CVE-2017-8917
CVE-2017-8917
Vexday Risk Score
60Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS —EPSS 99.8%KEV nãoPoC públicaNuclei simMetasploit simPatch —
Lifecycle
17 May 2017Metasploit module available
17 May 2017Published on NVD
19 May 2017Public PoC
Recommendation: Plan a near-term fix — a public PoC already exists.
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors.
Affected products
n/a · n/apublic PoCs found — 15
githubgithub.com/stefanlucas/Exploit-Joomla★ 67githubgithub.com/brianwrf/Joomla3.7-SQLi-CVE-2017-8917★ 7githubgithub.com/AkuCyberSec/CVE-2017-8917-Joomla-370-SQL-Injection★ 2githubgithub.com/BaptisteContreras/CVE-2017-8917-Joomla★ 2githubgithub.com/ztrxwzy/joomla.3.7.0exploit★ 1githubgithub.com/yayateayayatea/cve-2017-8917★ 0githubgithub.com/gloliveira1701/Joomblah★ 0githubgithub.com/cved-sources/cve-2017-8917★ 0githubgithub.com/gmohlamo/CVE-2017-8917★ 0githubgithub.com/Siopy/CVE-2017-8917★ 0githubgithub.com/ionutbaltariu/joomla_CVE-2017-8917★ 0exploitdbwww.exploit-db.com/exploits/44358unverifiedcve_referencewww.exploit-db.com/exploits/44358/unverifiedexploitdbwww.exploit-db.com/exploits/42033unverifiedcve_referencewww.exploit-db.com/exploits/42033/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →