← Vulnerability feed

Vulnerability record · CVE-2014-3996 · published 5 December 2014

CVE-2014-3996: Manageengine it360 sql injection vulnerability

Manageengine · It360

SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90043, Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7 build 7003, IT360 and IT360 Managed Service Providers (MSP) edition before 10.3.3 build 10330, and possibly other ManageEngine products, allows remote attackers or remote authenticated users to execute arbitrary SQL commands via the sv parameter to LinkViewFetchServlet.dat.

7.5 CVSS 2.0 High EPSS 38% · top 1.5% CWE-89 · SQL injection
7.5CVSS 2.0 base score
38%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
12References, 10 tagged exploit
17 Jun 2026Last modified by NVD

Description

SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90043, Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7 build 7003, IT360 and IT360 Managed Service Providers (MSP) edition before 10.3.3 build 10330, and possibly other ManageEngine products, allows remote attackers or remote authenticated users to execute arbitrary SQL commands via the sv parameter to LinkViewFetchServlet.dat.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-3996 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-28960Manageengine desktop central command injection vulnerabilityZoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handling of an input command in on-d…EPSS 2.0%9.8CVE-2015-8249ManageEngine Desktop Central FileUploadServlet unrestricted file uploadThe FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 fails to restrict uploaded files, allowing arbitrary file upload thr…EPSS 74%analysed8.8CVE-2014-5301ManageEngine ServiceDesk Plus and related products path traversalA directory traversal flaw (CWE-22) affects ManageEngine ServiceDesk Plus MSP v5 to v9.0 v9030, AssetExplorer v4 to v6.1, SupportCenter v5 to v7.9, a…EPSS 78%analysed8.8CVE-2014-5302Manageengine servicedesk plus path traversal vulnerabilityDirectory traversal vulnerability in ServiceDesk Plus and Plus MSP v5 through v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v…EPSS 11%6.5CVE-2014-8499Manageengine password manager pro sql injection vulnerabilityMultiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition be…EPSS 36%6.4CVE-2014-9372Manageengine password manager pro path traversal vulnerabilityDirectory traversal vulnerability in the UploadAccountActivities servlet in ManageEngine Password Manager Pro (PMP) before 7103 allows remote attacke…EPSS 2.4%4.3CVE-2009-4387Manageengine password manager pro cross-site scripting vulnerabilityThe cross-site scripting (XSS) protection mechanism in ShowInContentAreaAction.do in ManageEngine Password Manager Pro (PMP) before 6.1 Build 6104 us…EPSS 1.3%9.8CVE-2026-76461Cisco AsyncOS email parsing SQL injection allows root command executionCisco AsyncOS Software for Cisco Secure Email Gateway fails to properly validate email parsing input, allowing crafted email messages containing mali…KEVEPSS 28%analysed

Source: NIST National Vulnerability Database (record CVE-2014-3996), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.