
12/17/2015 · Pasha Kravtsov
What this post added
This post details the analysis of a zero-day vulnerability (CVE-2015-8562) in Joomla's unserialize functionality, which allows for remote code execution via crafted User-Agent or X-Forwarded-For headers. It explains the POP chain exploit mechanism, the vulnerable code paths in Joomla, and demonstrates how Cloudflare's Web Application Firewall (WAF) was updated with specific rules to block these attacks by default for Pro and higher plan customers. The post includes examples of observed attack payloads and WAF activity.