Cross-site scripting (XSS) vulnerability in the Artist avenue (comartistavenue) component for Joomla! and Mambo allows remote attackers to inject arbitrary web script or HTML via the Itemid parameter to index.php.
Cross-site scripting (XSS) vulnerability in the Hotel Booking Reservation System (aka HBS or comhbssearch) component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the adult parameter in a showhoteldetails action to index.php.
SQL injection vulnerability in the GameQ (comgameq) component 4.0 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the categoryid parameter in a page action to index.php.