SQL injection vulnerability in the SermonSpeaker (com_sermonspeaker) component before 3.2.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a speakerpopup action to index.php. NOTE: some of these details are obtained from third party information.
http://secunia.com/advisories/39385
http://joomlacode.org/gf/project/sermon_speaker/news/?action=NewsThreadView&id=2549