CVE-2015-7297
CVE-2015-7297
Vexday Risk Score
60Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS —EPSS 100.0%KEV nãoPoC públicaNuclei simMetasploit simPatch —
Lifecycle
22 Oct 2015Metasploit module available
29 Oct 2015Published on NVD
02 Nov 2015Public PoC
Recommendation: Plan a near-term fix — a public PoC already exists.
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2015-7858.
Affected products
n/a · n/apublic PoCs found — 7
githubgithub.com/CCrashBandicot/ContentHistory★ 1githubgithub.com/Cappricio-Securities/CVE-2015-7297★ 1githubgithub.com/areaventuno/exploit-joomla★ 0cve_referencewww.exploit-db.com/exploits/38797/unverifiedcve_referencepacketstormsecurity.com/files/134097/Joomla-3.44-SQL-Injection.htmlunverifiedexploitdbwww.exploit-db.com/exploits/38797unverifiedcve_referencepacketstormsecurity.com/files/134494/Joomla-Content-History-SQL-Injection-Remote-Code-Execution.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://developer.joomla.org/security-centre/628-20151001-core-sql-injection.htmlhttp://packetstormsecurity.com/files/134097/Joomla-3.44-SQL-Injection.htmlhttp://packetstormsecurity.com/files/134494/Joomla-Content-History-SQL-Injection-Remote-Code-Execution.htmlhttps://www.exploit-db.com/exploits/38797/https://www.trustwave.com/Resources/SpiderLabs-Blog/Joomla-SQL-Injection-Vulnerability-Exploit-Results-in-Full-Administrative-Access/http://www.rapid7.com/db/modules/auxiliary/gather/joomla_contenthistory_sqlihttp://www.rapid7.com/db/modules/exploit/unix/webapp/joomla_contenthistory_sqli_rcehttp://www.securityfocus.com/bid/77295http://www.securitytracker.com/id/1033950