Joke Website Script SQL Injection and Cross-Site Scripting Vulnerabilities

Please view the original advisory here.
The “Joke Website Script” is exposed to SQL Injection and Cross-Site Scripting attacks.

>> #1 SQL Injection
target/search.php?submit=Search&keyword=[SQLi]

>> #2 Cross-Site Scripting
target/search.php?submit=Search&keyword=[XSS]