CVE-2015-7857

Joomla! 3.2-3.4.4 - SQL Injection via list[select] Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2015-7857. PoCs published by Metasploit, Asaf Orpani, including Metasploit module exploits/unix/webapp/joomla_contenthistory_sqli_rce.

AI-analyzed exploit summary This Metasploit module exploits a SQL injection vulnerability in Joomla's Content History component to retrieve admin session cookies, then leverages them to create a malicious PHP template file for remote code execution.

Description

SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.php in Joomla! 3.2 before 3.4.5 allows remote attackers to execute arbitrary SQL commands via the list[select] parameter to index.php.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotephp
https://www.exploit-db.com/exploits/38797

This Metasploit module exploits a SQL injection vulnerability in Joomla's Content History component to retrieve admin session cookies, then leverages them to create a malicious PHP template file for remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Joomla 3.2 to 3.4.4
No auth needed
Prerequisites: Joomla installation with vulnerable version · Active admin session
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Asaf Orpani · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/joomla_contenthistory_sqli_rce.rb

This Metasploit module exploits a SQL injection vulnerability in Joomla's Content History component to retrieve admin session cookies, then uses them to authenticate and achieve remote code execution by creating a malicious PHP template file.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Joomla 3.2 to 3.4.4
No auth needed
Prerequisites: Joomla installation with vulnerable version · Active admin session
devstral-2 · analyzed Apr 30, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/77295
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1033950
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/38797/

Scores

EPSS 0.7218
EPSS Percentile 98.8%

Details

CWE
CWE-89
Status published
Products (15)
joomla/joomla\! 3.2.0
joomla/joomla\! 3.2.1
joomla/joomla\! 3.2.2
joomla/joomla\! 3.2.3
joomla/joomla\! 3.2.4
joomla/joomla\! 3.3.0
joomla/joomla\! 3.3.1
joomla/joomla\! 3.3.2
joomla/joomla\! 3.3.3
joomla/joomla\! 3.3.4
... and 5 more
Published Oct 29, 2015
Tracked Since Feb 18, 2026