VYPR

Manageengine Password Manager Pro

by Zohocorp

CVEs (24)

  • CVE-2021-33617MedJul 31, 2021
    risk 0.35cvss 5.3epss 0.02

    Zoho ManageEngine Password Manager Pro before 11.2 11200 allows login/AjaxResponse.jsp?RequestType=GetUserDomainName&userName= username enumeration, because the response (to a failed login request) is null only when the username is invalid.

  • CVE-2014-3997Dec 5, 2014
    risk 0.04cvss epss 0.13

    SQL injection vulnerability in the MetadataServlet servlet in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition 5 through 7 build 7003, IT360 and IT360 Managed Service Providers (MSP) edition before 10.3.3 build 10330, and…

  • CVE-2014-8498Nov 17, 2014
    risk 0.04cvss epss 0.13

    SQL injection vulnerability in BulkEditSearchResult.cc in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allows remote authenticated users to execute arbitrary SQL commands via the SEARCH_ALL…

  • CVE-2015-5459Jul 8, 2015
    risk 0.00cvss epss 0.04

    SQL injection vulnerability in the AdvanceSearch.class in AdventNetPassTrix.jar in ManageEngine Password Manager Pro (PMP) before 8.1 Build 8101 allows remote authenticated users to execute arbitrary SQL commands via the ANDOR parameter, as demonstrated by a request to…

Page 2 of 2