CVE-2014-3996

ManageEngine <9-0.90043 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2014-3996. PoCs published by Pedro Ribeiro, including Metasploit module exploits/multi/http/manage_engine_dc_pmp_sqli.

AI-analyzed exploit summary This Metasploit module exploits an unauthenticated blind SQL injection in ManageEngine Desktop Central and Password Manager Pro, leading to remote code execution as SYSTEM (Windows) or the user (Linux). It supports both PostgreSQL and MySQL databases, with payloads delivered in chunks due to URL size limitations.

Description

SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90043, Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7 build 7003, IT360 and IT360 Managed Service Providers (MSP) edition before 10.3.3 build 10330, and possibly other ManageEngine products, allows remote attackers or remote authenticated users to execute arbitrary SQL commands via the sv parameter to LinkViewFetchServlet.dat.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Pedro Ribeiro · rubywebappsmultiple
https://www.exploit-db.com/exploits/34409

This Metasploit module exploits an unauthenticated blind SQL injection in ManageEngine Desktop Central and Password Manager Pro, leading to remote code execution as SYSTEM (Windows) or the user (Linux). It supports both PostgreSQL and MySQL databases, with payloads delivered in chunks due to URL size limitations.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: ManageEngine Desktop Central v7 build 70200 to v9 build 90033, Password Manager Pro v6 build 6500 to v7 build 7002
No auth needed
Prerequisites: Network access to the target server · Vulnerable version of ManageEngine software
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/manage_engine_dc_pmp_sqli.rb

This Metasploit module exploits an unauthenticated blind SQL injection in ManageEngine Desktop Central and Password Manager Pro, leading to remote code execution via JSP file upload. It supports both PostgreSQL and MySQL backends, with targets for Windows and Linux.

Classification
Working Poc 100%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: ManageEngine Desktop Central v7 build 70200 to v9 build 90033, Password Manager Pro v6 build 6500 to v7 build 7002
No auth needed
Prerequisites: Network access to the target server · SQL injection vulnerability in LinkViewFetchServlet
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

EPSS 0.7116
EPSS Percentile 98.7%

Details

CWE
CWE-89
Status published
Products (3)
manageengine/desktop_central < 9.0 (2 CPE variants)
manageengine/it360 < 10.3.3 (2 CPE variants)
manageengine/password_manager_pro < 7.0 (2 CPE variants)
Published Dec 05, 2014
Tracked Since Feb 18, 2026