Multiple SQL injection vulnerabilities in index.php in Joomla! 1.5 RC3 allow remote attackers to execute arbitrary SQL commands via (1) the view parameter to the comcontent component, (2) the task parameter to the comsearch component, or (3) the option parameter in a search action to the comsearch component.
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.5.7 and earlier allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) the title and description parameters to the comweblinks module and (2) unspecified vectors in the comcontent module related to "article submission."