packetstormsecurity.com
http://packetstormsecurity.com/files/132766/Joomla-Helpdesk-Pro-XSS-File-Disclosure-SQL-Injection.html CVE-2015-4075
HIGH
Joomla! Component Helpdesk Pro < 1.4.0 - Multiple Vulnerabilities
Record summary
CVE-2015-4075 has a selected CVSS score of 8.1 (high); EIP currently links 1 catalogued exploit.
Description
The Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to write to arbitrary .ini files via a crafted language.save task.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBJoomla! Component Helpdesk Pro < 1.4.0 - Multiple VulnerabilitiesExploitDB exploitby Simon RawetNot analyzed1 file
References
520151231 Joomla! plugin Helpdesk Pro < 1.4.0mailing list
http://seclists.org/fulldisclosure/2015/Jul/102 75971vdb entry
http://www.securityfocus.com/bid/75971 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2015-4075 37666exploit
https://www.exploit-db.com/exploits/37666