← Back

CVE-2015-5459

nvd nist
Published: Jul 8, 2015Modified: May 6, 2026

JSON object

Loading...
6.5
Vector
AV:N/AC:L/Au:S/C:P/I:P/A:P
Exploitability: 8.0 / Impact: 6.4
Source: NVD

Description

SQL injection vulnerability in the AdvanceSearch.class in AdventNetPassTrix.jar in ManageEngine Password Manager Pro (PMP) before 8.1 Build 8101 allows remote authenticated users to execute arbitrary SQL commands via the ANDOR parameter, as demonstrated by a request to STATE_ID/1425543888647/SQLAdvancedALSearchResult.cc.

Affected (1)

1 product
Manageengine Password Manager Pro
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 8.1

References (10)

Timeline

No history available yet.