CVE-2015-4074
helpdesk_pro_project helpdesk_pro Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Record summary
CVE-2015-4074 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
Directory traversal vulnerability in the Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a ticket.download_attachment task.
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
helpdesk_proBrowse helpdesk_pro_project / helpdesk_pro | VulnCheck | Version data not supplied | |
Proofs of concept
1Catalogued exploits
ExploitDBJoomla! Component Helpdesk Pro < 1.4.0 - Multiple VulnerabilitiesExploitDB exploitby Simon RawetNot analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHJoomla! Helpdesk Pro plugin <1.4.0 - Local File InclusionCVSS 7.5
Directory traversal vulnerability in the Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a ticket.download_attachment task.
Impact
An attacker can exploit this vulnerability to read sensitive files on the server.
Remediation
Upgrade to Joomla! Helpdesk Pro plugin version 1.4.0 or later to fix the local file inclusion vulnerability.
Source: ProjectDiscovery