Multiple SQL injection vulnerabilities in the BookLibrary Basic (combooklibrary) component 1.5.3 before 1.5.320100620 for Joomla! allow remote attackers to execute arbitrary SQL commands via the bid[] parameter in a (1) lendrequest or (2) savelendrequest action to index.php, the id parameter in a (3) mdownload or (4) downitsf action to index.php, or (5) the searchtext parameter in a search action to index.php.
PHP remote file inclusion vulnerability in toolbarext.php in the BookLibrary (combooklibrary) component 1.5.2.4 Basic for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter.