CVE-2015-4074
HIGH EXPLOITED NUCLEIHelpdesk Pro < 1.3.0 - Path Traversal via Ticket Download Attachment Filename Parameter
Title source: llmExploitation Summary
CVE-2015-4074 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Simon Rawet. A Nuclei detection template is also available.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in Joomla! Helpdesk Pro < 1.4.0, including SQL injection, XSS, path traversal, and file upload. The PoC provides clear examples of how to exploit these vulnerabilities, including unauthenticated and authenticated attack vectors.
Description
Directory traversal vulnerability in the Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a ticket.download_attachment task.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in Joomla! Helpdesk Pro < 1.4.0, including SQL injection, XSS, path traversal, and file upload. The PoC provides clear examples of how to exploit these vulnerabilities, including unauthenticated and authenticated attack vectors.
Nuclei Templates (1)
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N