CVE-2015-7858

EXPLOITED

Joomla! <3.4.4 - SQL Injection

Title source: llm

Description

SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2015-7297.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotephp
https://www.exploit-db.com/exploits/38797
vulncheck_xdb WORKING POC
remote-auth
https://github.com/areaventuno/exploit-joomla
metasploit WORKING POC EXCELLENT
by Asaf Orpani · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/joomla_contenthistory_sqli_rce.rb

Scores

EPSS 0.6911
EPSS Percentile 98.6%

Details

VulnCheck KEV 2015-10-26
CWE
CWE-89
Status published
Products (14)
joomla/joomla\! 3.2.0
joomla/joomla\! 3.2.1
joomla/joomla\! 3.2.2
joomla/joomla\! 3.2.3
joomla/joomla\! 3.2.4
joomla/joomla\! 3.3.0
joomla/joomla\! 3.3.1
joomla/joomla\! 3.3.2
joomla/joomla\! 3.3.3
joomla/joomla\! 3.3.4
... and 4 more
Published Oct 29, 2015
Tracked Since Feb 18, 2026