Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 have multiple SQL injection vulnerabilities.
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Manageengine_access_manager_plus | Zohocorp | 4.0-build4000 (including) | 4.0-build4000 (including) |
Manageengine_access_manager_plus | Zohocorp | 4.1-build4100 (including) | 4.1-build4100 (including) |
Manageengine_access_manager_plus | Zohocorp | 4.1-build4101 (including) | 4.1-build4101 (including) |
Manageengine_access_manager_plus | Zohocorp | 4.2-build4200 (including) | 4.2-build4200 (including) |
Manageengine_access_manager_plus | Zohocorp | 4.2-build4201 (including) | 4.2-build4201 (including) |
Manageengine_access_manager_plus | Zohocorp | 4.2-build4202 (including) | 4.2-build4202 (including) |
Manageengine_access_manager_plus | Zohocorp | 4.2-build4203 (including) | 4.2-build4203 (including) |
Manageengine_access_manager_plus | Zohocorp | 4.3-build4300 (including) | 4.3-build4300 (including) |
Manageengine_access_manager_plus | Zohocorp | 4.3-build4301 (including) | 4.3-build4301 (including) |
Manageengine_access_manager_plus | Zohocorp | 4.3-build4302 (including) | 4.3-build4302 (including) |
Manageengine_access_manager_plus | Zohocorp | 4.3-build4303 (including) | 4.3-build4303 (including) |
Manageengine_access_manager_plus | Zohocorp | 4.3-build4304 (including) | 4.3-build4304 (including) |
Manageengine_pam360 | Zohocorp | 4.0 (including) | 4.0 (including) |
Manageengine_pam360 | Zohocorp | 4.0-build4001 (including) | 4.0-build4001 (including) |
Manageengine_pam360 | Zohocorp | 4.0-build4002 (including) | 4.0-build4002 (including) |
Manageengine_pam360 | Zohocorp | 4.1 (including) | 4.1 (including) |
Manageengine_pam360 | Zohocorp | 4.1-build4100 (including) | 4.1-build4100 (including) |
Manageengine_pam360 | Zohocorp | 4.1-build4101 (including) | 4.1-build4101 (including) |
Manageengine_pam360 | Zohocorp | 4.5 (including) | 4.5 (including) |
Manageengine_pam360 | Zohocorp | 4.5-build4500 (including) | 4.5-build4500 (including) |
Manageengine_pam360 | Zohocorp | 4.5-build4501 (including) | 4.5-build4501 (including) |
Manageengine_pam360 | Zohocorp | 5.0 (including) | 5.0 (including) |
Manageengine_pam360 | Zohocorp | 5.0-build5000 (including) | 5.0-build5000 (including) |
Manageengine_pam360 | Zohocorp | 5.0-build5001 (including) | 5.0-build5001 (including) |
Manageengine_pam360 | Zohocorp | 5.0-build5002 (including) | 5.0-build5002 (including) |
Manageengine_pam360 | Zohocorp | 5.0-build5003 (including) | 5.0-build5003 (including) |
Manageengine_pam360 | Zohocorp | 5.0-build5004 (including) | 5.0-build5004 (including) |
Manageengine_pam360 | Zohocorp | 5.1 (including) | 5.1 (including) |
Manageengine_pam360 | Zohocorp | 5.1-build5100 (including) | 5.1-build5100 (including) |
Manageengine_pam360 | Zohocorp | 5.2 (including) | 5.2 (including) |
Manageengine_pam360 | Zohocorp | 5.2-build5200 (including) | 5.2-build5200 (including) |
Manageengine_pam360 | Zohocorp | 5.3 (including) | 5.3 (including) |
Manageengine_pam360 | Zohocorp | 5.3-build5300 (including) | 5.3-build5300 (including) |
Manageengine_pam360 | Zohocorp | 5.3-build5301 (including) | 5.3-build5301 (including) |
Manageengine_pam360 | Zohocorp | 5.3-build5302 (including) | 5.3-build5302 (including) |
Manageengine_pam360 | Zohocorp | 5.3-build5303 (including) | 5.3-build5303 (including) |
Manageengine_pam360 | Zohocorp | 5.3-build5304 (including) | 5.3-build5304 (including) |
Manageengine_pam360 | Zohocorp | 5.3-build5305 (including) | 5.3-build5305 (including) |
Manageengine_pam360 | Zohocorp | 5.3-build5306 (including) | 5.3-build5306 (including) |
Manageengine_pam360 | Zohocorp | 5.4-build5400 (including) | 5.4-build5400 (including) |
Manageengine_pam360 | Zohocorp | 5.4-build5401 (including) | 5.4-build5401 (including) |
Manageengine_pam360 | Zohocorp | 5.5-build5500 (including) | 5.5-build5500 (including) |
Manageengine_pam360 | Zohocorp | 5.5-build5510 (including) | 5.5-build5510 (including) |
Manageengine_pam360 | Zohocorp | 5.5-build5520 (including) | 5.5-build5520 (including) |
Manageengine_pam360 | Zohocorp | 5.5-build5550 (including) | 5.5-build5550 (including) |
Manageengine_password_manager_pro | Zohocorp | 4.6-build4600 (including) | 4.6-build4600 (including) |
Manageengine_password_manager_pro | Zohocorp | 4.7-build4700 (including) | 4.7-build4700 (including) |
Manageengine_password_manager_pro | Zohocorp | 4.8-build4803 (including) | 4.8-build4803 (including) |
Manageengine_password_manager_pro | Zohocorp | 5.0 (including) | 5.0 (including) |
Manageengine_password_manager_pro | Zohocorp | 5.1 (including) | 5.1 (including) |
Manageengine_password_manager_pro | Zohocorp | 5.2 (including) | 5.2 (including) |
Manageengine_password_manager_pro | Zohocorp | 5.3 (including) | 5.3 (including) |
Manageengine_password_manager_pro | Zohocorp | 5.4 (including) | 5.4 (including) |
Manageengine_password_manager_pro | Zohocorp | 6.0 (including) | 6.0 (including) |
Manageengine_password_manager_pro | Zohocorp | 6.0-build6002 (including) | 6.0-build6002 (including) |
Manageengine_password_manager_pro | Zohocorp | 6.1 (including) | 6.1 (including) |
Manageengine_password_manager_pro | Zohocorp | 6.1-build6104 (including) | 6.1-build6104 (including) |
Manageengine_password_manager_pro | Zohocorp | 6.2 (including) | 6.2 (including) |
Manageengine_password_manager_pro | Zohocorp | 6.2-build6201 (including) | 6.2-build6201 (including) |
Manageengine_password_manager_pro | Zohocorp | 6.3 (including) | 6.3 (including) |
Manageengine_password_manager_pro | Zohocorp | 6.4 (including) | 6.4 (including) |
Manageengine_password_manager_pro | Zohocorp | 6.4-build6401 (including) | 6.4-build6401 (including) |
Manageengine_password_manager_pro | Zohocorp | 6.4-build6402 (including) | 6.4-build6402 (including) |
Manageengine_password_manager_pro | Zohocorp | 6.4-build6403 (including) | 6.4-build6403 (including) |
Manageengine_password_manager_pro | Zohocorp | 6.4-build6404 (including) | 6.4-build6404 (including) |
Manageengine_password_manager_pro | Zohocorp | 6.5 (including) | 6.5 (including) |
Manageengine_password_manager_pro | Zohocorp | 6.5-build6503 (including) | 6.5-build6503 (including) |
Manageengine_password_manager_pro | Zohocorp | 6.5-build6504 (including) | 6.5-build6504 (including) |
Manageengine_password_manager_pro | Zohocorp | 6.5-build6505 (including) | 6.5-build6505 (including) |
Manageengine_password_manager_pro | Zohocorp | 6.6-build6600 (including) | 6.6-build6600 (including) |
Manageengine_password_manager_pro | Zohocorp | 6.7-build6700 (including) | 6.7-build6700 (including) |
Manageengine_password_manager_pro | Zohocorp | 6.7-build6701 (including) | 6.7-build6701 (including) |
Manageengine_password_manager_pro | Zohocorp | 6.8-build6800 (including) | 6.8-build6800 (including) |
Manageengine_password_manager_pro | Zohocorp | 6.8-build6801 (including) | 6.8-build6801 (including) |
Manageengine_password_manager_pro | Zohocorp | 6.8-build6802 (including) | 6.8-build6802 (including) |
Manageengine_password_manager_pro | Zohocorp | 6.8-build6803 (including) | 6.8-build6803 (including) |
Manageengine_password_manager_pro | Zohocorp | 6.9 (including) | 6.9 (including) |
Manageengine_password_manager_pro | Zohocorp | 6.9-build6900 (including) | 6.9-build6900 (including) |
Manageengine_password_manager_pro | Zohocorp | 6.9-build6901 (including) | 6.9-build6901 (including) |
Manageengine_password_manager_pro | Zohocorp | 6.9-build6902 (including) | 6.9-build6902 (including) |
Manageengine_password_manager_pro | Zohocorp | 6.9-build6903 (including) | 6.9-build6903 (including) |
Manageengine_password_manager_pro | Zohocorp | 6.9-build6904 (including) | 6.9-build6904 (including) |
Manageengine_password_manager_pro | Zohocorp | 7.0 (including) | 7.0 (including) |
Manageengine_password_manager_pro | Zohocorp | 7.0-build7000 (including) | 7.0-build7000 (including) |
Manageengine_password_manager_pro | Zohocorp | 7.0-build7001 (including) | 7.0-build7001 (including) |
Manageengine_password_manager_pro | Zohocorp | 7.0-build7002 (including) | 7.0-build7002 (including) |
Manageengine_password_manager_pro | Zohocorp | 7.0-build7003 (including) | 7.0-build7003 (including) |
Manageengine_password_manager_pro | Zohocorp | 7.1 (including) | 7.1 (including) |
Manageengine_password_manager_pro | Zohocorp | 7.1-build7100 (including) | 7.1-build7100 (including) |
Manageengine_password_manager_pro | Zohocorp | 7.1-build7101 (including) | 7.1-build7101 (including) |
Manageengine_password_manager_pro | Zohocorp | 7.1-build7102 (including) | 7.1-build7102 (including) |
Manageengine_password_manager_pro | Zohocorp | 7.1-build7103 (including) | 7.1-build7103 (including) |
Manageengine_password_manager_pro | Zohocorp | 7.1-build7104 (including) | 7.1-build7104 (including) |
Manageengine_password_manager_pro | Zohocorp | 7.1-build7105 (including) | 7.1-build7105 (including) |
Manageengine_password_manager_pro | Zohocorp | 7.5-build7500 (including) | 7.5-build7500 (including) |
Manageengine_password_manager_pro | Zohocorp | 7.5-build7501 (including) | 7.5-build7501 (including) |
Manageengine_password_manager_pro | Zohocorp | 7.6-build7600 (including) | 7.6-build7600 (including) |
Manageengine_password_manager_pro | Zohocorp | 8.0-build8000 (including) | 8.0-build8000 (including) |
Manageengine_password_manager_pro | Zohocorp | 8.0-build8001 (including) | 8.0-build8001 (including) |
Manageengine_password_manager_pro | Zohocorp | 8.1-build8100 (including) | 8.1-build8100 (including) |
Manageengine_password_manager_pro | Zohocorp | 8.1-build8101 (including) | 8.1-build8101 (including) |
Manageengine_password_manager_pro | Zohocorp | 8.1-build8102 (including) | 8.1-build8102 (including) |
Manageengine_password_manager_pro | Zohocorp | 8.2-build8200 (including) | 8.2-build8200 (including) |
Manageengine_password_manager_pro | Zohocorp | 8.3-build8300 (including) | 8.3-build8300 (including) |
Manageengine_password_manager_pro | Zohocorp | 8.3-build8301 (including) | 8.3-build8301 (including) |
Manageengine_password_manager_pro | Zohocorp | 8.3-build8302 (including) | 8.3-build8302 (including) |
Manageengine_password_manager_pro | Zohocorp | 8.3-build8303 (including) | 8.3-build8303 (including) |
Manageengine_password_manager_pro | Zohocorp | 8.4-build8041 (including) | 8.4-build8041 (including) |
Manageengine_password_manager_pro | Zohocorp | 8.4-build8400 (including) | 8.4-build8400 (including) |
Manageengine_password_manager_pro | Zohocorp | 8.4-build8402 (including) | 8.4-build8402 (including) |
Manageengine_password_manager_pro | Zohocorp | 8.4-build8403 (including) | 8.4-build8403 (including) |
Manageengine_password_manager_pro | Zohocorp | 8.4-build8404 (including) | 8.4-build8404 (including) |
Manageengine_password_manager_pro | Zohocorp | 8.5-build8500 (including) | 8.5-build8500 (including) |
Manageengine_password_manager_pro | Zohocorp | 8.5-build8501 (including) | 8.5-build8501 (including) |
Manageengine_password_manager_pro | Zohocorp | 8.5-build8502 (including) | 8.5-build8502 (including) |
Manageengine_password_manager_pro | Zohocorp | 8.5-build8503 (including) | 8.5-build8503 (including) |
Manageengine_password_manager_pro | Zohocorp | 8.5-build8504 (including) | 8.5-build8504 (including) |
Manageengine_password_manager_pro | Zohocorp | 8.5-build8505 (including) | 8.5-build8505 (including) |
Manageengine_password_manager_pro | Zohocorp | 8.6-build8600 (including) | 8.6-build8600 (including) |
Manageengine_password_manager_pro | Zohocorp | 8.6-build8601 (including) | 8.6-build8601 (including) |
Manageengine_password_manager_pro | Zohocorp | 8.6-build8602 (including) | 8.6-build8602 (including) |
Manageengine_password_manager_pro | Zohocorp | 8.6-build8603 (including) | 8.6-build8603 (including) |
Manageengine_password_manager_pro | Zohocorp | 8.6-build8604 (including) | 8.6-build8604 (including) |
Manageengine_password_manager_pro | Zohocorp | 8.7-build8700 (including) | 8.7-build8700 (including) |
Manageengine_password_manager_pro | Zohocorp | 8.7-build8701 (including) | 8.7-build8701 (including) |
Manageengine_password_manager_pro | Zohocorp | 8.7-build8702 (including) | 8.7-build8702 (including) |
Manageengine_password_manager_pro | Zohocorp | 8.7-build8703 (including) | 8.7-build8703 (including) |
Manageengine_password_manager_pro | Zohocorp | 8.7-build8704 (including) | 8.7-build8704 (including) |
Manageengine_password_manager_pro | Zohocorp | 9.0 (including) | 9.0 (including) |
Manageengine_password_manager_pro | Zohocorp | 9.0-build9000 (including) | 9.0-build9000 (including) |
Manageengine_password_manager_pro | Zohocorp | 9.0-build9001 (including) | 9.0-build9001 (including) |
Manageengine_password_manager_pro | Zohocorp | 9.0-build9002 (including) | 9.0-build9002 (including) |
Manageengine_password_manager_pro | Zohocorp | 9.0-build9003 (including) | 9.0-build9003 (including) |
Manageengine_password_manager_pro | Zohocorp | 9.1 (including) | 9.1 (including) |
Manageengine_password_manager_pro | Zohocorp | 9.1-build9100 (including) | 9.1-build9100 (including) |
Manageengine_password_manager_pro | Zohocorp | 9.1-build9101 (including) | 9.1-build9101 (including) |
Manageengine_password_manager_pro | Zohocorp | 9.2 (including) | 9.2 (including) |
Manageengine_password_manager_pro | Zohocorp | 9.2-build9200 (including) | 9.2-build9200 (including) |
Manageengine_password_manager_pro | Zohocorp | 9.3 (including) | 9.3 (including) |
Manageengine_password_manager_pro | Zohocorp | 9.3-build9300 (including) | 9.3-build9300 (including) |
Manageengine_password_manager_pro | Zohocorp | 9.4-build9400 (including) | 9.4-build9400 (including) |
Manageengine_password_manager_pro | Zohocorp | 9.4-build9401 (including) | 9.4-build9401 (including) |
Manageengine_password_manager_pro | Zohocorp | 9.4-build9402 (including) | 9.4-build9402 (including) |
Manageengine_password_manager_pro | Zohocorp | 9.5-build9500 (including) | 9.5-build9500 (including) |
Manageengine_password_manager_pro | Zohocorp | 9.5-build9501 (including) | 9.5-build9501 (including) |
Manageengine_password_manager_pro | Zohocorp | 9.5-build9502 (including) | 9.5-build9502 (including) |
Manageengine_password_manager_pro | Zohocorp | 9.6-build9600 (including) | 9.6-build9600 (including) |
Manageengine_password_manager_pro | Zohocorp | 9.6-build9601 (including) | 9.6-build9601 (including) |
Manageengine_password_manager_pro | Zohocorp | 9.7-build9700 (including) | 9.7-build9700 (including) |
Manageengine_password_manager_pro | Zohocorp | 9.7-build9701 (including) | 9.7-build9701 (including) |
Manageengine_password_manager_pro | Zohocorp | 9.7-build9702 (including) | 9.7-build9702 (including) |
Manageengine_password_manager_pro | Zohocorp | 9.8-build9800 (including) | 9.8-build9800 (including) |
Manageengine_password_manager_pro | Zohocorp | 9.8-build9801 (including) | 9.8-build9801 (including) |
Manageengine_password_manager_pro | Zohocorp | 9.8-build9802 (including) | 9.8-build9802 (including) |
Manageengine_password_manager_pro | Zohocorp | 9.8-build9803 (including) | 9.8-build9803 (including) |
Manageengine_password_manager_pro | Zohocorp | 9.9 (including) | 9.9 (including) |
Manageengine_password_manager_pro | Zohocorp | 9.9-build9900 (including) | 9.9-build9900 (including) |
Manageengine_password_manager_pro | Zohocorp | 9.9-build9901 (including) | 9.9-build9901 (including) |
Manageengine_password_manager_pro | Zohocorp | 10.0 (including) | 10.0 (including) |
Manageengine_password_manager_pro | Zohocorp | 10.0-build10000 (including) | 10.0-build10000 (including) |
Manageengine_password_manager_pro | Zohocorp | 10.0-build10001 (including) | 10.0-build10001 (including) |
Manageengine_password_manager_pro | Zohocorp | 10.1-build10100 (including) | 10.1-build10100 (including) |
Manageengine_password_manager_pro | Zohocorp | 10.1-build10101 (including) | 10.1-build10101 (including) |
Manageengine_password_manager_pro | Zohocorp | 10.1-build10102 (including) | 10.1-build10102 (including) |
Manageengine_password_manager_pro | Zohocorp | 10.1-build10103 (including) | 10.1-build10103 (including) |
Manageengine_password_manager_pro | Zohocorp | 10.1-build10104 (including) | 10.1-build10104 (including) |
Manageengine_password_manager_pro | Zohocorp | 10.2-build10200 (including) | 10.2-build10200 (including) |
Manageengine_password_manager_pro | Zohocorp | 10.3-build10300 (including) | 10.3-build10300 (including) |
Manageengine_password_manager_pro | Zohocorp | 10.3-build10301 (including) | 10.3-build10301 (including) |
Manageengine_password_manager_pro | Zohocorp | 10.3-build10302 (including) | 10.3-build10302 (including) |
Manageengine_password_manager_pro | Zohocorp | 10.4 (including) | 10.4 (including) |
Manageengine_password_manager_pro | Zohocorp | 10.4-build10400 (including) | 10.4-build10400 (including) |
Manageengine_password_manager_pro | Zohocorp | 10.4-build10401 (including) | 10.4-build10401 (including) |
Manageengine_password_manager_pro | Zohocorp | 10.4-build10402 (including) | 10.4-build10402 (including) |
Manageengine_password_manager_pro | Zohocorp | 11.1 (including) | 11.1 (including) |
Manageengine_password_manager_pro | Zohocorp | 11.1-11104 (including) | 11.1-11104 (including) |
Manageengine_password_manager_pro | Zohocorp | 11.1-build_11101 (including) | 11.1-build_11101 (including) |
Manageengine_password_manager_pro | Zohocorp | 11.1-build_11102 (including) | 11.1-build_11102 (including) |
Manageengine_password_manager_pro | Zohocorp | 11.1-build_11103 (including) | 11.1-build_11103 (including) |
Manageengine_password_manager_pro | Zohocorp | 11.2 (including) | 11.2 (including) |
Manageengine_password_manager_pro | Zohocorp | 11.2-build11200 (including) | 11.2-build11200 (including) |
Manageengine_password_manager_pro | Zohocorp | 11.2-build11201 (including) | 11.2-build11201 (including) |
Manageengine_password_manager_pro | Zohocorp | 11.3-build11300 (including) | 11.3-build11300 (including) |
Manageengine_password_manager_pro | Zohocorp | 11.3-build11301 (including) | 11.3-build11301 (including) |
Manageengine_password_manager_pro | Zohocorp | 12.0-build12000 (including) | 12.0-build12000 (including) |
Manageengine_password_manager_pro | Zohocorp | 12.0-build12001 (including) | 12.0-build12001 (including) |
Manageengine_password_manager_pro | Zohocorp | 12.0-build12002 (including) | 12.0-build12002 (including) |
Manageengine_password_manager_pro | Zohocorp | 12.0-build12003 (including) | 12.0-build12003 (including) |
Manageengine_password_manager_pro | Zohocorp | 12.0-build12004 (including) | 12.0-build12004 (including) |
Manageengine_password_manager_pro | Zohocorp | 12.0-build12005 (including) | 12.0-build12005 (including) |
Manageengine_password_manager_pro | Zohocorp | 12.0-build12006 (including) | 12.0-build12006 (including) |
Manageengine_password_manager_pro | Zohocorp | 12.0-build12007 (including) | 12.0-build12007 (including) |
Manageengine_password_manager_pro | Zohocorp | 12.1-build12100 (including) | 12.1-build12100 (including) |
Manageengine_password_manager_pro | Zohocorp | 12.1-build12101 (including) | 12.1-build12101 (including) |
Manageengine_password_manager_pro | Zohocorp | 12.1-build12110 (including) | 12.1-build12110 (including) |
Manageengine_password_manager_pro | Zohocorp | 12.1-build12120 (including) | 12.1-build12120 (including) |
Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data. This can be used to alter query logic to bypass security checks, or to insert additional statements that modify the back-end database, possibly including execution of system commands. SQL injection has become a common issue with database-driven web sites. The flaw is easily detected, and easily exploited, and as such, any site or product package with even a minimal user base is likely to be subject to an attempted attack of this kind. This flaw depends on the fact that SQL makes no real distinction between the control and data planes.