Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-2429. PoCs published by anonymous.
AI-analyzed exploit summary The exploit demonstrates an unauthorized access vulnerability in ManageEngine Password Manager Pro by directly connecting to the MySQL database with root credentials. The issue arises from a design error allowing remote access without authentication.
Description
ManageEngine PasswordManager Pro (PMP) allows remote attackers to obtain administrative access to a database by injecting a certain command line for the mysql program, as demonstrated by the "-port 2345" and "-u root" arguments. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
The exploit demonstrates an unauthorized access vulnerability in ManageEngine Password Manager Pro by directly connecting to the MySQL database with root credentials. The issue arises from a design error allowing remote access without authentication.