CVE-2014-3997
05.12.2014, 15:59
SQL injection vulnerability in the MetadataServlet servlet in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition 5 through 7 build 7003, IT360 and IT360 Managed Service Providers (MSP) edition before 10.3.3 build 10330, and possibly other ManageEngine products, allows remote attackers or remote authenticated users to execute arbitrary SQL commands via the sv parameter to MetadataServlet.dat.
Vendor | Product | Version |
---|---|---|
zohocorp | manageengine_password_manager_pro | 5.0 |
zohocorp | manageengine_password_manager_pro | 5.1 |
zohocorp | manageengine_password_manager_pro | 5.2 |
zohocorp | manageengine_password_manager_pro | 5.3 |
zohocorp | manageengine_password_manager_pro | 5.4 |
zohocorp | manageengine_password_manager_pro | 6.0 |
zohocorp | manageengine_password_manager_pro | 6.0:build6002 |
zohocorp | manageengine_password_manager_pro | 6.1:build6104 |
zohocorp | manageengine_password_manager_pro | 6.2 |
zohocorp | manageengine_password_manager_pro | 6.2:build6201 |
zohocorp | manageengine_password_manager_pro | 6.3 |
zohocorp | manageengine_password_manager_pro | 6.4 |
zohocorp | manageengine_password_manager_pro | 6.4:build6401 |
zohocorp | manageengine_password_manager_pro | 6.4:build6402 |
zohocorp | manageengine_password_manager_pro | 6.4:build6403 |
zohocorp | manageengine_password_manager_pro | 6.4:build6404 |
zohocorp | manageengine_password_manager_pro | 6.5 |
zohocorp | manageengine_password_manager_pro | 6.5:build6503 |
zohocorp | manageengine_password_manager_pro | 6.5:build6504 |
zohocorp | manageengine_password_manager_pro | 6.5:build6505 |
zohocorp | manageengine_password_manager_pro | 6.6:build6600 |
zohocorp | manageengine_password_manager_pro | 6.7:build6700 |
zohocorp | manageengine_password_manager_pro | 6.7:build6701 |
zohocorp | manageengine_password_manager_pro | 6.8:build6800 |
zohocorp | manageengine_password_manager_pro | 6.8:build6801 |
zohocorp | manageengine_password_manager_pro | 6.8:build6802 |
zohocorp | manageengine_password_manager_pro | 6.8:build6803 |
zohocorp | manageengine_password_manager_pro | 6.9 |
zohocorp | manageengine_password_manager_pro | 6.9:build6900 |
zohocorp | manageengine_password_manager_pro | 6.9:build6901 |
zohocorp | manageengine_password_manager_pro | 6.9:build6902 |
zohocorp | manageengine_password_manager_pro | 6.9:build6903 |
zohocorp | manageengine_password_manager_pro | 6.9:build6904 |
zohocorp | manageengine_password_manager_pro | 7.0 |
zohocorp | manageengine_password_manager_pro | 7.0:build7000 |
zohocorp | manageengine_password_manager_pro | 7.0:build7001 |
zohocorp | manageengine_password_manager_pro | 7.0:build7002 |
zohocorp | manageengine_password_manager_pro | 7.0:build7003 |
zohocorp | manageengine_it360 | 𝑥 ≤ 10.3.3 |
zohocorp | manageengine_it360 | 𝑥 ≤ 10.3.3 |
zohocorp | manageengine_password_manager_pro | 5.0 |
zohocorp | manageengine_password_manager_pro | 5.1 |
zohocorp | manageengine_password_manager_pro | 5.2 |
zohocorp | manageengine_password_manager_pro | 5.3 |
zohocorp | manageengine_password_manager_pro | 5.4 |
zohocorp | manageengine_password_manager_pro | 6.0 |
zohocorp | manageengine_password_manager_pro | 6.0:build6002 |
zohocorp | manageengine_password_manager_pro | 6.1 |
zohocorp | manageengine_password_manager_pro | 6.1:build6104 |
zohocorp | manageengine_password_manager_pro | 6.2 |
zohocorp | manageengine_password_manager_pro | 6.2:build6201 |
zohocorp | manageengine_password_manager_pro | 6.3 |
zohocorp | manageengine_password_manager_pro | 6.4 |
zohocorp | manageengine_password_manager_pro | 6.4:build6401 |
zohocorp | manageengine_password_manager_pro | 6.4:build6402 |
zohocorp | manageengine_password_manager_pro | 6.4:build6403 |
zohocorp | manageengine_password_manager_pro | 6.4:build6404 |
zohocorp | manageengine_password_manager_pro | 6.5 |
zohocorp | manageengine_password_manager_pro | 6.5:build6503 |
zohocorp | manageengine_password_manager_pro | 6.5:build6504 |
zohocorp | manageengine_password_manager_pro | 6.5:build6505 |
zohocorp | manageengine_password_manager_pro | 6.6:build6600 |
zohocorp | manageengine_password_manager_pro | 6.7:build6700 |
zohocorp | manageengine_password_manager_pro | 6.7:build6701 |
zohocorp | manageengine_password_manager_pro | 6.8:build6800 |
zohocorp | manageengine_password_manager_pro | 6.8:build6801 |
zohocorp | manageengine_password_manager_pro | 6.8:build6802 |
zohocorp | manageengine_password_manager_pro | 6.8:build6803 |
zohocorp | manageengine_password_manager_pro | 6.9 |
zohocorp | manageengine_password_manager_pro | 6.9:build6900 |
zohocorp | manageengine_password_manager_pro | 6.9:build6901 |
zohocorp | manageengine_password_manager_pro | 6.9:build6902 |
zohocorp | manageengine_password_manager_pro | 6.9:build6903 |
zohocorp | manageengine_password_manager_pro | 6.9:build6904 |
zohocorp | manageengine_password_manager_pro | 7.0 |
zohocorp | manageengine_password_manager_pro | 7.0:build7000 |
zohocorp | manageengine_password_manager_pro | 7.0:build7001 |
zohocorp | manageengine_password_manager_pro | 7.0:build7002 |
zohocorp | manageengine_password_manager_pro | 7.0:build7003 |
𝑥
= Vulnerable software versions
References