jcomments,versions 3.0.5 and all previous, inadequate input validation of object_group parameter leads to possible exploits including arbitrary local file inclusion
resolution: update to version 3.0.6
There is evidence that this is being actively exploited, so users are recommended to update ASAP.
update notice: http://www.joomlatune.com/n28-104.html