PHP remote file inclusion vulnerability in admin.slideshow1.php in the Flash Slide Show (comslideshow) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfiglivesite parameter.
SQL injection vulnerability in the Slide Show (comslideshow) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.