Directory traversal vulnerability in the BF Survey (combfsurvey) component for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.
SQL injection vulnerability in the BF Survey Pro (combfsurveypro) component before 1.3.1, BF Survey Pro Free (combfsurveyprofree) component 1.2.6, and BF Survey Basic component before 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php. NOTE: some of these details are obtained from third party information.