7.5
CVSSv2

CVE-2014-3997

Published: 05/12/2014 Updated: 16/07/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the MetadataServlet servlet in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition 5 through 7 build 7003, IT360 and IT360 Managed Service Providers (MSP) edition prior to 10.3.3 build 10330, and possibly other ManageEngine products, allows remote attackers or remote authenticated users to execute arbitrary SQL commands via the sv parameter to MetadataServlet.dat.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zohocorp manageengine password manager pro 5.2

zohocorp manageengine password manager pro 5.4

zohocorp manageengine password manager pro 6.2

zohocorp manageengine password manager pro 6.4

zohocorp manageengine password manager pro 6.5

zohocorp manageengine password manager pro 6.6

zohocorp manageengine password manager pro 6.9

zohocorp manageengine password manager pro 7.0

zohocorp manageengine password manager pro 5.0

zohocorp manageengine password manager pro 6.0

zohocorp manageengine password manager pro 6.1

zohocorp manageengine password manager pro 6.7

zohocorp manageengine password manager pro 6.8

zohocorp manageengine password manager pro 5.1

zohocorp manageengine password manager pro 5.3

zohocorp manageengine password manager pro 6.3

zohocorp manageengine it360

Exploits

source: wwwsecurityfocuscom/bid/69303/info ManageEngine Password Manager Pro and ManageEngine IT360 are prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query Exploiting this issue could allow an attacker to compromise the application, access or modify data, o ...
ManageEngine Desktop Central, Password Manager Pro, and IT360 suffer from remote blind SQL injection vulnerabilities Metasploit module included ...