<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: sol injection in Report Server</title>
    <link>https://community.fabric.microsoft.com/t5/Report-Server/sol-injection/m-p/323161#M2885</link>
    <description>&lt;P&gt;going from what you have posted it seem that sqlmap is telling you that the tests it ran cant find a way to inject.&lt;/P&gt;&lt;P&gt;Have you tried using&amp;nbsp;the&amp;nbsp;parameters in the logs?&lt;/P&gt;</description>
    <pubDate>Wed, 13 Dec 2017 22:39:40 GMT</pubDate>
    <dc:creator>markp</dc:creator>
    <dc:date>2017-12-13T22:39:40Z</dc:date>
    <item>
      <title>sol injection</title>
      <link>https://community.fabric.microsoft.com/t5/Report-Server/sol-injection/m-p/322215#M2860</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;I tried to exploit a vulnerability that was found with a program that find vulnerable but sqlmap says this message though it's vulnerable to be cause and how I can go over&lt;BR /&gt;&lt;BR /&gt;[WARNING] The GET parameter 'query' does not seem to be injectable&lt;BR /&gt;&lt;SPAN&gt;[18:18:41] [CRITICAL] all tested parameters appear to be not injectable.&lt;/SPAN&gt; &lt;SPAN&gt;Try to increase '-level' / '- risk' values to perform more tests.&lt;/SPAN&gt; &lt;SPAN&gt;Also, you can try to rerun by providing either a valid value for option '--string' (or '--regexp').&lt;/SPAN&gt; &lt;SPAN&gt;If you suspect that there is some kind of protection mechanism involved (eg WAF), maybe you could try again with a '--tamper' option (eg '--tamper = space2comment')&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 18:34:10 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Report-Server/sol-injection/m-p/322215#M2860</guid>
      <dc:creator>deep666</dc:creator>
      <dc:date>2017-12-12T18:34:10Z</dc:date>
    </item>
    <item>
      <title>Re: sol injection</title>
      <link>https://community.fabric.microsoft.com/t5/Report-Server/sol-injection/m-p/323161#M2885</link>
      <description>&lt;P&gt;going from what you have posted it seem that sqlmap is telling you that the tests it ran cant find a way to inject.&lt;/P&gt;&lt;P&gt;Have you tried using&amp;nbsp;the&amp;nbsp;parameters in the logs?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2017 22:39:40 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Report-Server/sol-injection/m-p/323161#M2885</guid>
      <dc:creator>markp</dc:creator>
      <dc:date>2017-12-13T22:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: sol injection</title>
      <link>https://community.fabric.microsoft.com/t5/Report-Server/sol-injection/m-p/323553#M2895</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;i have used parameters from the documentation and vain the parameter is vulnerable as it is found with owasp zap but can not pass those waf protectors with code can use to be able to pass for filtering&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Dec 2017 11:08:07 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Report-Server/sol-injection/m-p/323553#M2895</guid>
      <dc:creator>deep666</dc:creator>
      <dc:date>2017-12-14T11:08:07Z</dc:date>
    </item>
  </channel>
</rss>

