Show filters
80 Total Results
Displaying 71-80 of 80
Sort by:
Attacker Value
Unknown
CVE-2014-3996
Disclosure Date: December 05, 2014 (last updated October 05, 2023)
SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90043, Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7 build 7003, IT360 and IT360 Managed Service Providers (MSP) edition before 10.3.3 build 10330, and possibly other ManageEngine products, allows remote attackers or remote authenticated users to execute arbitrary SQL commands via the sv parameter to LinkViewFetchServlet.dat.
0
Attacker Value
Unknown
CVE-2014-8498
Disclosure Date: November 17, 2014 (last updated October 05, 2023)
SQL injection vulnerability in BulkEditSearchResult.cc in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allows remote authenticated users to execute arbitrary SQL commands via the SEARCH_ALL parameter.
0
Attacker Value
Unknown
CVE-2014-8499
Disclosure Date: November 17, 2014 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allow remote authenticated users to execute arbitrary SQL commands via the SEARCH_ALL parameter to (1) SQLAdvancedALSearchResult.cc or (2) AdvancedSearchResult.cc.
0
Attacker Value
Unknown
CVE-2014-2600
Disclosure Date: April 05, 2014 (last updated October 05, 2023)
Unspecified vulnerability in HP IceWall Identity Manager 4.0 through SP1 and 5.0 and IceWall SSO 10.0 Password Reset Option, when Apache Commons FileUpload is used, allows remote authenticated users to cause a denial of service via unknown vectors.
0
Attacker Value
Unknown
CVE-2013-6246
Disclosure Date: October 24, 2013 (last updated October 05, 2023)
The Dell Quest One Password Manager, possibly 5.0, allows remote attackers to bypass CAPTCHA protections and obtain sensitive information (user's full name) by sending a login request with a valid domain and username but without the CaptchaType, UseCaptchaEveryTime, and CaptchaResponse parameters.
0
Attacker Value
Unknown
CVE-2011-1840
Disclosure Date: May 13, 2011 (last updated October 04, 2023)
The MartiniCreations PassmanLite Password Manager application before 1.48 for Android stores the master password and unspecified other account information in cleartext, which allows local users to obtain sensitive information by leveraging shell access.
0
Attacker Value
Unknown
CVE-2009-4387
Disclosure Date: December 22, 2009 (last updated October 04, 2023)
The cross-site scripting (XSS) protection mechanism in ShowInContentAreaAction.do in ManageEngine Password Manager Pro (PMP) before 6.1 Build 6104 uses case-sensitive checks for malicious inputs, which allows remote attackers to inject arbitrary web script or HTML via the searchtext parameter and other unspecified inputs.
0
Attacker Value
Unknown
CVE-2006-5161
Disclosure Date: October 05, 2006 (last updated October 04, 2023)
IBM Client Security Password Manager stores and distributes saved passwords based upon the title of a website, which allows remote attackers to obtain username and password credentials by changing the title of an HTML page.
0
Attacker Value
Unknown
CVE-2005-0822
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Citrix Metaframe Password Manager 2.5 and earlier stores a password in cleartext although it is obfuscated when presented to a user, which allows users to view their secondary passwords even if it is not allowed by policy.
0
Attacker Value
Unknown
CVE-2004-1902
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
The Citrix MetaFrame Password Manager 2.0, when a central credential store is not configured, does not encrypt passwords entered immediately after executing the First Time User Wizards, which allows local users to gain sensitive information.
0