Joomla Improper Input Validation Vulnerability - CVE-2008-4105
JRequest in Joomla 1.5 before 1.5.7 does not sanitize variables that were set with JRequest::setVar which allows remote attackers to conduct quotvariable injectionquot attacks and have unspecified other impact.