Rusty Joomla RCE

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

## **Introduction** During one of our research activities, we discovered **an undisclosed PHP Object Injection** on Joomla CMS from the release 3.0.0 to the 3.4.6 (releases from 2012 to December 2015) that leads to Remote Code Execution. A PHP Object Injection was discovered in the wild and patched in the 3.4.5 version (CVE-2015-8562), however, this vulnerability depends also a lot on the PHP release installed becoming not really trusty for all environments. Comparing this RCE with CVE-2015-8562: \+ It is completely independent from the environment, becoming more reliable; \+ Vulnerable from the 3.0.0 to 3.4.6 (just one more minor release, not so much by the way); \- Few releases vulnerable compared to CVE-2015-8562. However, the fun part of this vulnerability was the exploitation. There aren’t a lot of blog posts about some more advanced and manual exploitation of PHP Object Injection (except for some good resources from RIPS) so this paper can be useful while exploiting it in...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息