See how weberr compares to other vendors in security performance
Directory traversal vulnerability in captcha/captchaimage.php in the RWCards (comrwcards) 3.0.11 component for Joomla!, when magicquotesgpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the img parameter.
Directory traversal vulnerability in index.php in the RWCards (comrwcards) component 3.0.18 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter.