The Aardvertiser component before 2.2.1 for Joomla! uses insecure permissions (777) in unspecified folders, which allows local users to modify, create, or delete certain files.
https://exchange.xforce.ibmcloud.com/vulnerabilities/60927
http://www.securityfocus.com/bid/42239
http://sourceforge.net/projects/aardvertiser/forums/forum/989030/topic/3788365