CVE-2014-8499
ManageEngine Password Manager Pro < 7.1 - Authenticated SQL Injection via SEARCH_ALL Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2014-8499.
PoCs published by Pedro Ribeiro, including Metasploit module auxiliary/admin/http/manageengine_pmp_privesc.
AI-analyzed exploit summary This is a detailed writeup describing an authenticated blind SQL injection vulnerability in Password Manager Pro. It explains the constraints, exploitation techniques, and includes references to a Metasploit module for privilege escalation and data exfiltration.
Description
Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allow remote authenticated users to execute arbitrary SQL commands via the SEARCH_ALL parameter to (1) SQLAdvancedALSearchResult.cc or (2) AdvancedSearchResult.cc.
Exploits (2)
This is a detailed writeup describing an authenticated blind SQL injection vulnerability in Password Manager Pro. It explains the constraints, exploitation techniques, and includes references to a Metasploit module for privilege escalation and data exfiltration.
This Metasploit module exploits an authenticated blind SQL injection vulnerability in ManageEngine Password Manager Pro (PMP) to escalate privileges to Super Administrator. It leverages PostgreSQL stacked queries to create a new admin user and dump the password database.