See how fernando soares compares to other vendors in security performance
PHP remote file inclusion vulnerability in mamboleto.php in the Fernando Soares Mamboleto (commamboleto) component 2.0 RC3 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter.