SQL injection vulnerability in sub_votepic.php in the Datsogallery (com_datsogallery) module 1.6 for Joomla! allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header.
https://www.exploit-db.com/exploits/5583
https://exchange.xforce.ibmcloud.com/vulnerabilities/42324