Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2014-8499

Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allow remote authenticated users to execute arbitrary SQL commands via the SEARCH_ALL parameter to (1) SQLAdvancedALSearchResult.cc or (2) AdvancedSearchResult.cc.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.78
EPSS Ranking 98.9%
CVSS Severity
CVSS v2 Score 6.5
References
Products affected by CVE-2014-8499


Contact Us

Shodan ® - All rights reserved