PHP remote file inclusion vulnerability in shambo2.php in the Shambo2 (comshambo2) component for Mambo 4.5 allows remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter.
SQL injection vulnerability in index.php in the Shambo2 (comshambo2) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter.