CVE-2014-8498
ManageEngine Password Manager Pro < 7.1 - Authenticated SQL Injection via BulkEditSearchResult.cc SEARCH_ALL Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-8498. PoCs published by Pedro Ribeiro.
AI-analyzed exploit summary This is a detailed writeup describing an authenticated blind SQL injection vulnerability in Password Manager Pro. It explains the constraints, exploitation techniques, and includes references to a Metasploit module for privilege escalation and data exfiltration.
Description
SQL injection vulnerability in BulkEditSearchResult.cc in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allows remote authenticated users to execute arbitrary SQL commands via the SEARCH_ALL parameter.
Exploits (1)
This is a detailed writeup describing an authenticated blind SQL injection vulnerability in Password Manager Pro. It explains the constraints, exploitation techniques, and includes references to a Metasploit module for privilege escalation and data exfiltration.