filter_sql of the file code.php of the component Uploader. The manipulation of the argument id leads to sql injection.This vulnerability is traded as CVE-2009-1742. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
SOCIAL SHARE CARD GENERATOR