Joomla!是美国Open Source Matters团队的一套使用PHP和MySQL开发的开源、跨平台的内容管理系统(CMS)。 Joomla!中存在安全漏洞。远程攻击者可借助HTTP User-Agent头利用该漏洞实施PHP对象注入攻击,执行任意PHP代码。以下版本受到影响:Joomla! 1.5.x版本,2.x版本,3.4.6之前3.x版本。(在2015年12月广泛利用)
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | All versions of the Joomla! below 3.4.6 are known to be vulnerable. But exploitation is possible with PHP versions below 5.5.29, 5.6.13 and below 5.5. | https://github.com/ZaleHack/joomla_rce_CVE-2015-8562 | POC详情 |
| 2 | A proof of concept for Joomla's CVE-2015-8562 vulnerability | https://github.com/RobinHoutevelts/Joomla-CVE-2015-8562-PHP-POC | POC详情 |
| 3 | CVE-2015-8562 Exploit in bash | https://github.com/atcasanova/cve-2015-8562-exploit | POC详情 |
| 4 | None | https://github.com/thejackerz/scanner-exploit-joomla-CVE-2015-8562 | POC详情 |
| 5 | Joomla 1.5 - 3.4.5 Object Injection RCE X-Forwarded-For header | https://github.com/paralelo14/CVE-2015-8562 | POC详情 |
| 6 | A proof of concept for Joomla's CVE-2015-8562 vulnerability (Object Injection RCE) | https://github.com/VoidSec/Joomla_CVE-2015-8562 | POC详情 |
| 7 | Adapted CVE-2015-8562 payload | https://github.com/xnorkl/Joomla_Payload | POC详情 |
| 8 | 没有编写完成,以后学习更多知识在回来完善 | https://github.com/guanjivip/CVE-2015-8562 | POC详情 |
| 9 | Docker-compose to set up a test environment for exploiting CVE-2015-8562 | https://github.com/lorenzodegiorgi/setup-cve-2015-8562 | POC详情 |
| 10 | None | https://github.com/Caihuar/Joomla-cve-2015-8562 | POC详情 |
| 11 | Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the HTTP User-Agent header, as exploited in the wild in December 2015 | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2015/CVE-2015-8562.yaml | POC详情 |
| 12 | None | https://github.com/Threekiii/Awesome-POC/blob/master/CMS%E6%BC%8F%E6%B4%9E/Joomla%203.4.5%20%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E%20CVE-2015-8562.md | POC详情 |
| 13 | https://github.com/vulhub/vulhub/blob/master/joomla/CVE-2015-8562/README.md | POC详情 | |
| 14 | Modified PoC exploit demonstrating remote code execution via object injection vulnerability in Joomla! 1.5.0 through 3.4.5 (CVE-2015-8562). | https://github.com/Anonydra/joomla-1.5-3.4.5-rce | POC详情 |
未找到公开 POC。
登录以生成 AI POC| CVE-2015-5304 | Red Hat JBoss Enterprise Application Platform 拒绝服务漏洞 | |
| CVE-2015-7221 | Mozilla Firefox 缓冲区溢出漏洞 | |
| CVE-2015-7222 | Mozilla Firefox和Firefox ESR libstagefright 整数溢出漏洞 | |
| CVE-2015-7223 | Mozilla Firefox WebExtension APIs 安全漏洞 | |
| CVE-2015-6425 | Cisco Unified Communications Manager Identity Management子系统资源管理错误漏洞 | |
| CVE-2015-8000 | ISC BIND named 拒绝服务漏洞 | |
| CVE-2015-8461 | ISC BIND named 竞争条件漏洞 | |
| CVE-2015-8577 | McAfee VirusScan Enterprise Buffer Overflow Protection功能安全漏洞 | |
| CVE-2015-8578 | AVG Internet Security 安全漏洞 | |
| CVE-2015-8579 | Kaspersky Total Security 安全漏洞 | |
| CVE-2015-7220 | Mozilla Firefox 缓冲区溢出漏洞 | |
| CVE-2015-8357 | Bitrix bitrix.xscan模块目录遍历漏洞 | |
| CVE-2015-8358 | Bitrix bitrix.mpbuilder模块目录遍历漏洞 | |
| CVE-2015-8476 | PHPMailer‘class.phpmailer.php’CRLF注入漏洞 | |
| CVE-2015-8563 | Joomla! com_templates组件跨站请求伪造漏洞 | |
| CVE-2015-8564 | Joomla! 目录遍历漏洞 | |
| CVE-2015-8565 | Joomla! 目录遍历漏洞 | |
| CVE-2015-8566 | Joomla! Framework Session程序包远程代码执行漏洞 | |
| CVE-2015-8580 | Foxit Reader和Foxit PhantomPDF 释放后重用漏洞 | |
| CVE-2015-7211 | Mozilla Firefox 输入验证漏洞 |
显示前 20 条,共 38 条。 查看全部 → →
暂无评论