7.5
CVSSv2

CVE-2015-8566

Published: 16/12/2015 Updated: 17/12/2015
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Session package 1.x prior to 1.3.1 for Joomla! Framework allows remote malicious users to execute arbitrary code via unspecified session values.

Vulnerable Product Search on Vulmon Subscribe to Product

joomla session 1.3.0

Exploits

#!/usr/bin/env python # Exploit Title: Joomla 15 - 345 Object Injection RCE X-Forwarded-For header # Date: 12/17/2015 # Exploit Author: original - Gary@ Sec-1 ltd, Modified - Andrew McNicol BreakPoint Labs (@0xcc_labs) # Vendor Homepage: wwwjoomlaorg/ # Software Link: joomlacodeorg/gf/project/joomla/frs/ # Version: Joomla 15 ...