CVE-2015-7857

Joomla! <3.4.5 - SQL Injection

Title source: llm

Description

SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.php in Joomla! 3.2 before 3.4.5 allows remote attackers to execute arbitrary SQL commands via the list[select] parameter to index.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotephp
https://www.exploit-db.com/exploits/38797

Scores

EPSS 0.7218
EPSS Percentile 98.7%

Classification

CWE
CWE-89
Status draft

Affected Products (15)

joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!

Timeline

Published Oct 29, 2015
Tracked Since Feb 18, 2026