SQL Injection exists in the AlphaIndex Dictionaries 1.0 component for Joomla! via the letter parameter.
multiplanet alphaindex dictionaries 1.0