CVE-2015-7857

Joomla! <3.4.5 - SQL Injection

Title source: llm

Description

SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.php in Joomla! 3.2 before 3.4.5 allows remote attackers to execute arbitrary SQL commands via the list[select] parameter to index.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotephp
https://www.exploit-db.com/exploits/38797

Scores

EPSS 0.7218
EPSS Percentile 98.8%

Details

CWE
CWE-89
Status published
Products (15)
joomla/joomla\! 3.2.0
joomla/joomla\! 3.2.1
joomla/joomla\! 3.2.2
joomla/joomla\! 3.2.3
joomla/joomla\! 3.2.4
joomla/joomla\! 3.3.0
joomla/joomla\! 3.3.1
joomla/joomla\! 3.3.2
joomla/joomla\! 3.3.3
joomla/joomla\! 3.3.4
... and 5 more
Published Oct 29, 2015
Tracked Since Feb 18, 2026