CVE-2014-3997
ManageEngine Password Manager Pro 5-7 build 7003 - SQL Injection via MetadataServlet sv Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-3997. PoCs published by Pedro Ribeiro.
AI-analyzed exploit summary This is a detailed writeup describing blind SQL injection vulnerabilities in ManageEngine Password Manager Pro and IT360. It includes affected versions, constraints, and proof-of-concept URLs but does not contain executable exploit code.
Description
SQL injection vulnerability in the MetadataServlet servlet in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition 5 through 7 build 7003, IT360 and IT360 Managed Service Providers (MSP) edition before 10.3.3 build 10330, and possibly other ManageEngine products, allows remote attackers or remote authenticated users to execute arbitrary SQL commands via the sv parameter to MetadataServlet.dat.
Exploits (1)
This is a detailed writeup describing blind SQL injection vulnerabilities in ManageEngine Password Manager Pro and IT360. It includes affected versions, constraints, and proof-of-concept URLs but does not contain executable exploit code.