Pre-Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

ECCouncil Certified Ethical Hacker Exam (CEHv13) 312-50v13 Question # 86 Topic 9 Discussion

ECCouncil Certified Ethical Hacker Exam (CEHv13) 312-50v13 Question # 86 Topic 9 Discussion

312-50v13 Exam Topic 9 Question 86 Discussion:
Question #: 86
Topic #: 9

A penetration tester suspects that the web application's "Order History" page is vulnerable to SQL injection because it displays user orders based on an unprotected user ID parameter in the URL. What is the most appropriate approach to test this?


A.

Inject JavaScript into the URL parameter to test for Cross-Site Scripting (XSS)


B.

Modify the URL parameter to userID=1 OR 1=1 and observe if all orders are displayed


C.

Perform a directory traversal attack to access sensitive system files


D.

Use a brute-force attack on the login form to identify valid user credentials


Get Premium 312-50v13 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.