5
CVSSv2

CVE-2015-4074

Published: 20/09/2017 Updated: 22/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in the Helpdesk Pro plugin prior to 1.4.0 for Joomla! allows remote malicious users to read arbitrary files via a .. (dot dot) in the filename parameter in a ticket.download_attachment task.

Vulnerable Product Search on Vulmon Subscribe to Product

helpdesk pro project helpdesk pro

Exploits

Document Title ============== Joomla! plugin Helpdesk Pro < 140 Reported By =========== Simon Rawet from Outpost24 Kristian Varnai from Outpost24 Gregor Mynarsky from Outpost24 wwwoutpost24com/ For full details, see; wwwoutpost24com/outpost24-has-found-critical-vulnerabilities-in-joomla-helpdesk-pro/ Tested on ========= ...
Joomla Helpdesk Pro versions prior to 140 suffers from cross site scripting, local file disclosure, remote file upload, remote SQL injection, and insecure direct object reference vulnerabilities ...