Website Security & Threat Management
A Different Kind of POP: The Joomla Unserialize Vulnerability

A Different Kind of POP: The Joomla Unserialize Vulnerability

12/17/2015 · Pasha Kravtsov

What this post added

This post details the analysis of a zero-day vulnerability (CVE-2015-8562) in Joomla's unserialize functionality, which allows for remote code execution via crafted User-Agent or X-Forwarded-For headers. It explains the POP chain exploit mechanism, the vulnerable code paths in Joomla, and demonstrates how Cloudflare's Web Application Firewall (WAF) was updated with specific rules to block these attacks by default for Pro and higher plan customers. The post includes examples of observed attack payloads and WAF activity.

Read the original post ↗