Unspecified vulnerability in com_content in Joomla! before 1.0.11, when $mosConfig_hideEmail is set, allows attackers to perform the emailform and emailsend tasks.
http://www.vupen.com/english/advisories/2006/3408
http://www.joomla.org/content/view/1843/74/