CVE-2015-7857
HIGH 7.5EPSS 94.5%
SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.php in Joomla! 3.2 before 3.4.5 allows remote attackers to execute arbitrary SQL commands via the list[select] parameter to index.php.
- CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 94.47% chance of exploitation in the next 30 days, 100th percentile
- Published
- 2015-10-29
- Updated
- 2024-08-06
Proof-of-concept exploits (17)
- https://www.trustwave.com/Resources/SpiderLabs-Blog/Joomla-SQL-Injection-Vulnerability-Ex…
- http://www.rapid7.com/db/modules/exploit/unix/webapp/joomla_contenthistory_sqli_rce
- Ciber1401/Mai1★ · 2020-01-22
- Jahismighty/maltrail0★ · 2018-12-26
- JustF0rWork/malware3★ · 2016-01-12
- Mezantrop74/MAILTRAIL5★ · 2021-09-05
- Pythunder/maltrail5★ · 2020-10-27
- RsbCode/maltrail0★ · 2017-08-15
- Youhoohoo/maltrail-iie4★ · 2020-01-07
- a-belard/maltrail0★ · 2026-05-27
- areaventuno/exploit-joomla0★ · 2020-09-13
- hxp2k6/https-github.com-stamparm-maltrail9★ · 2015-12-17
- khanzjob/maltrail0★ · 2024-08-06
- mukarramkhalid/joomla-sqli-mass-exploit29★ · 2021-08-17
- rsumner31/maltrail1★ · 2018-02-23
- uni-tue-kn/MalFIX0★ · 2025-03-24
- yasir27uk/maltrail3★ · 2021-02-22