ManageEngine Password Manager Pro 8.1 SQL Injection vulnerability

Posted by Blazej Adamczyk on Jun 30

Title: ManageEngine Password Manager Pro SQL 8.1 Injection vulnerability
Author: Blazej Adamczyk (br0x)
Date: 2015-06-30
Download site: https://www.manageengine.com/products/passwordmanagerpro/download.html
Version: 8.1 and below
Vendor: https://www.manageengine.com/products/passwordmanagerpro/
Vendor Notified: 2015-06-30
Vendor Contact: passwordmanagerpro-support () manageengine com

Description:
An authenticated user (even the guest user) is…

Leave a Reply