SQL injection vulnerability in the RokModule (com_rokmodule) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the moduleid parameter in a raw action to index.php.
http://www.rockettheme.com/extensions-updates/673-rokmodule-security-update-released
http://www.rockettheme.com/extensions-downloads/free/rokmodule/1040-rokmodule-component/download