ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 345 - PT0-002 discussion

Report
Export

A company developed a new web application to allow its customers to submit loan applications. A penetration tester is reviewing the application and discovers that the application was developed in ASP and used MSSQL for its back-end database. Using the application's search form, the penetration tester inputs the following code in the search input field:

IMG SRC=vbscript:msgbox ('Vulnerable_to_Attack') ; >originalAttribute='SRC'originalPath='vbscript;msgbox ('Vulnerable_to_Attack ') ;>'

When the tester checks the submit button on the search form, the web browser returns a pop-up windows that displays 'Vulnerable_to_Attack.' Which of the following vulnerabilities did the tester discover in the web application?

A.
SQL injection
Answers
A.
SQL injection
B.
Command injection
Answers
B.
Command injection
C.
Cross-site request forgery
Answers
C.
Cross-site request forgery
D.
Cross-site scripting
Answers
D.
Cross-site scripting
Suggested answer: D
asked 02/10/2024
Felipe Santos Cardoso
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first