Cross-site scripting (XSS) vulnerability in the JFaq (com_jfaq) component 1.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the question parameter in an add2 action to index.php.Referenceshttp://osvdb.org/65694http://www.securityfocus.com/bid/41029http://secunia.com/advisories/40219http://packetstormsecurity.org/1006-exploits/joomlajfaq-sqlxss.txt