Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeba Backup for Joomla! Professional 3.0.0 through 4.0.2; Backup Professional for WordPress 1.0.b1 through 1.1.3; Solo 1.0.b1 through 1.1.2; Admin Tools Core and Professional 2.0.0 through 2.4.4; and CMS Update 1.0.a1 through 1.0.1, when performing a backup or update for an archive, does not delete parameters from $_GET and $_POST when it is cleansing $_REQUEST, but later accesses $_GET and $_POST using the getQueryParam function, which allows remote attackers to bypass encryption and execute arbitrary code via a command message that extracts a crafted archive.
We have discovered 129,482 live websites that are affected by CVE-2014-7228.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 129,482 live websites (97% of Joomla install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 16 versions ( 12% of all versions) |
| 7,136 websites | |
| 36,678 websites | |
| 11,574 websites | |
| 7,048 websites | |
| 7,016 websites | |
| 5,239 websites | |
| 5,077 websites | |
| 4,611 websites | |
| 4,284 websites | |
| 3,728 websites |
| .com | 28,158 websites |
| .it | 24,408 websites |
| .ru | 9,618 websites |
| .nl | 3,964 websites |
| .de | 3,670 websites |
| .se | 3,140 websites |
| .org | 3,093 websites |
| .cz | 2,965 websites |
| .co.uk | 2,766 websites |
| .net | 2,582 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.com | **,*** | ||
| ************.com | **,*** | ||
| ************.com | **,*** | ||
| *********************.com | **,*** | ||
| *****.org | **,*** | ||
| ********.com | **,*** | ||
| *****.it | **,*** | ||
| *********.com | **,*** | ||
| ******.cz | **,*** | ||
| *******.ru | **,*** |