Back to Rule

Rule History

SID: 2022261 • Source: et/open

Versions (4)

Version DetailsCurrent

Rev: 5Dec 14, 2015, 12:00 PM

ET EXPLOIT Joomla RCE (JDatabaseDriverMysqli)

alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET EXPLOIT Joomla RCE (JDatabaseDriverMysqli)"; flow:established,to_server; http.user_agent; content:"JDatabaseDriverMysqli"; fast_pattern; reference:url,blog.sucuri.net/2015/12/remote-command-execution-vulnerability-in-joomla.html; classtype:web-application-attack; sid:2022261; rev:5; metadata:created_at 2015_12_14, confidence Medium, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_12;)

Dec 14, 2015, 12:00 PM

Mar 12, 2024, 12:00 PM

Sep 21, 2024, 3:00 AM

Oct 6, 2025, 4:34 PM

rules/emerging-exploit.rules