Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

ECCouncil Certified Ethical Hacker Exam (CEHv13) 312-50v13 Question # 133 Topic 14 Discussion

ECCouncil Certified Ethical Hacker Exam (CEHv13) 312-50v13 Question # 133 Topic 14 Discussion

312-50v13 Exam Topic 14 Question 133 Discussion:
Question #: 133
Topic #: 14

A penetration tester is assessing a web application that does not properly sanitize user input in the search field. The tester suspects the application is vulnerable to a SQL injection attack. Which approach should the tester take to confirm the vulnerability?


A.

Use directory traversal in the search field to access sensitive files on the server


B.

Input a SQL query such as 1 OR 1=1 — into the search field to check for SQL injection


C.

Perform a brute-force attack on the login page to identify weak passwords


D.

Inject JavaScript into the search field to perform a Cross-Site Scripting (XSS) attack


Get Premium 312-50v13 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.