CVE-2015-5459

ManageEngine PMP <8.1 - SQL Injection

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in the AdvanceSearch.class in AdventNetPassTrix.jar in ManageEngine Password Manager Pro (PMP) before 8.1 Build 8101 allows remote authenticated users to execute arbitrary SQL commands via the ANDOR parameter, as demonstrated by a request to STATE_ID/1425543888647/SQLAdvancedALSearchResult.cc.

References (5)

Core 5
Core References
Exploit mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2015/Jun/104
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/75692
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2015/Jul/19

Scores

EPSS 0.0084
EPSS Percentile 74.9%

Details

CWE
CWE-89
Status published
Products (1)
zohocorp/manageengine_password_manager_pro < 8.1
Published Jul 08, 2015
Tracked Since Feb 18, 2026