CVE-2014-8499
Currently unrated 🤨
Summary
Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allow remote authenticated users to execute arbitrary SQL commands via the SEARCH_ALL parameter to (1) SQLAdvancedALSearchResult.cc or (2) AdvancedSearchResult.cc.
Refferences
https://exchange.xforce.ibmcloud.com/vulnerabilities/98595
vdb-entryx_refsource_XF
http://osvdb.org/show/osvdb/114485
vdb-entryx_refsource_OSVDB
http://osvdb.org/show/osvdb/114484
vdb-entryx_refsource_OSVDB
http://www.securityfocus.com/bid/71018
vdb-entryx_refsource_BID
https://exchange.xforce.ibmcloud.com/vulnerabilities/98597
vdb-entryx_refsource_XF
http://packetstormsecurity.com/files/129036/Password-Mana...
x_refsource_MISC
http://seclists.org/fulldisclosure/2014/Nov/18
mailing-listx_refsource_FULLDISC
https://raw.githubusercontent.com/pedrib/PoC/master/Manag...
x_refsource_MISC
http://www.exploit-db.com/exploits/35210
exploitx_refsource_EXPLOIT-DB
EPSS Score
1% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database