Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown
CVE-2024-5546
Disclosure Date: August 28, 2024 (last updated September 20, 2024)
Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by authenticated SQL Injection vulnerability via a global search option.
0
Attacker Value
Unknown
CVE-2022-40300
Disclosure Date: September 16, 2022 (last updated January 14, 2025)
Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 have multiple SQL injection vulnerabilities.
0
Attacker Value
Unknown
CVE-2022-29081
Disclosure Date: April 28, 2022 (last updated February 23, 2025)
Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProductDetails. GetDashboard. FetchEvents. and Synchronize) via the ../RestAPI substring.
0
Attacker Value
Unknown
CVE-2020-8469
Disclosure Date: March 12, 2020 (last updated February 21, 2025)
Trend Micro Password Manager for Windows version 5.0 is affected by a DLL hijacking vulnerability would could potentially allow an attacker privleged escalation.
0
Attacker Value
Unknown
CVE-2019-15629
Disclosure Date: November 25, 2019 (last updated November 27, 2024)
Trend Micro Password Manager versions 3.x, 5.0, and 5.1 for Android is affected by a FLAG_MISUSE vulnerability that could be exploited to allow the application to share information to third-party applications on the device.
0
Attacker Value
Unknown
CVE-2019-14684
Disclosure Date: August 20, 2019 (last updated November 27, 2024)
A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This process is very similar, yet not identical to CVE-2019-14687.
0
Attacker Value
Unknown
CVE-2019-14687
Disclosure Date: August 20, 2019 (last updated November 08, 2023)
A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This process is very similar, yet not identical to CVE-2019-14684.
0
Attacker Value
Unknown
CVE-2014-3997
Disclosure Date: December 05, 2014 (last updated October 05, 2023)
SQL injection vulnerability in the MetadataServlet servlet in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition 5 through 7 build 7003, IT360 and IT360 Managed Service Providers (MSP) edition before 10.3.3 build 10330, and possibly other ManageEngine products, allows remote attackers or remote authenticated users to execute arbitrary SQL commands via the sv parameter to MetadataServlet.dat.
0
Attacker Value
Unknown
CVE-2014-2600
Disclosure Date: April 05, 2014 (last updated October 05, 2023)
Unspecified vulnerability in HP IceWall Identity Manager 4.0 through SP1 and 5.0 and IceWall SSO 10.0 Password Reset Option, when Apache Commons FileUpload is used, allows remote authenticated users to cause a denial of service via unknown vectors.
0
Attacker Value
Unknown
CVE-2013-6246
Disclosure Date: October 24, 2013 (last updated October 05, 2023)
The Dell Quest One Password Manager, possibly 5.0, allows remote attackers to bypass CAPTCHA protections and obtain sensitive information (user's full name) by sending a login request with a valid domain and username but without the CaptchaType, UseCaptchaEveryTime, and CaptchaResponse parameters.
0