CVE-2015-7297

NUCLEI

Joomla! - SQL Injection

Title source: rule

Description

SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2015-7858.

Exploits (5)

nomisec SCANNER 1 stars
by Cappricio-Securities · poc
https://github.com/Cappricio-Securities/CVE-2015-7297
nomisec WORKING POC 1 stars
by CCrashBandicot · poc
https://github.com/CCrashBandicot/ContentHistory
nomisec WORKING POC
by areaventuno · poc
https://github.com/areaventuno/exploit-joomla
exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotephp
https://www.exploit-db.com/exploits/38797
metasploit WORKING POC
by Asaf Orpani, bperry, Nixawk · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/joomla_contenthistory_sqli.rb

Nuclei Templates (1)

Joomla! Core SQL Injection
HIGHby princechaddha
Shodan: http.html:"joomla! - open source content management" || http.component:"joomla" || cpe:"cpe:2.3:a:joomla:joomla\!"
FOFA: body="joomla! - open source content management"

Scores

EPSS 0.9161
EPSS Percentile 99.7%

Classification

CWE
CWE-89
Status draft

Affected Products (15)

joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!

Timeline

Published Oct 29, 2015
Tracked Since Feb 18, 2026