CVE-2014-8499

ManageEngine Password Manager Pro < 7.1 - Authenticated SQL Injection via SEARCH_ALL Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2014-8499. PoCs published by Pedro Ribeiro, including Metasploit module auxiliary/admin/http/manageengine_pmp_privesc.

AI-analyzed exploit summary This is a detailed writeup describing an authenticated blind SQL injection vulnerability in Password Manager Pro. It explains the constraints, exploitation techniques, and includes references to a Metasploit module for privilege escalation and data exfiltration.

Description

Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allow remote authenticated users to execute arbitrary SQL commands via the SEARCH_ALL parameter to (1) SQLAdvancedALSearchResult.cc or (2) AdvancedSearchResult.cc.

Exploits (2)

exploitdb WRITEUP
by Pedro Ribeiro · textwebappsmultiple
https://www.exploit-db.com/exploits/35210

This is a detailed writeup describing an authenticated blind SQL injection vulnerability in Password Manager Pro. It explains the constraints, exploitation techniques, and includes references to a Metasploit module for privilege escalation and data exfiltration.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Password Manager Pro / Pro MSP (versions < 6.8 use MySQL, versions >= 6.8 use PostgreSQL)
Auth required
Prerequisites: Valid user account (low privileged guest account is sufficient)
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/http/manageengine_pmp_privesc.rb

This Metasploit module exploits an authenticated blind SQL injection vulnerability in ManageEngine Password Manager Pro (PMP) to escalate privileges to Super Administrator. It leverages PostgreSQL stacked queries to create a new admin user and dump the password database.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: ManageEngine Password Manager Pro (PMP) v6.8 to v7.1 build 7104
Auth required
Prerequisites: Valid credentials for an authenticated user · PostgreSQL as the backend database
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/98595
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/show/osvdb/114485
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/show/osvdb/114484
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/71018
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/98597
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Nov/18
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/35210

Scores

EPSS 0.7492
EPSS Percentile 98.9%

Details

CWE
CWE-89
Status published
Products (1)
manageengine/password_manager_pro < 7.1 (2 CPE variants)
Published Nov 17, 2014
Tracked Since Feb 18, 2026