CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Softwares and Software Security
A web application accepts a user's login name and places it directly into a database query string without validation. An attacker types a fragment of query code into the login field and gains access to records of other users. Which vulnerability has the attacker exploited?
The attacker has exploited SQL injection. The application inserted unvalidated user input straight into a database query, so the attacker's typed code changed the query's logic and exposed other users' records. Input validation and parameterised queries are the standard defences against this weakness.
- ACross-site request forgery
- BSQL injectionCorrect
- CBuffer underflow in the browser
- DSession fixation through cookie expiry
Explanation
Unvalidated user input concatenated into a database query lets an attacker alter the query logic, which is SQL injection. Cross-site request forgery tricks an authenticated user's browser into sending unwanted requests and does not involve inserting query code through an input field.
Did you get it right without looking?
One question tells you little. A timed set on Softwares and Software Security shows your real accuracy, how long you take and where you lose marks.
More Softwares and Software Security questions
- During which SDLC phase are bugs reported by users after go-live fixed and the software updated for changed business needs?
- Under the IT Act framework, which Indian body is designated as the national agency responsible for responding to cyber security incidents su…
- Ravi Textiles Ltd. in Surat buys a licence for 50 users of an accounting package, but the IT head installs it on 80 computers. Which charact…
- Meridian Textiles Pvt Ltd installs a single-user licensed accounting package on 25 office computers after purchasing only one licence. Which…
- An employee at a Pune company downloads a free utility. It appears to work as advertised but secretly lets a remote person control the compu…
- Which feature distinguishes a copyleft open-source licence such as the GNU General Public License from a permissive licence such as MIT?