Notice 4.0 rc1]''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''WebAmoeba Ticket System 3.0.0'''&lt;br /&gt;
|  Summary:  '''WebAmoeba Ticket System 3.0.0''', a Joomla help desk component. The vulnerability is with the BBCode library used to parse BBCode tags, as it does not strip javascript: urls from [url] tags. Added November 2009&lt;br /&gt;
|  [http://jeffchannell.com/Joomla/webamoeba-ticket-system-300-bbcode-xss.html Alert]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |'''Kunena 1.5.x''' &lt;br /&gt;
|Summary: This is an important security release and users are urged to update immediately. Five security issues and an Internet Explorer 8 table bug have been resolved in this release. This release also contains many other important bug fixes. Added 18 November 2009&lt;br /&gt;
|[http://www.kunena.com/blog/19-developer-blog/51-kunena-157-security-release-now-available Advisory]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |[http://www.kunena.com/blog/19-developer-blog/52-kunena-158-service-release-now-available Latest 1.5.8 Version]&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_siirler'''&lt;br /&gt;
|  Summary:  SQL injection vulnerability in the '''Q-Proje Siirler Bileseni (com_siirler)''' component 1.2 RC for Joomla! allows remote attackers to execute arbitrary SQL commands via the sid parameter in an sdetay action to index.php. Added 18 November 2009&lt;br /&gt;
|  [[NIST:CVE-2009-3972 | CVE-2009-3972]]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''jTips (com_jtips)'''&lt;br /&gt;
|SUmmary:SQL injection vulnerability in the '''jTips (com_jtips)''' component 1.0.7 and 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the season parameter in a ladder action to index.php. Added 18 November 2009&lt;br /&gt;
| [[NIST:CVE-2009-3971 |CVE-2009-3971]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''NinjaMonials'''&lt;br /&gt;
| Summary: SQL injection vulnerability in the '''NinjaMonials (com_ninjacentral)''' component 1.1.0 for '''Joomla 1.0.x''' ! allows remote attackers to execute arbitrary SQL commands via the testimID parameter in a display action to index.php. Added 18 November 2009&lt;br /&gt;
|  [[NIST:CVE-2009-3964 | CVE-2009-3964]]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |'''  [http://ninjaforge.com/index.php?option=com_ninjacentral&amp;amp;page=show_package&amp;amp;id=14&amp;amp;Itemid=235 developer patch Ver 1.2]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;   | '''webee 1.1.1 &amp;amp;1.2'''&lt;br /&gt;
|Summary: '''webee 1.1.1,''' a Joomla commenting plugin, suffers from multiple vulnerabilities. '''webee has been updated to 1.2''' as of 12 November 2009 and''' still suffers''' from SQL Injection. XSS was not tested in 1.2. Added 19 November 2009&lt;br /&gt;
| [http://jeffchannell.com/Joomla/webee-111-multiple-vulnerabilities.html jeffchannell.com]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | ''' [http://extensions.joomla.org/extensions/contacts-and-feedback/articles-comments/10155 developer update ver2.0]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''iF Portfolio Nexus'''&lt;br /&gt;
|Summary: The '''iF Portfolio Nexus component for Joomla!''' is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements using the id parameter, which could allow the attacker to view, add, modify or delete information in the back-end database. Nov 18, 2009&lt;br /&gt;
|[http://secunia.com/advisories/37408/ secunia.com 37408/]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; |[http://www.inertialfate.za.net/help/forums/topic?id=10&amp;amp;p=3#p172 iF Portfolio Nexus v1.1.1 released]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''JoomClip'''&lt;br /&gt;
|Summary: The '''JoomClip component for Joomla!''' is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements to the index.php script using the cat parameter, which could allow the attacker to view, add, modify or delete information in the back-end database.  Nov 18, 2009&lt;br /&gt;
|[http://secunia.com/advisories/37400/ secunia.com 37400/]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''Joomla XML'''&lt;br /&gt;
|Summary: Joomla! before 1.5.15 allows remote attackers to read an extension's XML file, and thereby obtain the extension's version number, via a direct request.&lt;br /&gt;
Published: 11/16/2009&lt;br /&gt;
|[[NIST:CVE-2009-3946 | CVE-2009-3946]] &lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |'''[http://developer.joomla.org/security/news/306-20091103-core-xml-file-read-issue.html Resolution]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Mygallery Remote SQL Injection Vulnerability''' &lt;br /&gt;
|Summary: Joomla Component mygallery ( farbinform_krell) Remote SQL Injection Vulnerability Added 27 Nov 2009 {{JVer|1.5}} NB: This could be an error in our database as the only one we could find was for wordpress.If anyone know of one for joomla please let us know..(poss joomlicious.com CM)&lt;br /&gt;
|[http://www.exploit-db.com] &lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Extreme Google Calendar'''&lt;br /&gt;
|Summary: '''com_gcalendar 1.1.2''' (gcid) Remote SQL Injection Vulnerability&lt;br /&gt;
Remote SQL Injection were identified in Google Calendar Component [http://extensions.joomla.org/extensions/calendars-a-events/calendars/4188 Extension Link] Added 27 Nov 2009 &lt;br /&gt;
|[http://www.exploit-db.com reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''LyftenBloggie'''&lt;br /&gt;
| Summary: [http://www.lyften.com/products/lyftenbloggie.html LyftenBloggie] Component &amp;quot;author&amp;quot; SQL Injection Vulnerability LyftenBloggie 1.x Added 27 Nov 2009&lt;br /&gt;
|[http://secunia.com/advisories/product/28005/	 SA37499]&lt;br /&gt;
| [http://jeffchannell.com/Joomla/lyften-bloggie-sql-injection-fix.html Un official fix]. Developer fix not release at 30 Nov 09 ''' [http://www.lyften.com/products/lyftenbloggie/extensions/download/id-20.html 1.0.4a (last update on Dec 28, 2009)]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''Sermon speaker'''&lt;br /&gt;
|Summary: [http://joomlacode.org/gf/project/sermon_speaker sermon speaker] sql vulnerability and password reset vulnerability version 3.2 and below&lt;br /&gt;
|&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |[http://joomlacode.org/gf/project/sermon_speaker/forum/?action=ForumBrowse&amp;amp;forum_id=7897&amp;amp;_forum_action=ForumMessageBrowse&amp;amp;thread_id=15219 Developer fix] 30 Nov 2009&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | [http://joomlacode.org/gf/project/musicgallery/ MusicGallery]&lt;br /&gt;
|Summary: [http://joomlacode.org/gf/project/musicgallery/ Component MusicGallery] SQL Injection Vulnerability 30 November {{JVer|1.5}}&lt;br /&gt;
|[[NIST:CVE-2009-4217 | CVE-2009-4217]]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; | [http://joomlacode.org/gf/project/musicgallery/ developer]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== December 2009 Compiled Reports ==&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  '''Extension'''&lt;br /&gt;
! class=&amp;quot;unsortable&amp;quot;| '''Details'''&lt;br /&gt;
!  '''Reference Link'''&lt;br /&gt;
!  '''Extension Update Link'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Omilen Photo Gallery'''&lt;br /&gt;
|Summary: Directory traversal vulnerability in the [http://extensions.joomla.org/extensions/photos-&amp;amp;-images/photo-flash-gallery/6373/details Omilen Photo Gallery] (com_omphotogallery) component Beta 0.5 for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the controller parameter to index.php.&lt;br /&gt;
Published: 12/04/2009&lt;br /&gt;
|[[NIST:CVE-2009-4202 | CVE-2009-4202]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''Seminar'''&lt;br /&gt;
|Summary: SQL injection vulnerability in the [http://seminar.vollmar.ws/ Seminar] (com_seminar) component 1.28 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a View_seminar action to index.php.&lt;br /&gt;
Published: 12/04/2009&lt;br /&gt;
|[[NIST:CVE-2009-4200 | CVE-2009-4200]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''Mambo Resident'''&lt;br /&gt;
|Summary: Multiple SQL injection vulnerabilities in the Mambo Resident (aka Mos Res or com_mosres) component 1.0f for Mambo and Joomla!, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) property_uid parameter in a viewproperty action to index.php and the (2) regID parameter in a showregion action to index.php. Mambo Resident component for v4.5.2 '''may only be for 1.0.xx versions of J!'''&lt;br /&gt;
Published: 12/04/2009&lt;br /&gt;
|[[NIST:CVE-2009-4199 | CVE-2009-4199]]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; |[http://www.jomres.net/ Replacement Extension 08 dec 09]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''ProofReader''' &lt;br /&gt;
|Summary: Multiple cross-site scripting (XSS) vulnerabilities in index.php in the ProofReader (com_proofreader) component 1.0 RC9 and earlier for Joomla! allow remote attackers to inject arbitrary web script or HTML via the URI, which is not properly handled in (1) 404 or (2) error pages. Published: 12/02/2009 CVSS Severity: 4.3 (MEDIUM)&lt;br /&gt;
| [[NIST:CVE-2009-4157 | CVE-2009-4157]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''Laoneo Google Calendar GCalendar'''&lt;br /&gt;
|Summary: SQL injection vulnerability in the [http://g4j.laoneo.net/content/extensions/download/cat_view/20-joomla-15x/21-gcalendar.html Google Calendar GCalendar] (com_gcalendar) component 1.1.2, 2.1.4, and possibly earlier versions for Joomla! allows remote attackers to execute arbitrary SQL commands via the gcid parameter. NOTE: some of these details are obtained from third party information. Published: 11/29/2009 CVSS Severity: 7.5 (HIGH) Note: There is already a listing for GCalendar 1.1.2&lt;br /&gt;
|[[NIST:CVE-2009-4099 | CVE-2009-4099]]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;   | [http://g4j.laoneo.net/content/extensions/download/doc_details/28-gcalendar-suite-215.html Latest version GCalendar Suite 2.1.5]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''D4J eZine'''&lt;br /&gt;
|Summary: PHP remote file inclusion vulnerability in class/php/d4m_ajax_pagenav.php in the D4J eZine (com_ezine) component 2.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS mosConfig_absolute_path parameter. Published: 11/29/2009 CVSS Severity: 7.5 (HIGH)&lt;br /&gt;
|[[NIST:CVE-2009-4094 | CVE-2009-4094]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''Quick News'''&lt;br /&gt;
| Summary: The Joomla [http://joomlacode.org/gf/project/quicknews/ Quick News component] suffers from a remote SQL injection vulnerability. added 1st Dec 09&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''Joaktree component'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/miscellaneous/genealogy/9842 Joaktree] Vulnerability : SQL injection/ added 1st Dec 09&lt;br /&gt;
|[http://securityreason.com/exploitalert/7508 7508]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | '''  [http://naastniels.nl/index.php/en/joaktree/downloads version 1.1 update]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''mojoblog'''&lt;br /&gt;
|Summary [http://www.joomlify.com/files/mojoblog/ MojoBlog] Multiple Remote File Include Vulnerability added 1st Dec 09 {{JVer|1.5}}&lt;br /&gt;
|[http://securityreason.com/exploitalert/7509 7509]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''YJ Whois''' &lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/external-contents/domain-search/5774 YJ Whois] '''Low security risk''',and fixesMalicious users may inject JavaScript, VBScript, ActiveX, HTML or Flash into a vulnerable application to fool a user in order to gather data from them. An attacker can steal the session cookie and take over the account. Files affected is , modules/mod_yj_whois.php added 3 December 09&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; |[http://www.youjoomla.com/xss-security-patch-for-yj-whois.html Developer Notice and fix 03 dec 09]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; | '''yt_color YOOOtheme'''&lt;br /&gt;
|Summary: [http://www.yootheme.com/ YT_color yootheme] Malicious users may inject JavaScript, VBScript, ActiveX, HTML or Flash into a vulnerable application to fool a user in order to gather data from them. An attacker can steal the session cookie and take over the account. added 5 dec 09&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | '''  [http://www.yootheme.com/member-area/downloads/item/templates-15/xss-and-php-53-patches All members without an active membership can download the template patches here].'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''TP Whois''' &lt;br /&gt;
|summary: [http://www.templateplazza.com/view-details/tpwhois/183-component-tp-whois-for-joomla-1.5.x.html TP Whois ] Malicious users may inject JavaScript, VBScript, ActiveX, HTML or Flash into a vulnerable application to fool a user in order to gather data from them. An attacker can steal the session cookie and take over the account. Added 3 december {{JVer|1.5}}&lt;br /&gt;
|[http://www.exploit-db.com Refrence]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''com_job'''&lt;br /&gt;
|Summary: Component com_job ( showMoreUse) SQL injection vulnerability  Added 9th Dec&lt;br /&gt;
|[http://xforce.iss.net/xforce/xfdb/54626 Reference]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |  '''JQuarks''' &lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/contacts-and-feedback/quiz-a-surveys/10590 JQuarks] SQL injection vulnerability {{JVer|1.5}} added 8th dec 09&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | [http://www.iptechinside.com/labs/projects/list_files/jquarks Developer Update ]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  |  '''Mamboleto Component 2.0 RC3'''&lt;br /&gt;
|Summary: [http://www.fernandosoares.com.br/index.php?option=com_docman&amp;amp;task=cat_view&amp;amp;gid=28&amp;amp;Itemid=28 Mamboleto Component 2.0 RC3]SQL injection vulnerability {{JVer|1.5}} added 12 December&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |  ''' JS JOBS'''&lt;br /&gt;
|Summary [http://www.joomshark.com/index.php?option=com_content&amp;amp;view=article&amp;amp;id=4&amp;amp;Itemid=8 JS JOBS] Joomla Component com_jsjobs 1.0.5.6 SQL Injection Vulnerabilities {{JVer|1.5}} added 12 December&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | '''  [http://www.joomsky.com/index.php?option=com_rokdownloads&amp;amp;view=folder&amp;amp;Itemid=3&amp;amp;id=2:components Developer update 1.0.5.7]''' &lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |  '''corePHP JPhoto'''&lt;br /&gt;
|Summary: [http://extensions.joomla.org/extensions/photos-a-images/photo-gallery/10365 'corePHP' JPhoto]SQL injection vulnerability {{JVer|1.5}} added 12 December&lt;br /&gt;
|[http://secunia.com/advisories/37676/ Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | '''  [http://www.corephp.com/blog/uber-fast-jphoto-security-release/ Developer Upgrade]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;    | '''com_virtuemart'''&lt;br /&gt;
|Summary: &amp;quot;com_virtuemart&amp;quot; http://virtuemart.net/  '''Version : 1.0''' Vulnerability : SQL injection added Date : 07- dec -09 {{JVer|1.5}}&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  |[http://virtuemart.net/ latest version]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | ''' Kide Shoutbox'''&lt;br /&gt;
&lt;br /&gt;
|Summary: The Kide Shoutbox (com_kide) component 0.4.6 for Joomla! does not properly perform authentication, which allows remote attackers to post messages with an arbitrary account name via an insertar action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Added: December 08&lt;br /&gt;
|[[NIST:CVE-2009-4232 | CVE-2009-4232]]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | ''' JoomPortfolio Component'''&lt;br /&gt;
|Summary: [http://www.joomplace.com/joomportfolio/joomportfolio.html JoomPortfolio] Input passed via the &amp;quot;secid&amp;quot; parameter to index.php (when &amp;quot;option&amp;quot; is set to &amp;quot;com_joomportfolio&amp;quot; and &amp;quot;task&amp;quot; is set to &amp;quot;showcat&amp;quot;) is not properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.The vulnerability is reported in version 1.0.0. Other versions may also be affected. Added: December 18 {{JVer|1.5}}&lt;br /&gt;
|[http://secunia.com/advisories/37838/ Reporting Site]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''City Portal (templates?)'''&lt;br /&gt;
|Summary:   City Portal Blind SQL Injection Vulnerability added: 2009-12-18&lt;br /&gt;
|[http://www.exploit-db.com Reference] Possibly this [http://www.youjoomla.com/jclick-city-portal-joomla-template.html tempate]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''Event Manager'''&lt;br /&gt;
|Summary:  [http://www.jforjoomla.com/Joomla-Components/event-manager-15-component.html Event Manager] Blind SQL Injection Vulnerability EDB-ID: 10549&lt;br /&gt;
added: 2009-12-18&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | com_zcalendar&lt;br /&gt;
|Summary:  com_zcalendar Blind SQL-injection Vulnerability&lt;br /&gt;
EDB-ID: 10548 added: 2009-12-18&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''com_acmisc'''&lt;br /&gt;
|Summary:  com_acmisc SQL injection added: 2009-12-18&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''com_digistore'''&lt;br /&gt;
|Summary:  com_digistore SQL injection EDB-ID: 10546 added: 2009-12-18  {{JVer|1.5}}&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | '''  [http://www.ijoomla.com/ijoomla-digistore/ijoomla-digistore/ijoomla-digistore-change-log/ Update change log] '''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''com_jbook'''&lt;br /&gt;
|Summary:   com_jbook Blind SQL-injection EDB-ID: 10545 added: 2009-12-18 {{JVer|1.0}}&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |  '''com_personel'''&lt;br /&gt;
|Summary: com_personel component for Joomla! is vulnerable to SQL injection.&lt;br /&gt;
|[http://xforce.iss.net/xforce/xfdb/54903 iss.net reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |  '''JEEMA Article Collection'''&lt;br /&gt;
|Summary: [http://www.forum.jeema.net/component/content/article/4-jeema-article-collection-component/13-about-jeema-article-collection.html JEEMA Article Collection] Input passed via the &amp;quot;catid&amp;quot; parameter to index.php (when &amp;quot;option&amp;quot; is set to &amp;quot;com_jeemaarticlecollection&amp;quot; and &amp;quot;view&amp;quot; is set to &amp;quot;longlook&amp;quot;) is not properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. version 1.0.0.1 {{JVer|1.5}} added 22 dec 09&lt;br /&gt;
| [http://secunia.com/advisories/37865/ secunia]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;    | [http://www.jeema.net/downloads/free-joomla-extensions/joomla-components/12-jeema-joomla-article-collection.htm fixed the same in the version v102.]&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |  '''HotBrackets Tournament Brackets '''&lt;br /&gt;
|Summary: The [http://extensions.joomla.org/extensions/sports-a-games/sports/10746 HotBrackets Tournament Brackets] component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. {{JVer|1.5}} added 22 dec &lt;br /&gt;
|[http://www.securityfocus.com/bid/37439/ Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''Car Manager'''&lt;br /&gt;
|Summary: http://webformatique.com/ com_carman Cross Site Scripting Vulnerability added 24 december 09{{JVer|1.5}}&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot; |'''Schools component'''&lt;br /&gt;
|Summary: The 'com_schools' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.&lt;br /&gt;
|[http://www.securityfocus.com/bid/37469 Reference] added 24 dec 09&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''webcamxp'''&lt;br /&gt;
|[http://extensions.joomla.org/extensions/communication/video-conference/4490 com_webcamxp] Cross Site Scripting Vulnerabilities  Last version 2008 {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''beeheard'''&lt;br /&gt;
|[http://extensions.joomla.org/extensions/contacts-and-feedback/testimonials-a-suggestions/10283 beeheard]  Blind SQL injection Vulnerability {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | '''  [http://beeheard.cmstactics.com/change-log Version 1.4.2] 04 Jan'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''jm-recommend'''&lt;br /&gt;
|jm-recommendCross Site Scripting Vulnerabilities. unable to locate on jed. {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | facileforms&lt;br /&gt;
| com_facileforms Cross Site Scripting Vulnerabilities. unable to locate on jed. Product considered retired.  {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''adagency'''&lt;br /&gt;
| [http://www.ijoomla.com/ijoomla-ad-agency/ijoomla-ad-agency/index/ adagency ]Vulnerabilities {{JVer|1.5}} Dec 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |  '''com_intuit'''&lt;br /&gt;
|[http://www.san-diego-web-designer.com/new-file-download/item/root/aboutimage-igateway-for-joomla.html com_intuit]Local File Inclusion Vulnerability {{JVer|1.5}} Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot; | '''  [http://www.securityfocus.com/bid/37494/discuss Retired]'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; | '''MemoryBook'''&lt;br /&gt;
|[http://extensions.joomla.org/extensions/calendars-a-events/birthdays-a-historic-events/10868 MemoryBook 1.2]  Multiple Vulnerabilities. requires: magic quotes OFF, user account {{JVer|1.5}} Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''qpersonel'''&lt;br /&gt;
|[http://extensions.joomla.org/extensions/directory-a-documentation/thematic-directory/7049 qpersonel ] Cross Site Scripting Vulnerabilities {{JVer|1.0}}[[Image:http://extensions.joomla.org/images/jed/compat_15_legacy.png]] Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''opryknings point''' &lt;br /&gt;
|com_oprykningspoint_mc Cross Site Scripting Vulnerabilities {{JVer|1.5}} Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''trabalhe conosco'''&lt;br /&gt;
|com_trabalhe_conosco Cross Site Scripting Vulnerabilities {{JVer|1.5}} Dec. 27&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot; |'''DhForum'''&lt;br /&gt;
|com_dhforum SQL Injection Vulnerability. considered retired/EOL Dec. 27 {{JVer|1.0}}1.5 legacy&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:red; color:white&amp;quot;  | '''  Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot; |'''com_morfeoshow'''&lt;br /&gt;
|[http://extensions.joomla.org/extensions/photos-a-images/photo-gallery-add-ons/9810 morfeoshow] this was a false report &lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  | '''  false report'''&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:black&amp;quot;  |'''Run Digital Download rd-download''' &lt;br /&gt;
|[http://extensions.joomla.org/extensions/directory-a-documentation/downloads/7838 RD Download] Local File Disclosure Vulnerability  {{JVer|1.5}} Dec. 30 Version affected not disclosed.&lt;br /&gt;
|[http://www.exploit-db.com Reference]&lt;br /&gt;
|style=&amp;quot;background:#cef2e0; color:white&amp;quot;  | [http://extensions.joomla.org/extensions/directory-a-documentation/downloads/7838 Version 0.9 relased] &lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|}&lt;br /&gt;
== November 2009 Compiled Vulnerability Reports. RESOLVED ONLY  ==&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
Items are not in any particular order.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  '''Extension'''&lt;br /&gt;
! class=&amp;quot;unsortable&amp;quot;| '''Details'''&lt;br /&gt;
!  '''Reference Link'''&lt;br /&gt;
!  '''Extension Update Link'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_djcatalog'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the DJ-Catalog ('''com_djcatalog''') component for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a showItem action and (2) cid parameter in a show action to index.php.&lt;br /&gt;
Published: 10/11/2009&lt;br /&gt;
CVSS Severity: 6.8 (MEDIUM)&lt;br /&gt;
|  [[NIST:CVE-2009-3661|CVE-2009-3661]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  |  '''com_soundset'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Soundset ('''com_soundset''') component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter to index.php.&lt;br /&gt;
Published: 10/09/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3644|CVE-2009-3644]]&lt;br /&gt;
| style=&amp;quot;background:red; color:white&amp;quot;  |  '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  |'''com_sportfusion'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Kinfusion SportFusion ('''com_sportfusion''') component 0.2.2 through 0.2.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid[0] parameter in a teamdetail action to index.php.&lt;br /&gt;
Published: 09/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3491|CVE-2009-3491]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  |'''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_icrmbasic'''&lt;br /&gt;
|  Summary: A certain interface in the iCRM Basic ('''com_icrmbasic''') component 1.4.2.31 for Joomla! does not require administrative authentication, which has unspecified impact and remote attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.&lt;br /&gt;
Published: 09/30/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3481|CVE-2009-3481]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_mytube'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the MyRemote Video Gallery ('''com_mytube''') component 1.0 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter in a videos action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3446|CVE-2009-3446]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|   '''com_facebook'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the JoomlaFacebook ('''com_facebook''') component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a student action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3438|CVE-2009-3438]]&lt;br /&gt;
|   [http://extensions.joomla.org/extensions/4446/details JED entry.] [http://forge.joomla.org/gf/project/joomla-facebook/ Download site] Developer states reports not proven 24/07/10&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_tupinambis'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Tupinambis ('''com_tupinambis''') component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the proyecto parameter in a verproyecto action to index.php.&lt;br /&gt;
Published: 09/28/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3434|CVE-2009-3434]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_hbssearch'''&lt;br /&gt;
|  Summary: Cross-site scripting ('''XSS''') vulnerability in the Hotel Booking Reservation System ('''aka HBS or com_hbssearch''') component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the adult parameter in a showhoteldetails action to index.php.&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 4.3 ('''MEDIUM''')&lt;br /&gt;
|  [[NIST:CVE-2009-3368|CVE-2009-3368]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_hbssearch'''&lt;br /&gt;
|  Summary: Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System ('''aka HBS or com_hbssearch''') component for Joomla! allow remote attackers to execute arbitrary SQL commands via the ('''1''') h_id, ('''2''') id, and ('''3''') rid parameters to longDesc.php, and the h_id parameter to ('''4''') detail.php, ('''5''') detail1.php, ('''6''') detail2.php, ('''7''') detail3.php, ('''8''') detail4.php, ('''9''') detail5.php, ('''10''') detail6.php, ('''11''') detail7.php, and ('''12''') detail8.php, different vectors than [[NIST:CVE-2008-5865|CVE-2008-5865]], [[NIST:CVE-2008-5874|CVE-2008-5874]], and [[NIST:CVE-2008-5875|CVE-2008-5875]].&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3357|CVE-2009-3357]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''TurtuShout'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the TurtuShout component 0.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Name field.&lt;br /&gt;
Published: 09/24/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3335|CVE-2009-3335]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''com_jinc'''&lt;br /&gt;
|  Summary: SQL injection vulnerability in the Lhacky! Extensions Cave Joomla! Integrated Newsletters Component ('''aka JINC or com_jinc''') component 0.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a messages action to index.php.&lt;br /&gt;
Published: 09/23/2009&lt;br /&gt;
CVSS Severity: 7.5 ('''HIGH''')&lt;br /&gt;
|  [[NIST:CVE-2009-3334|CVE-2009-3334]]&lt;br /&gt;
|  style=&amp;quot;background:red; color:white&amp;quot;  | '''Not Known'''&lt;br /&gt;
|-&lt;br /&gt;
|  style=&amp;quot;background:red; color:wh