PHP remote file inclusion vulnerability in facileforms.frame.php in the FacileForms (comfacileforms) component 1.4.4 for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the ffcompath parameter.
SQL injection vulnerability in the Facile Forms (comfacileforms) component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.
Cross-site scripting (XSS) vulnerability in the Facileforms (comfacileforms) component for Joomla! and Mambo allows remote attackers to inject arbitrary web script or HTML via the Itemid parameter to index.php.