Manageengine Password Manager Pro vulnerabilities

5 known vulnerabilities affecting manageengine/password_manager_pro.

Total CVEs
5
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2024-5546HIGHCVSS 8.8fixed in 124312024-08-28
CVE-2024-5546 [HIGH] CWE-89 CVE-2024-5546: Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions be Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by authenticated SQL Injection vulnerability via a global search option.
cvelistv5nvd
CVE-2014-9372MEDIUMCVSS 6.4≤ 7.12014-12-16
CVE-2014-9372 [MEDIUM] CWE-22 CVE-2014-9372: Directory traversal vulnerability in the UploadAccountActivities servlet in ManageEngine Password Ma Directory traversal vulnerability in the UploadAccountActivities servlet in ManageEngine Password Manager Pro (PMP) before 7103 allows remote attackers to delete arbitrary files via a .. (dot dot) in a filename.
nvd
CVE-2014-3996HIGHCVSS 7.5PoC≤ 7.02014-12-05
CVE-2014-3996 [HIGH] CWE-89 CVE-2014-3996: SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90043, Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7 build 7003, IT360 and IT360 Managed Service Providers (MSP) edition befo
nvd
CVE-2014-8499MEDIUMCVSS 6.5PoC≤ 7.12014-11-17
CVE-2014-8499 [MEDIUM] CWE-89 CVE-2014-8499: Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manag Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allow remote authenticated users to execute arbitrary SQL commands via the SEARCH_ALL parameter to (1) SQLAdvancedALSearchResult.cc or (2) AdvancedSearchResult.cc.
nvd
CVE-2009-4387MEDIUMCVSS 4.3≤ 6.1v4.6+8 more2009-12-22
CVE-2009-4387 [MEDIUM] CWE-79 CVE-2009-4387: The cross-site scripting (XSS) protection mechanism in ShowInContentAreaAction.do in ManageEngine Pa The cross-site scripting (XSS) protection mechanism in ShowInContentAreaAction.do in ManageEngine Password Manager Pro (PMP) before 6.1 Build 6104 uses case-sensitive checks for malicious inputs, which allows remote attackers to inject arbitrary web script or HTML via the searchtext parameter and other unspecified inputs.
nvd