Vulnerability: ManageEngine Password Manager Pro 8.1 SQL Injection vulnerability Author: Blazej Adamczyk Date: 2015-06-30 Vendor: ManageEngine Link: Link to Download Site Version Affected: 8.1 and below Description: An authenticated user (including guest users) can execute arbitrary SQL code using a forged request to the SQLAdvancedALSearchResult.cc. Details: SQL injection issue in the AdvanceSearch.class of AdventNetPassTrix.jar due to improper escaping when more than one condition is specified in the advanced search. Example URL: Broken URL Contact**: passwordmanagerpro-support @ manageengine.com