vendor:
Desktop Central, Password Manager Pro and IT360 (including MSP versions)
by:
Pedro Ribeiro (pedrib@gmail.com), Agile Information Security
9
CVSS
HIGH
Blind SQL Injection
89
CWE
Product Name: Desktop Central, Password Manager Pro and IT360 (including MSP versions)
Affected Version From: ManageEngine Password Manager Pro 5 through 7 build 7003, ManageEngine IT360 8 through 10.1.1 build 10110
Affected Version To: ManageEngine Password Manager Pro 5 through 7 build 7003, ManageEngine IT360 8 through 10.1.1 build 10110
Patch Exists: YES
Related CWE: CVE-2014-5317
CPE: a:manageengine:desktop_central
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2014
Blind SQL injection in ManageEngine Desktop Central, Password Manager Pro and IT360 (including MSP versions)
ManageEngine Desktop Central, Password Manager Pro and IT360 (including MSP versions) are vulnerable to Blind SQL Injection in the MetadataServlet.dat servlet. The vulnerability is caused due to the lack of input validation of the ‘sv’ parameter. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
Mitigation:
Upgrade to the latest version of ManageEngine Desktop Central, Password Manager Pro and IT360 (including MSP versions).