← back
CVE-2015-7857

CVE-2015-7857

60Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 94%
from disclosure to weapon25 days
Published on NVDOct 29
1st PoC+25d
metasploitOct 23
exploitation probability
94%top 1% of all CVEs
observed exploitation
nono source reports it
4 public exploit(s)
SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.php in Joomla! 3.2 before 3.4.5 allows remote attackers to execute arbitrary SQL commands via the list[select] parameter to index.php.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.