Hackers wasted no time and started looking for vulnerable websites immediately after the disclosure of a dangerous vulnerability in the Joomla platform.
According to researchers, the most recent vulnerability discovered in Joomla (CVE-2015-8562) is being exploited by cybercriminals, who are launching approximately 16,600 attacks per day in an attempt to compromise vulnerable websites. These attacks often exceed 20,000 per day.
The exploited vulnerability, which was partially patched in Joomla version 3.4.6 released on December 14, allowed attackers to take complete control of affected websites. The vulnerability affected all versions of the CMS, and Joomla developers have released a new update, as well as patches for older installations, helping webmasters protect their websites against hostile attacks.
The vulnerability arose from the way the CMS handled user agent strings. As in most cases, the strings were not properly filtered to detect malicious strings, which allowed attackers to inject malicious code that could be executed in the CMS backend.
A study by Sucuri helped to better understand the vulnerability, and it was later discovered by the Joomla team that the problem was actually deeper and was caused, in part, by a bug in PHP.
The vulnerability is only present in certain versions of PHP
The issue was caused by a use-after-free vulnerability in PHP's session deserializer, which was patched in September 2015, with the release of PHP 4.5.45, 5.5.29, 5.6.13. The newer PHP 7 version correctly handles the issue by default.
According to the Joomla team, the only Joomla websites affected by the CVE-2015-8562 vulnerability are those hosted on vulnerable versions of PHP (CVE-2015-6835). On December 21, Joomla developers released version 3.4.7, to further address the vulnerability and allow the CMS to address this issue on vulnerable versions of PHP.

