Multiple SQL injection vulnerabilities in index.php in Joomla! 1.5 RC3 allow remote attackers to execute arbitrary SQL commands via (1) the view parameter to the comcontent component, (2) the task parameter to the comsearch component, or (3) the option parameter in a search action to the comsearch component.