CVE-2015-2562

Web-Dorado ECommerce WD for Joomla! search_category_id SQL Injection Scanner

Title source: metasploit
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2015-2562. PoCs published by Brandon Perry, bperry, including Metasploit module auxiliary/scanner/http/joomla_ecommercewd_sqli_scanner.

AI-analyzed exploit summary This exploit demonstrates unauthenticated SQL injection vulnerabilities in the ECommerce-WD Joomla plugin via multiple POST parameters. It includes payloads for boolean-based blind, error-based, and time-based blind SQLi attacks.

Description

Multiple SQL injection vulnerabilities in the Web-Dorado ECommerce WD (com_ecommercewd) component 1.2.5 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) search_category_id, (2) sort_order, or (3) filter_manufacturer_ids in a displayproducts action to index.php.

Exploits (2)

exploitdb WORKING POC
by Brandon Perry · textwebappsphp
https://www.exploit-db.com/exploits/36439

This exploit demonstrates unauthenticated SQL injection vulnerabilities in the ECommerce-WD Joomla plugin via multiple POST parameters. It includes payloads for boolean-based blind, error-based, and time-based blind SQLi attacks.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: ECommerce-WD Joomla plugin version 1.2.5
No auth needed
Prerequisites: Joomla installation with vulnerable ECommerce-WD plugin
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit SCANNER
by bperry · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/joomla_ecommercewd_sqli_scanner.rb

This Metasploit auxiliary module scans for an unauthenticated SQL injection vulnerability in Web-Dorado ECommerce WD for Joomla! by injecting a UNION-based payload into the 'search_category_id' parameter and checking for a pattern in the response.

Classification
Scanner 100%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Web-Dorado ECommerce WD for Joomla! 1.2.5 and prior
No auth needed
Prerequisites: Target must have the vulnerable Joomla extension installed and accessible
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/36439/
Exploit mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2015/Mar/123
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/73285

Scores

EPSS 0.3895
EPSS Percentile 98.4%

Details

CWE
CWE-89
Status published
Products (1)
web-dorado/ecommerce_wd 1.2.5
Published Mar 20, 2015
Tracked Since Feb 18, 2026