Vulnerabilities > CVE-2007-2429 - Remote Unauthorized Access vulnerability in ManageEngine Password Manager Pro Database

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
manageengine
critical
exploit available

Summary

ManageEngine PasswordManager Pro (PMP) allows remote attackers to obtain administrative access to a database by injecting a certain command line for the mysql program, as demonstrated by the "-port 2345" and "-u root" arguments. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Vulnerable Configurations

Part Description Count
Application
Manageengine
1

Exploit-Db

descriptionManageEngine Password Manager Pro Build 5401 Database Remote Unauthorized Access Vulnerability. CVE-2007-2429. Remote exploits for multiple platform
idEDB-ID:29931
last seen2016-02-03
modified2007-04-27
published2007-04-27
reporteranonymous
sourcehttps://www.exploit-db.com/download/29931/
titleManageEngine Password Manager Pro Build 5401 Database Remote Unauthorized Access Vulnerability