Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
SQL Injection
Vulnerability Description
Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by authenticated SQL Injection vulnerability via a global search option.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
ZOHO ManageEngine Password Manager Pro 安全漏洞
Vulnerability Description
ZOHO ManageEngine Password Manager Pro是美国卓豪(ZOHO)公司的一款密码管理器。 ZOHO ManageEngine Password Manager Pro 12431之前版本和ManageEngine PAM360 7001之前版本存在安全漏洞,该漏洞源于通过全局搜索选项未能正确过滤输入,可能导致恶意用户执行SQL注入攻击。
CVSS Information
N/A
Vulnerability Type
N/A