SQL injection vulnerability in webhosting.php in the Webhosting Component (com_webhosting) module before 1.1 RC7 for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.
https://www.exploit-db.com/exploits/5527
https://exchange.xforce.ibmcloud.com/vulnerabilities/42124
https://euvd.enisa.europa.eu/vulnerability/EUVD-2008-6615