VulnerabilityModified
CVE-2015-8562
1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the HTTP User-Agent header, as exploited in the wild in December 2015.
HIGH 7.5EPSS 98.3%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 98.3%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the HTTP User-Agent header, as exploited in the wild in December 2015.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 98.28% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- joomla/joomla\!
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/134949/Joomla-HTTP-Header-Unauthenticated-Remote-Code-Execution.htmlExploit
- http://packetstormsecurity.com/files/135100/Joomla-3.4.5-Object-Injection.html
- http://www.rapid7.com/db/modules/exploit/multi/http/joomla_http_header_rce
- http://www.securityfocus.com/archive/1/537219/100/0/threaded
- http://www.securityfocus.com/bid/79195
- https://blog.sucuri.net/2015/12/remote-command-execution-vulnerability-in-joomla.htmlExploit
- https://developer.joomla.org/security-centre/630-20151214-core-remote-code-execution-vulnerability.htmlVendor Advisory
- https://www.exploit-db.com/exploits/38977/Exploit
- https://www.exploit-db.com/exploits/39033/Exploit
- http://packetstormsecurity.com/files/134949/Joomla-HTTP-Header-Unauthenticated-Remote-Code-Execution.htmlExploit
- http://packetstormsecurity.com/files/135100/Joomla-3.4.5-Object-Injection.html
- http://www.rapid7.com/db/modules/exploit/multi/http/joomla_http_header_rce
- http://www.securityfocus.com/archive/1/537219/100/0/threaded
- http://www.securityfocus.com/bid/79195
- https://blog.sucuri.net/2015/12/remote-command-execution-vulnerability-in-joomla.htmlExploit
- https://developer.joomla.org/security-centre/630-20151214-core-remote-code-execution-vulnerability.htmlVendor Advisory
- https://www.exploit-db.com/exploits/38977/Exploit
- https://www.exploit-db.com/exploits/39033/Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.