CVE-2014-3996

Scores

EPSS

0.712medium71.2%
0%20%40%60%80%100%

Percentile: 71.2%

CVSS

7.5high2.0
0246810

CVSS Score: 7.5/10

All CVSS Scores

CVSS 2.0
7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Description

SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90043, Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7 build 7003, IT360 and IT360 Managed Service Providers (MSP) edition before 10.3.3 build 10330, and possibly other ManageEngine products, allows remote attackers or remote authenticated users to execute arbitrary SQL commands via the sv parameter to LinkViewFetchServlet.dat.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-89

Exploits

Exploit ID: 34409

Source: exploitdb

URL: https://www.exploit-db.com/exploits/34409

Vulnerable Software (3)

Type: Configuration

Vendor: *

Product: desktop_central

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:manageengine:desktop_central:*:build_90043:*:*:*:*:*:*",      "versionEndIncluding": "9.0",      "vulnerable": true    },    {      "cpe23uri...

Source: nvd

Type: Configuration

Vendor: *

Product: it360

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:manageengine:it360:*:build_10330:*:*:*:*:*:*",      "versionEndIncluding": "10.3.3",      "vulnerable": true    },    {      "cpe23uri": "cpe...

Source: nvd

Type: Configuration

Vendor: *

Product: password_manager_pro

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:manageengine:password_manager_pro:*:build_7003:*:*:*:*:*:*",      "versionEndIncluding": "7.0",      "vulnerable": true    },    {      "cpe2...

Source: nvd

End of list