CVE-2014-8498

ManageEngine Password Manager Pro < 7.1 - Authenticated SQL Injection via BulkEditSearchResult.cc SEARCH_ALL Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-8498. PoCs published by Pedro Ribeiro.

AI-analyzed exploit summary This is a detailed writeup describing an authenticated blind SQL injection vulnerability in Password Manager Pro. It explains the constraints, exploitation techniques, and includes references to a Metasploit module for privilege escalation and data exfiltration.

Description

SQL injection vulnerability in BulkEditSearchResult.cc in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allows remote authenticated users to execute arbitrary SQL commands via the SEARCH_ALL parameter.

Exploits (1)

exploitdb WRITEUP
by Pedro Ribeiro · textwebappsmultiple
https://www.exploit-db.com/exploits/35210

This is a detailed writeup describing an authenticated blind SQL injection vulnerability in Password Manager Pro. It explains the constraints, exploitation techniques, and includes references to a Metasploit module for privilege escalation and data exfiltration.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Password Manager Pro / Pro MSP (versions < 6.8 use MySQL, versions >= 6.8 use PostgreSQL)
Auth required
Prerequisites: Valid user account (low privileged guest account is sufficient)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/71016
Broken Link vdb-entry x_refsource_osvdb
http://osvdb.org/show/osvdb/114483
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/129036/Password-Manager-Pro-SQL-Injection.html
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Nov/18
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/35210

Scores

EPSS 0.1275
EPSS Percentile 95.8%

Details

CWE
CWE-89
Status published
Products (1)
zohocorp/manageengine_password_manager_pro < 7.1 (2 CPE variants)
Published Nov 17, 2014
Tracked Since Feb 18, 2026