Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Snort Report Remote Command Execution Vulnerability in Nmap and NBTSCan Scripts

Vulnerability

A remote command execution vulnerability has been identified in Snort Report versions prior to 1.3.2. The issue resides in the nmap.php and nbtscan.php scripts, which do not properly sanitize user input from the target GET parameter. This lack of input validation allows attackers to inject arbitrary shell commands. Exploitation of this vulnerability requires no authentication and could lead to a complete compromise of the underlying system.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the server where Snort Report is installed, potentially leading to a full system compromise.

Reproduction

To reproduce this vulnerability, send a GET request to the server with the target parameter set to a crafted payload. This payload should include base64-encoded commands that, when decoded and executed, could compromise the system. The response should be checked for indications that the commands were executed successfully.

Remediation

Users are advised to upgrade to Snort Report version 1.3.2 or later, where this vulnerability has been addressed.

Added: Aug 13, 2025, 10:38 PM
Updated: Aug 13, 2025, 10:38 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
9.1
remediation
0.0
relevance
0.3
threat
9.3
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.