CVE-2017-8917
CRITICAL NUCLEIJoomla! <3.7.1 - SQL Injection
Title source: llmDescription
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors.
Exploits (17)
nomisec
WORKING POC
2 stars
by AkuCyberSec · poc
https://github.com/AkuCyberSec/CVE-2017-8917-Joomla-370-SQL-Injection
nomisec
WORKING POC
2 stars
by BaptisteContreras · poc
https://github.com/BaptisteContreras/CVE-2017-8917-Joomla
github
WORKING POC
1 stars
by vaishakhcv · perlpoc
https://github.com/vaishakhcv/CVE-exploits/tree/master/CVE-2017-8917
github
WORKING POC
by winterwolf32 · perlpoc
https://github.com/winterwolf32/CVE_Exploits-/tree/master/CVE-2017-8917
metasploit
WORKING POC
EXCELLENT
by Mateus Lino · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/joomla_comfields_sqli_rce.rb
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubywebappsphp
https://www.exploit-db.com/exploits/44358
Nuclei Templates (1)
Joomla! <3.7.1 - SQL Injection
CRITICALVERIFIEDby princechaddha
Shodan:
http.component:"Joomla" || http.html:"joomla! - open source content management" || http.component:"joomla" || cpe:"cpe:2.3:a:joomla:joomla\!"
FOFA:
body="joomla! - open source content management"
References (5)
Scores
CVSS v3
9.8
EPSS
0.9451
EPSS Percentile
100.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-89
Status
draft
Affected Products (1)
joomla/joomla\!
Timeline
Published
May 17, 2017
Tracked Since
Feb 18, 2026