SolarWinds Storage Manager Server SQL Injection Authentication Bypass Exploit

This module exploits a vulnerability in the SolarWinds Storage Manager Server. The LoginServlet page available on port 9000 is vulnerable to SQL injection via the loginName field. An attacker can send a specially crafted username and execute arbitrary SQL commands leading to remote code execution.
Exploit Type - Old
Exploits/Remote
Exploit Platform
Exploit Type
Product Name