ManageEngine Password Manager Pro Database Remote Unauthorized Access Vulnerability

BID:23693

Info

ManageEngine Password Manager Pro Database Remote Unauthorized Access Vulnerability

Bugtraq ID: 23693
Class: Design Error
CVE:
Remote: Yes
Local: No
Published: Apr 27 2007 12:00AM
Updated: May 08 2007 05:29PM
Credit: An anonymous security researcher is credited with the discovery of this vulnerability.
Vulnerable: ManageEngine PasswordManager Pro Build 5401
Not Vulnerable: ManageEngine PasswordManager Pro Build 5402

Discussion

ManageEngine Password Manager Pro Database Remote Unauthorized Access Vulnerability

ManageEngine Password Manager Pro is prone to a remote unauthorized-access vulnerability due to a design error.

An attacker may leverage this issue to gain unauthorized access to the application's database with administrative privileges. Successful exploits will result in a complete compromise of vulnerable applications and may aid in further attacks.

ManageEngine Password Manager Pro Free edition is vulnerable; other versions may also be affected.

Exploit / POC

ManageEngine Password Manager Pro Database Remote Unauthorized Access Vulnerability

An attacker may exploit this issue by submitting the following connection request:

$mysql -h example.com --port 2345 -u root

Solution / Fix

ManageEngine Password Manager Pro Database Remote Unauthorized Access Vulnerability

Solution:
The vendor released product build version 4502 and a patch to address this issue. Please see the references for more information.


ManageEngine PasswordManager Pro Build 5401

References

ManageEngine Password Manager Pro Database Remote Unauthorized Access Vulnerability

References:
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report