CVE-2015-7297
NUCLEIJoomla! - SQL Injection
Title source: ruleDescription
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2015-7858.
Exploits (5)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotephp
https://www.exploit-db.com/exploits/38797
nomisec
SCANNER
1 stars
by Cappricio-Securities · poc
https://github.com/Cappricio-Securities/CVE-2015-7297
nomisec
WORKING POC
1 stars
by CCrashBandicot · poc
https://github.com/CCrashBandicot/ContentHistory
metasploit
WORKING POC
by Asaf Orpani, bperry, Nixawk · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/joomla_contenthistory_sqli.rb
Nuclei Templates (1)
Joomla! Core SQL Injection
HIGHby princechaddha
Shodan:
http.html:"joomla! - open source content management" || http.component:"joomla" || cpe:"cpe:2.3:a:joomla:joomla\!"
FOFA:
body="joomla! - open source content management"
References (9)
Scores
EPSS
0.9161
EPSS Percentile
99.7%
Details
CWE
CWE-89
Status
published
Products (15)
joomla/joomla\!
3.2.0
joomla/joomla\!
3.2.1
joomla/joomla\!
3.2.2
joomla/joomla\!
3.2.3
joomla/joomla\!
3.2.4
joomla/joomla\!
3.3.0
joomla/joomla\!
3.3.1
joomla/joomla\!
3.3.2
joomla/joomla\!
3.3.3
joomla/joomla\!
3.3.4
... and 5 more
Published
Oct 29, 2015
Tracked Since
Feb 18, 2026