SQL injection vulnerability in the Slide Show (comslideshow) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.
PHP remote file inclusion vulnerability in admin.slideshow1.php in the Flash Slide Show (comslideshow) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfiglivesite parameter.