Joomla · Com Philaform · CVE-2007-2933
**Name of the Vulnerable Software and Affected Versions**
com philaform versions 1.2.0.0 and earlier
**Description**
The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the `form id` parameter in the index.php file of the com philaform component for Joomla!.
**Recommendations**
For versions 1.2.0.0 and earlier, avoid using the `form id` parameter in the affected API endpoint until the issue is resolved. As a temporary workaround, consider restricting access to the index.php file in the com philaform component to minimize the risk of exploitation.