Weekend Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

ECCouncil Certified Ethical Hacker Exam (CEHv13) 312-50v13 Question # 32 Topic 4 Discussion

ECCouncil Certified Ethical Hacker Exam (CEHv13) 312-50v13 Question # 32 Topic 4 Discussion

312-50v13 Exam Topic 4 Question 32 Discussion:
Question #: 32
Topic #: 4

A penetration tester suspects that a web application's user profile page is vulnerable to SQL injection, as it uses the userID parameter in SQL queries without proper sanitization. Which technique should the tester use to confirm the vulnerability?


A.

Use the userID parameter to perform a brute-force attack on the admin login page


B.

Modify the userID parameter in the URL to ' OR '1'='1 and check if it returns multiple profiles


C.

Inject HTML code into the userID parameter to test for Cross-Site Scripting (XSS)


D.

Attempt a directory traversal attack using the userID parameter


Get Premium 312-50v13 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.