⚠ Exploited in the wild
Exploitation observed in the wild. Not yet on CISA KEV.
CVE-2015-8562 — Improper Input Validation in Joomla !
Severity
7.5HIGHNVD
EPSS
92.9%
top 0.22%
CISA KEV
Not in KEV
Exploit
Exploited in wild
Active exploitation observed
Affected products
Timeline
PublishedDec 16
Latest updateMay 14
Description
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the HTTP User-Agent header, as exploited in the wild in December 2015.
CVSS vector
AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4
Affected Packages1 packages
🔴Vulnerability Details
3💥Exploits & PoCs
4Exploit-DB
▶
Nuclei▶
Joomla HTTP Header Unauthenticated - Remote Code Execution