packetstormsecurity.com
http://packetstormsecurity.com/files/132766/Joomla-Helpdesk-Pro-XSS-File-Disclosure-SQL-Injection.html CVE-2015-4071
MEDIUM
Joomla! Component Helpdesk Pro < 1.4.0 - Multiple Vulnerabilities
Record summary
CVE-2015-4071 has a selected CVSS score of 5.3 (medium); EIP currently links 1 catalogued exploit.
Description
The Helpdesk Pro Plugin before 1.4.0 for Joomla! allows remote attackers to read the support tickets of arbitrary users via obtaining the target ticketId, and navigating to http://{target}/component/helpdeskpro/?view=ticket&id={ticketId}.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBJoomla! Component Helpdesk Pro < 1.4.0 - Multiple VulnerabilitiesExploitDB exploitby Simon RawetNot analyzed1 file
References
620151231 Joomla! plugin Helpdesk Pro < 1.4.0mailing list
http://seclists.org/fulldisclosure/2015/Jul/102 20151231 New CVE's to be released the 17th of June.mailing list
http://seclists.org/fulldisclosure/2015/Jul/82 75971vdb entry
http://www.securityfocus.com/bid/75971 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2015-4071 37666exploit
https://www.exploit-db.com/exploits/37666