[原文]Multiple SQL injection vulnerabilities in Joomla! before 1.0.10 allow remote attackers to execute arbitrary SQL commands via unspecified parameters involving the (1) "Remember Me" function, (2) "Related Items" module, and the (3) "Weblinks submission".
Joomla! contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the application not properly sanitizing user-supplied input to the 'Remember Me' functionality. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
Upgrade to version 1.0.10 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.