CVE-2015-8562
HIGH 7.5EPSS 98.3%
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the HTTP User-Agent header, as exploited in the wild in December 2015.
- CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 98.28% chance of exploitation in the next 30 days, 100th percentile
- Nuclei
- high
- Published
- 2015-12-16
- Updated
- 2024-08-06
Proof-of-concept exploits (13)
- http://www.securityfocus.com/archive/1/537219/100/0/threaded
- http://www.rapid7.com/db/modules/exploit/multi/http/joomla_http_header_rce
- Caihuar/Joomla-cve-2015-85621★ · 2022-09-23
- RobinHoutevelts/Joomla-CVE-2015-8562-PHP-POC2★ · 2016-01-05
- VoidSec/Joomla_CVE-2015-856211★ · 2024-05-03
- ZaleHack/joomla_rce_CVE-2015-85628★ · 2016-01-04
- atcasanova/cve-2015-8562-exploit0★ · 2016-02-08
- guanjivip/CVE-2015-85620★ · 2020-07-25
- lorenzodegiorgi/setup-cve-2015-85620★ · 2021-05-03
- paralelo14/CVE-2015-85624★ · 2017-01-08
- parzel/rusty-joomla-rce1★ · 2020-12-03
- thejackerz/scanner-exploit-joomla-CVE-2015-85620★ · 2016-06-08
- xnorkl/Joomla_Payload0★ · 2020-02-07