PHP remote file inclusion vulnerability in index.php in Joomla! 1.0.11 through 1.0.14, when RGEMULATION is enabled in configuration.php, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter.
Directory traversal vulnerability in attachmentlibrary.php in the XStandard component for Joomla! 1.5.8 and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in the XCMSLIBRARYPATH HTTP header.
Cross-site scripting (XSS) vulnerability in the comsearch component in Joomla! 1.0.13 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchword parameter. NOTE: this might be related to CVE-2007-4189.1.
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.5.7 and earlier allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) the title and description parameters to the comweblinks module and (2) unspecified vectors in the comcontent module related to "article submission."