Joomla · Joomla! Akobook · CVE-2009-2638
**Name of the Vulnerable Software and Affected Versions**
Joomla! AkoBook component version 2.3
**Description**
The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the `gbid` parameter in a reply action to "index.php".
**Recommendations**
For version 2.3, consider restricting access to the reply action in index.php to minimize the risk of exploitation. Avoid using the `gbid` parameter in the affected API endpoint until the issue is resolved.