CVE-2010-0374
Cross-site scripting (XSS) vulnerability in the Marketplace (com_marketplace) component 1.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the catid parameter in a show_category action to index.php.
Date published : 2010-01-21
http://www.securityfocus.com/bid/37819
http://www.packetstormsecurity.com/1001-exploits/joomlamarketplace-xss.txt