HTTP: Joomla com_fields SQL Injection

This signature detects attempts to exploit a known vulnerability against Joomla. A remote, unauthenticated attacker could exploit this vulnerability by sending an HTTP request with a malicious SQL query to the target server. Successful exploitation could result in disclosure of sensitive information from the underlying database.

Extended Description

SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors.

Affected Products

Joomla joomla!

Short Name
HTTP:SQL:INJ:JOOMLA-COM-FIELD
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2017-8917 Injection Joomla SQL bid:98515 com_fields
Release Date
04/30/2019
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Joomla

CVSS Score

7.5

Found a potential security threat?