CVE-2014-8499

Manageengine Password Manager Pro < 7.1 - SQL Injection

Title source: rule

Description

Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allow remote authenticated users to execute arbitrary SQL commands via the SEARCH_ALL parameter to (1) SQLAdvancedALSearchResult.cc or (2) AdvancedSearchResult.cc.

Exploits (2)

exploitdb WRITEUP
by Pedro Ribeiro · textwebappsmultiple
https://www.exploit-db.com/exploits/35210
metasploit WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/http/manageengine_pmp_privesc.rb

Scores

EPSS 0.7492
EPSS Percentile 98.9%

Details

CWE
CWE-89
Status published
Products (1)
manageengine/password_manager_pro < 7.1 (2 CPE variants)
Published Nov 17, 2014
Tracked Since Feb 18, 2026