Multiple SQL injection vulnerabilities in the Mambo Resident (aka Mos Res or commosres) component 1.0f for Mambo and Joomla!, when magicquotesgpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) propertyuid parameter in a viewproperty action to index.php and the (2) regID parameter in a showregion action to index.php.