← back
CVE-2014-3997

CVE-2014-3997

23Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 9.2%
from disclosure to weapon0 days
Published on NVDDec 5
1st PoCAug 20
exploitation probability
9.2%top 5% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
SQL injection vulnerability in the MetadataServlet servlet in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition 5 through 7 build 7003, IT360 and IT360 Managed Service Providers (MSP) edition before 10.3.3 build 10330, and possibly other ManageEngine products, allows remote attackers or remote authenticated users to execute arbitrary SQL commands via the sv parameter to MetadataServlet.dat.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.