SQL injection vulnerability in the com_detail component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. NOTE: this issue might be site-specific. If so, it should not be included in CVE.
http://www.securityfocus.com/archive/1/488325/100/0/threaded
http://www.securityfocus.com/archive/1/488278/100/0/threaded