This exploit demonstrates a SQL injection vulnerability in Snort Report <= 1.3.2 via the 'ipAddress' parameter in the 'ipdetail.php' script. The PoC includes a crafted URL with a time-based SQL injection payload designed to extract the current database user.
Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target:Snort Report <= 1.3.2
No auth needed
Prerequisites:Access to the vulnerable Snort Report web interface