An update for MyBlog for Joomla 1.5 has been released. This patch addresses an issue where attacker may read any arbitrary file within the server, if the php process has a full read access to those files.
Affected software: MyBlog 3.x for Joomla 1.5
Recommendation: Customers should apply the patch immediately.
To install this patch
Patch file: myblog.zip