SQL injection vulnerability in index.php in the McQuiz (commcquiz) 0.9 Final component for Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a usertstshw action.
SQL injection vulnerability in index.php in the Quiz (comquiz) 0.81 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a usertstshw action.