Record summary

CVE-2015-4074 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

Directory traversal vulnerability in the Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a ticket.download_attachment task.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Sep 19, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

1

Catalogued exploits

ExploitDBJoomla! Component Helpdesk Pro < 1.4.0 - Multiple VulnerabilitiesExploitDB exploitby Simon RawetNot analyzed1 file

linked to 5 vulnerabilities

ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHJoomla! Helpdesk Pro plugin <1.4.0 - Local File InclusionCVSS 7.5

Directory traversal vulnerability in the Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a ticket.download_attachment task.

Impact

An attacker can exploit this vulnerability to read sensitive files on the server.

Remediation

Upgrade to Joomla! Helpdesk Pro plugin version 1.4.0 or later to fix the local file inclusion vulnerability.

WeaknessesCWE-22
Authors0x_Akoko
Template tagscve2015cvelfipacketstormedbjoomlapluginhelpdesk_pro_projectjoomla\!xssvkevvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:helpdesk_pro_project:helpdesk_pro:*:*:*:*:*:joomla\!:*:*

Source: ProjectDiscovery

References

5