CompTIA PenTest+ Certification Exam PT0-002 Question # 130 Topic 14 Discussion

CompTIA PenTest+ Certification Exam PT0-002 Question # 130 Topic 14 Discussion

PT0-002 Exam Topic 14 Question 130 Discussion:
Question #: 130
Topic #: 14

A tester who is performing a penetration test on a website receives the following output:

Warning: mysql_fetch_array() expects parameter 1 to be resource, boolean given in /var/www/search.php on line 62

Which of the following commands can be used to further attack the website?


A.

<script>var adr= ‘../evil.php?test=’ + escape(document.cookie);</script>


B.

../../../../../../../../../../etc/passwd


C.

/var/www/html/index.php;whoami


D.

1 UNION SELECT 1, DATABASE(),3--


Get Premium PT0-002 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.