ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 197 - PT0-002 discussion

Report
Export

During a penetration test, a tester is able to change values in the URL from example.com/login.php?id=5 to example.com/login.php?id=10 and gain access to a web application.

Which of the following vulnerabilities has the penetration tester exploited?

A.
Command injection
Answers
A.
Command injection
B.
Broken authentication
Answers
B.
Broken authentication
C.
Direct object reference
Answers
C.
Direct object reference
D.
Cross-site scripting
Answers
D.
Cross-site scripting
Suggested answer: C

Explanation:

Insecure direct object reference (IDOR) is a vulnerability where the developer of the application does not implement authorization features to verify that someone accessing data on the site is allowed to access that data.

asked 02/10/2024
christopher tenney
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first