CVE-2014-3996

ManageEngine <9-0.90043 - SQL Injection

Title source: llm

Description

SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90043, Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7 build 7003, IT360 and IT360 Managed Service Providers (MSP) edition before 10.3.3 build 10330, and possibly other ManageEngine products, allows remote attackers or remote authenticated users to execute arbitrary SQL commands via the sv parameter to LinkViewFetchServlet.dat.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Pedro Ribeiro · rubywebappsmultiple
https://www.exploit-db.com/exploits/34409
metasploit WORKING POC EXCELLENT
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/manage_engine_dc_pmp_sqli.rb

Scores

EPSS 0.7116
EPSS Percentile 98.7%

Details

CWE
CWE-89
Status published
Products (3)
manageengine/desktop_central < 9.0 (2 CPE variants)
manageengine/it360 < 10.3.3 (2 CPE variants)
manageengine/password_manager_pro < 7.0 (2 CPE variants)
Published Dec 05, 2014
Tracked Since Feb 18, 2026