SQL injection vulnerability in the jTips (com_jtips) component 1.0.7 and 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the season parameter in a ladder action to index.php.Referenceshttp://www.securityfocus.com/bid/36123http://www.exploit-db.com/exploits/9504http://www.vupen.com/english/advisories/2009/2405