CVE-2016-8869
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote attackers to gain privileges by leveraging incorrect use of unfiltered data when registering on a site.
- Affected products
- Joomla!
- Joomla Joomla\!
- ≤ 3.6.3
- Fix
- Available
- CVSS 3.0
- 9.8 CRITICAL
- EPSS
- 97.4% (100th percentile)
- Weakness
- CWE-20
- NVD status
- Modified
- Published
- 2016-11-04
CVE-2016-8869 at NVD
14 known exploits for CVE-2016-8869
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for Improper Input Validation in Joomla Joomla\!
Exploit for OS Command Injection in Gnu Bash
Joomla Account Creation And Privilege Escalation
Exploit for Improper Input Validation in Joomla Joomla\!
Exploit for Improper Input Validation in Joomla Joomla\!
Exploit for Improper Input Validation in Joomla Joomla\!
Exploit for Improper Input Validation in Joomla Joomla\!
Exploit for Improper Input Validation in Joomla Joomla\!
Exploit for Improper Input Validation in Joomla Joomla\!
Joomla! 3.4.4 < 3.6.4 - Account Creation / Privilege Escalation
Joomla 3.4.4 - 3.6.4 - Account Creation / Privilege Escalation Exploit
Joomla Account Creation and Privilege Escalation
Joomla 3.4.4 - 3.6.3 not authorized to create user vulnerability
Joomla : 3.4.4 - 3.6.3 privilege elevation vulnerability