SQL injection vulnerability in the iJoomla News Portal (comnewsportal) component 1.0 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.
SQL injection vulnerability in index.php in the Giorgio Nordo Ricette (comricette) 1.0 component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter.