CVE-2015-8562
CVE-2015-8562
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the HTTP User-Agent header, as exploited in the wild in December 2015.
Productos afectados
n/a · n/aPoCs públicas encontradas — 17
githubgithub.com/VoidSec/Joomla_CVE-2015-8562★ 10githubgithub.com/ZaleHack/joomla_rce_CVE-2015-8562★ 8githubgithub.com/paralelo14/CVE-2015-8562★ 4githubgithub.com/RobinHoutevelts/Joomla-CVE-2015-8562-PHP-POC★ 2githubgithub.com/Caihuar/Joomla-cve-2015-8562★ 1githubgithub.com/guanjivip/CVE-2015-8562★ 0githubgithub.com/xnorkl/Joomla_Payload★ 0githubgithub.com/lorenzodegiorgi/setup-cve-2015-8562★ 0githubgithub.com/drolley919/joomla-cve-2015-8562-exploit-and-linux-forensic-analysis★ 0githubgithub.com/atcasanova/cve-2015-8562-exploit★ 0githubgithub.com/thejackerz/scanner-exploit-joomla-CVE-2015-8562★ 0exploitdbwww.exploit-db.com/exploits/39033no verificadocve_referencepacketstormsecurity.com/files/135100/Joomla-3.4.5-Object-Injection.htmlno verificadocve_referencewww.exploit-db.com/exploits/38977/no verificadocve_referencewww.exploit-db.com/exploits/39033/no verificadoexploitdbwww.exploit-db.com/exploits/38977no verificadocve_referencepacketstormsecurity.com/files/134949/Joomla-HTTP-Header-Unauthenticated-Remote-Code-Execution.htmlno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://packetstormsecurity.com/files/134949/Joomla-HTTP-Header-Unauthenticated-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/135100/Joomla-3.4.5-Object-Injection.htmlhttps://blog.sucuri.net/2015/12/remote-command-execution-vulnerability-in-joomla.htmlhttps://developer.joomla.org/security-centre/630-20151214-core-remote-code-execution-vulnerability.htmlhttps://www.exploit-db.com/exploits/38977/https://www.exploit-db.com/exploits/39033/http://www.rapid7.com/db/modules/exploit/multi/http/joomla_http_header_rcehttp://www.securityfocus.com/archive/1/537219/100/0/threadedhttp://www.securityfocus.com/bid/79195