PHP remote file inclusion vulnerability in toolbarext.php in the BookLibrary (combooklibrary) component 1.5.2.4 Basic for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter.
Multiple SQL injection vulnerabilities in the BookLibrary Basic (combooklibrary) component 1.5.3 before 1.5.320100620 for Joomla! allow remote attackers to execute arbitrary SQL commands via the bid[] parameter in a (1) lendrequest or (2) savelendrequest action to index.php, the id parameter in a (3) mdownload or (4) downitsf action to index.php, or (5) the searchtext parameter in a search action to index.php.