PHP remote file inclusion vulnerability in akocomments.php in AkoComment 1.1 module (comakocomment) for Mambo 4.5 allows remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter.
Multiple SQL injection vulnerabilities in akocomment.php in AkoComment 2.0 module for Mambo, with magicquotesgpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) acname or (2) contentid parameter.