Joomla! 3.7.x versions before 3.7.1 contain an SQL injection vulnerability. Attackers can exploit unspecified vectors to execute arbitrary SQL commands.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository purpose: a CTF/lab-friendly proof-of-concept exploit for Joomla com_fields SQL injection (CVE-2017-8917) that demonstrates end-to-end exploitation: vulnerability probe, DB enumeration, and data extraction. Structure: - README.md: explains CVE-2017-8917, the vulnerable parameter (list[fullordering]), and the PoC workflow (probe → enumerate → dump). Includes example output. - exploit.py: standalone Python exploit script (requests-based) implementing the full exploitation chain. - LICENSE/.gitignore: standard. Exploit flow (exploit.py): - CLI: --host (required) and --debug. - Builds base URL assuming HTTP on port 80 (e.g., http://<host>:80/index.php). - Creates a persistent requests.Session with a distinctive User-Agent. - Fetches a CSRF token from the Joomla administrator/login page (via fetch_token()). - Probes SQLi by injecting an arithmetic expression ("40 + 2") and checking whether "42" appears in the returned HTML <title>. - Uses error-based SQLi wrapping queries with UpdateXML(...) to force DB errors that contain query output. - Extracts leaked data by parsing the <title> tag and then extracting between markers (e.g., "#039;:" ... ":'"). - Enumeration: retrieves DB version (SELECT VERSION()) and current database (DATABASE()), lists tables from information_schema.tables, lists columns from information_schema.columns, then dumps rows from #__users. - Dumping: concatenates columns with a separator and performs chunked substring extraction to avoid truncation (CHUNK_SIZE=31), iterating over row ranges. Notable characteristics: - Network-only attack against a web endpoint. - Focused on data extraction (no RCE/reverse shell). - Includes retry/timeout constants and debug logging, making it more operational than a minimal probe-only PoC.
This repository is a Python-based exploit for CVE-2017-8917, a SQL injection vulnerability in Joomla 3.7.0. The main file, main.py, implements a command-line tool that targets Joomla installations by sending crafted HTTP GET requests to exploit the 'list[fullordering]' parameter in the com_fields component. The exploit retrieves a CSRF token from the login page, then uses error-based SQL injection (via UpdateXML) to extract data from the #__users table, such as usernames and password hashes. The script supports custom column extraction and handles password hash chunking due to MySQL error message length limits. The repository includes a README with setup instructions, a requirements.txt for dependencies, and a usage.txt with example commands. The exploit is a proof-of-concept and outputs the extracted user data in a readable table format. No hardcoded endpoints are present; the target is specified by the user at runtime.
This repository contains a single Metasploit module (Ruby file) that exploits a SQL injection vulnerability (CVE-2017-8917) in the com_fields component of Joomla 3.7.0. The exploit works by leveraging SQL injection to extract the table prefix and an active administrator session cookie, then uses this session to authenticate to the Joomla admin interface. It proceeds to create a new PHP file in the template directory, injects a Metasploit PHP payload into it, and finally executes the payload by making an HTTP request to the uploaded file. The module is fully weaponized, allowing the attacker to achieve remote code execution on vulnerable Joomla installations. The code is structured as a standard Metasploit module, using the HttpClient and Joomla mixins, and is designed for remote, unauthenticated exploitation over the network. All endpoints targeted are HTTP(S) requests to the Joomla web application.
This repository contains a Python exploit script (main.py) targeting CVE-2017-8917, a SQL injection vulnerability in Joomla! 3.7.0. The exploit is designed for educational and penetration testing purposes, as noted in the README. The main script takes command-line arguments for the target's schema (http/https), host, port, and URI, and automates the exploitation process. The exploit works by sending crafted GET requests to the Joomla! 'com_fields' component, injecting SQL via the 'list[fullordering]' parameter. It first checks if the target is vulnerable, then extracts the database version, lists databases and tables, describes the 'users' table, and finally dumps user data (including usernames and password hashes). The script uses the UpdateXML() SQL function to extract data from the database and handles chunked data extraction for large results. The repository also includes a docker-compose.yaml file for setting up a test environment with MariaDB and phpMyAdmin, and a README with usage instructions. The only code file is main.py, which is the entry point and contains all exploit logic. No hardcoded endpoints are present; the script is parameterized to target any specified Joomla! instance. The attack vector is network-based, exploiting a web application vulnerability over HTTP(S).
This repository contains a Python exploit script (joomblah.py) targeting CVE-2017-8917, a SQL injection vulnerability in Joomla! 3.7.0's com_fields component. The exploit automates the process of extracting sensitive data from the Joomla! database by leveraging a blind SQL injection vulnerability. It first fetches a CSRF token from the login page, then uses crafted requests to the com_fields component to extract table names, user credentials (including password hashes and OTP keys), and session data. The script is operational and provides real data extraction capabilities, making it more than a simple proof-of-concept. The README provides a brief description and a reference link for further information. The main entry point is joomblah.py, which is written in Python and uses the requests library for HTTP communication. No hardcoded IPs or domains are present, but the script requires the user to specify the target Joomla! URL.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.