Attackers exploited SQL injection flaw to attack Joomla
Just four hours after the release of a patch for a critical vulnerability, malicious actors began attacks against Joomla, a popular open source content management system , exploiting an SQL injection flaw
The SQL injection flaw (CVE-2015-7297, CVE-2015-7857, CVE-2015-7858) found in Joomla versions 3.2 to 3.4.4 and could potentially grant attackers full administrative access to any vulnerable site, was discovered by Trustwave researchers and announced in separate blog posts on the Joomla and Trustwave sites.
"CVE-2015-7857 allows an unauthorized remote user to gain administrator privileges by hijacking the administrator session. After exploiting the vulnerability, the attacker can gain complete control of the website and perform additional attacks," the researchers explained in a blog post.
Just hours after the release of version 3.4.5, web security firm Sucuri reported a direct attack against two of its customers. The attack attempted to extract the current session from any logged-in admin user, but they were blocked by its generic SQL Injection signatures:
“What’s even scarier is that none of these sites had been patched at the time,” Sucuri CTO Daniel Cid said in a blog post on Monday. “The discovery came on Thursday afternoon (evening in Europe), when many webmasters were already off for the day.”
Within just 24 hours, the company began seeing Internet-wide scans for the flaw as well as a number of attacks. Sucuri recorded 12,000 attempts to exploit the vulnerability.

