SQL injection vulnerability in the GBU Facebook (com_gbufacebook) component 1.0.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the face_id parameter in a show_face action to index.php.Referenceshttp://www.securityfocus.com/bid/39576https://exchange.xforce.ibmcloud.com/vulnerabilities/57946http://www.vupen.com/english/advisories/2010/0944http://packetstormsecurity.org/1004-exploits/joomlagbufacebook-sql.txthttp://www.exploit-db.com/exploits/12299http://secunia.com/advisories/39487