HomeSecuritySQL injection flaw exploited to attack Joomla

SQL injection flaw exploited to attack Joomla

Attackers exploited SQL injection flaw to attack Joomla

Just four hours after the release of a patch for a critical vulnerability, malicious actors began attacks against Joomla, a popular open source content management system , exploiting an SQL injection flaw

SQL injection flaw exploited to attack Joomla

The SQL injection flaw (CVE-2015-7297, CVE-2015-7857, CVE-2015-7858) found in Joomla versions 3.2 to 3.4.4 and could potentially grant attackers full administrative access to any vulnerable site, was discovered by Trustwave researchers and announced in separate blog posts on the Joomla and Trustwave sites.

"CVE-2015-7857 allows an unauthorized remote user to gain administrator privileges by hijacking the administrator session. After exploiting the vulnerability, the attacker can gain complete control of the website and perform additional attacks," the researchers explained in a blog post.

Just hours after the release of version 3.4.5, web security firm Sucuri reported a direct attack against two of its customers. The attack attempted to extract the current session from any logged-in admin user, but they were blocked by its generic SQL Injection signatures:

“What’s even scarier is that none of these sites had been patched at the time,” Sucuri CTO Daniel Cid said in a blog post on Monday. “The discovery came on Thursday afternoon (evening in Europe), when many webmasters were already off for the day.”

Within just 24 hours, the company began seeing Internet-wide scans for the flaw as well as a number of attacks. Sucuri recorded 12,000 attempts to exploit the vulnerability.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS