CVE-2015-4073
CRITICALHelpdesk Pro < 1.3.0 - SQL Injection via Ticket Code or Email Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-4073. PoCs published by Simon Rawet.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in Joomla! Helpdesk Pro < 1.4.0, including SQL injection, XSS, path traversal, and file upload. The PoC provides clear examples of how to exploit these vulnerabilities, including unauthenticated and authenticated attack vectors.
Description
Multiple SQL injection vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) ticket_code or (2) email parameter or (3) remote authenticated users to execute arbitrary SQL commands via the filter_order parameter.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in Joomla! Helpdesk Pro < 1.4.0, including SQL injection, XSS, path traversal, and file upload. The PoC provides clear examples of how to exploit these vulnerabilities, including unauthenticated and authenticated attack vectors.
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H