目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2015-8562 PoC — Joomla! Core 远程代码执行漏洞

来源
关联漏洞
标题: Joomla! Core 远程代码执行漏洞 (CVE-2015-8562)
Description:Joomla!是美国Open Source Matters团队的一套使用PHP和MySQL开发的开源、跨平台的内容管理系统(CMS)。 Joomla!中存在安全漏洞。远程攻击者可借助HTTP User-Agent头利用该漏洞实施PHP对象注入攻击,执行任意PHP代码。以下版本受到影响:Joomla! 1.5.x版本,2.x版本,3.4.6之前3.x版本。(在2015年12月广泛利用)
Description
Modified PoC exploit demonstrating remote code execution via object injection vulnerability in Joomla! 1.5.0 through 3.4.5 (CVE-2015-8562).
介绍
# Joomla! Object Injection RCE (Modified PoC)

This is a **modified** Proof of Concept exploit for the Joomla! vulnerability  
affecting versions **1.5.0 through 3.4.5** (CVE-2015-8562). The vulnerability  
allows remote code execution via PHP object injection.

## Usage

1. Update the target URL in the script.
2. Customize the payload as needed.
3. Run the script to test if the Joomla! instance is vulnerable.

## Disclaimer

This tool is for educational and authorized testing purposes only.  
Do not use it on systems without explicit permission.

## References

- [CVE-2015-8562](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8562)  
- [Original Joomla! Advisory](https://developer.joomla.org/security-centre/630-20151104-core-remote-code-execution.html)
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →