Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam 312-50v12 All Questions

View all questions & answers for the 312-50v12 exam

Exam 312-50v12 topic 1 question 287 discussion

Actual exam question from ECCouncil's 312-50v12
Question #: 287
Topic #: 1
[All 312-50v12 Questions]

Calvin, a software developer, uses a feature that helps him auto-generate the content of a web page without manual involvement and is integrated with SSI directives. This leads to a vulnerability in the developed web application as this feature accepts remote user inputs and uses them on the page. Hackers can exploit this feature and pass malicious SSI directives as input values to perform malicious activities such as modifying and erasing server files.

What is the type of injection attack Calvin's web application is susceptible to?

  • A. CRLF injection
  • B. Server-side template injection
  • C. Server-side JS injection
  • D. Server-side includes injection
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
shaody
3 months ago
Selected Answer: D
Server-side Includes is an application feature. Attackers exploit this feature to pass malicious SSI directives as input values and perform malicious activities.
upvoted 1 times
...
LordXander
7 months, 3 weeks ago
Selected Answer: D
CEHv12 - 1913
upvoted 1 times
...
insaniunt
9 months ago
Selected Answer: D
D. Server-side includes injection
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...