Well what do you know... I installed version 1.1.2.2 of this component in Joomla and sure enough, the exploits work as long as register_globals is enabled! George -- theall at tenablesecurity.com